MALICIOUS — a1fd0f76a835566d3060987379690eb1b4c5eaedceeffacfbb144fbd4846b806
MALICIOUS — a1fd0f76a835566d3060987379690eb1b4c5eaedceeffacfbb144fbd4846b806 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the Vobfus family. 5 of 51 detection engines flagged it.
Identification
- SHA-256:
a1fd0f76a835566d3060987379690eb1b4c5eaedceeffacfbb144fbd4846b806 - SHA-1:
c4b93e5b12610688bdb3093b6feff8fd162a445b - MD5:
97a97b7bc50645dc13f316abe0e6d634 - imphash:
c71faf810a074bbdd48daa092307bb81 - ssdeep:
6144:Ustj9IXHG6uB4a2TURdYDZ23w8QEoKHjWZLKBPvHIWMv+:CVaCZ2A81vWpaPvC+ - TLSH:
T1F349F899E51A1B03F87989022951282E90BDF9F260BF31CC13539C7E67D255BA2341BF - Submitted as: a1fd0f76a835566d3060987379690eb1b4c5eaedceeffacfbb144fbd4846b806
- File type: pe · Size: 394888 bytes
- Verdict: malicious (89/100) · Family: Vobfus
Detections (5 of 51 engines)
- ClamAV (daily): Win.Malware.Vobfus-9972871-0
- Microsoft Defender: Trojan:Win32/Pronny!pz
- Emsisoft (Emergency Kit): Gen:Variant.Midie.103239
- Trellix Stinger (McAfee): VBObfus.ek
- Kaspersky (KVRT): Trojan.Win32.Jorik.Vobfus.dsgb
Why this verdict
The malicious score of 89/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Malware.Vobfus-9972871-0 (rule
Win.Malware.Vobfus-9972871-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: Http://Avaco-Software.Tripod.com, http://Avaco-Software.tripod.com, Http://Avaco-Software.tripod.com - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- Http://Avaco-Software.Tripod.com
- http://Avaco-Software.tripod.com
- Http://Avaco-Software.tripod.com
Embedded domains
- yahoo.com
- avaco-software.tripod.com
Registry keys
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{Nama
File paths
- C:\Program
- C:\WINDOWS\Start
- c:\windows\regedit.exe
More Vobfus samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report