MALICIOUS — a3676562571f48c269027a069ecb08ee08973b7017f4965fa36a8fa34a18134e.bin
MALICIOUS — a3676562571f48c269027a069ecb08ee08973b7017f4965fa36a8fa34a18134e.bin is a unknown sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (85/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a3676562571f48c269027a069ecb08ee08973b7017f4965fa36a8fa34a18134e - SHA-1:
f7cc106b208a9c3e4d630627954489dd2b0d5bda - MD5:
863ead7a592b47d7547ab7931c935633 - ssdeep:
24:2VZpKXKLgJ0KexhvFpZpQeVkttg90KF2m6egsUZo2tCE7DjOgnCDE7DjOeiqi:2zpWagJWx3kttg9zFb5gsUZo2tH7DjOj - TLSH:
T16A138BDDFDF2C7A6075E4144B41D20BDA2B99D3A116220613FF47682A42F7753074B89 - Submitted as: a3676562571f48c269027a069ecb08ee08973b7017f4965fa36a8fa34a18134e.bin
- File type: unknown · Size: 1325 bytes
- Verdict: malicious (85/100)
Source: MalShare · first seen 2026-09-04T19:05:08.563Z · SHA-256 verified
Detections (3 of 53 engines)
- capa (capabilities): capability:execution/powershell
- Microsoft Defender: Trojan:Win32/Webshell.B
- Kaspersky (KVRT): Trojan.ASP.Webshell.aj
MITRE ATT&CK
Why this verdict
The malicious score of 85/100 is the fusion of 4 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Webshell.B (rule
Trojan:Win32/Webshell.B) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.ASP.Webshell.aj (rule
Trojan.ASP.Webshell.aj) - engine signal, weight 0.55, confidence 0.85 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report