MALICIOUS — a4ca315da86fed98d9a31948b421eef56d2b8b307c87e794a63a1dc5e2b35a4b
MALICIOUS — a4ca315da86fed98d9a31948b421eef56d2b8b307c87e794a63a1dc5e2b35a4b is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the Vobfus family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
a4ca315da86fed98d9a31948b421eef56d2b8b307c87e794a63a1dc5e2b35a4b - SHA-1:
f9af0a1e2269ff9586fcf4e02aa94f58b3a1ba1a - MD5:
03e5321fd257c32d78c2a638902f03a0 - imphash:
8262fdc48a399d7b8190a3af463a61f7 - ssdeep:
3072:jNUNSItEiROnFSmPjCXMN5iH1VMZZZZWMkIJCh:qpdmEMN+1VHYe - TLSH:
T153410594FEDDE6B5D066E20749411C6C768EE75EFEAA573113BA4A1E04D23E3202072C - Submitted as: a4ca315da86fed98d9a31948b421eef56d2b8b307c87e794a63a1dc5e2b35a4b
- File type: pe · Size: 184320 bytes
- Verdict: malicious (89/100) · Family: Vobfus
Detections (5 of 52 engines)
- ClamAV (daily): Win.Trojan.Vobfus-45
- Microsoft Defender: Worm:Win32/Vobfus.FI
- Emsisoft (Emergency Kit): Gen:Variant.Symmi.769
- Trellix Stinger (McAfee): VBObfus.ei
- Kaspersky (KVRT): Trojan.Win32.Vobfus.llu
Why this verdict
The malicious score of 89/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Vobfus-45 (rule
Win.Trojan.Vobfus-45) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://vbnet.mvps.org/index.html, http://www.Planet-Source-Code.com/vb/, http://vb.mvps.org/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://vbnet.mvps.org/index.html
- http://www.Planet-Source-Code.com/vb/
- http://vb.mvps.org/
- http://allapi.mentalis.org/apilist/apilist.php
Embedded domains
- vbnet.mvps.org
- vb.mvps.org
- allapi.mentalis.org
- www.planet-source-code.com
File paths
- C:\Windows\system32\msvbvm60.dll\3
- C:\Program
More Vobfus samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report