MALICIOUS — 739_WMIGhost.bin
MALICIOUS — 739_WMIGhost.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Syndicasec family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
a6ff8dfe654da70390cd71626cdca8a6f6a0d7980cd7d82269373737b04fd206 - SHA-1:
81b26dfabd1094678a21a016dc2692f67c6cde03 - MD5:
0df40b226a4913a57668b83b7c7b443c - imphash:
b7f5b233929749025d236965e9a9aaec - ssdeep:
384:ltJ8FWfDSt3YHc51GW9qs7Uso0503kdVi7:j+hYHAGW9h7Vi - TLSH:
T17A2A2A4296153928DC7382A3CB938ECD3923CE71B063060412D1DAD6DF67CA7B80B52D - Submitted as: 739_WMIGhost.bin
- File type: pe · Size: 20480 bytes
- Verdict: malicious (99/100) · Family: Syndicasec
Detections (5 of 52 engines)
- ClamAV (daily): {MD5}bin.trojan.syndicasec.9296.UNOFFICIAL
- Microsoft Defender: Trojan:Win32/Syndicasec.A
- Emsisoft (Emergency Kit): Gen:Variant.Fugrafa.114848
- Trellix Stinger (McAfee): Trojan-Thrip!0DF40B226A49
- Kaspersky (KVRT): Trojan.Win32.Agentb.bevf
Why this verdict
The malicious score of 99/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged {MD5}bin.trojan.syndicasec.9296.UNOFFICIAL (rule
{MD5}bin.trojan.syndicasec.9296.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Syndicasec.A (rule
Trojan:Win32/Syndicasec.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Fugrafa.114848 (rule
Gen:Variant.Fugrafa.114848) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Trojan-Thrip!0DF40B226A49 (rule
Trojan-Thrip!0DF40B226A49) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Agentb.bevf (rule
Trojan.Win32.Agentb.bevf) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- C:\Windows\system32\Instell.exe
More Syndicasec samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report