CLEAN — a94e9aca1aca0c7e006a0d8684c5423b1a3bd7e48734eee4f12f0caa3b5d901a.exe
CLEAN — a94e9aca1aca0c7e006a0d8684c5423b1a3bd7e48734eee4f12f0caa3b5d901a.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (14/100). 4 of 52 detection engines flagged it.
Identification
- SHA-256:
a94e9aca1aca0c7e006a0d8684c5423b1a3bd7e48734eee4f12f0caa3b5d901a - SHA-1:
689a96b72e20cc501fa145637d1cdc3f76d68a3c - MD5:
be2f08950440b3bb987fc5d0999b3f1f - imphash:
35171f6f6a1bfee47cbc04cb345c411f - ssdeep:
98304:4cOQTlHoQK8lS9TvPcBI2jJZcTkGZ2NRT+2lqGWl0bzcncr/YQBv:4JQTKXyS9rPyPrHT+2sVWHcbQB - TLSH:
T114642329B0173E9ACDD3F9951C061D6D4F3BB4029595588CB29038CBE2C4A6F6AF50F2 - Submitted as: a94e9aca1aca0c7e006a0d8684c5423b1a3bd7e48734eee4f12f0caa3b5d901a.exe
- File type: pe · Size: 5210112 bytes
- Verdict: clean (14/100)
Source: MalwareBazaar · first seen 2026-08-01T00:00:00.000Z · SHA-256 verified
Detections (4 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.g .
- Microsoft Defender: Trojan:Win32/Egairtigado!rfn
- Emsisoft (Emergency Kit): Trojan.GenericKD.81008344
- Kaspersky (KVRT): UDS:Backdoor.Win32.PMax
Why this verdict
The clean score of 14/100 is the fusion of 1 weighted signal:
- Packing/obfuscation: high-entropy-sections:.g . - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- b7.to
- 5k.cf
File paths
- r:\R
- t:\Uf
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report