MALICIOUS — aae6e8280d732a64cff457993646161c28df2d52fb410e3ebc12f49a95ffb066
MALICIOUS — aae6e8280d732a64cff457993646161c28df2d52fb410e3ebc12f49a95ffb066 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Vindor family. 4 of 55 detection engines flagged it.
Identification
- SHA-256:
aae6e8280d732a64cff457993646161c28df2d52fb410e3ebc12f49a95ffb066 - SHA-1:
a3f39ed38cee521f57aa24211773c4a0f57c26b3 - MD5:
06ea5420bb600b3204412d132b0308ae - imphash:
92f377bec2fd08bb16ed274dff1cdbcc - ssdeep:
12288:uy+5+JL0dLo1d1W89Iy+5+JL0dLo1d1W8T:W5+t0pOdR65+t0pOdRT - TLSH:
T1B14D7D8D8336B705E6F6CF705C44FE0D5056B0DA273EA85C0683C22E72E646FA53694A - Submitted as: aae6e8280d732a64cff457993646161c28df2d52fb410e3ebc12f49a95ffb066
- File type: pe · Size: 610638 bytes
- Verdict: malicious (92/100) · Family: Vindor
Detections (4 of 55 engines)
- ClamAV (daily): Win.Worm.Vindor-9886047-0
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- LIEF (executable format parser): lief:invalid-authenticode
- Kaspersky (KVRT): Worm.Win32.AutoRun.vx
Why this verdict
The malicious score of 92/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Worm.Vindor-9886047-0 (rule
Win.Worm.Vindor-9886047-0) - engine signal, weight 0.90, confidence 0.95 - YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://www.digicert.com/ssl-cps-repository.htm0
- http://crl3.digicert.com/assured-cs-2011a.crl03
- http://crl4.digicert.com/assured-cs-2011a.crl0
- http://cacerts.digicert.com/DigiCertAssuredIDCodeSigningCA-1.crt0
- http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
- http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
- http://crl.thawte.com/ThawteTimestampingCA.crl0
Embedded domains
- schemas.microsoft.com
- www.digicert.com
- cacerts.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- ts-aia.ws.symantec.com
- ts-crl.ws.symantec.com
- crl.thawte.com
File paths
- c:\builds\moz2_slave\rel-m-rel-w32_bld-000000000000\build\obj-firefox\ipc\app\plugin-container.pdb
- T:\:d:l:t:
- D:\:`:
- C:\Program
More Vindor samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report