MALICIOUS — b28ae9aecc867478b51ea65b52d66bccb95632181dd1ac31aa0b18eecd374401
MALICIOUS — b28ae9aecc867478b51ea65b52d66bccb95632181dd1ac31aa0b18eecd374401 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the Zbot family. 6 of 51 detection engines flagged it.
Identification
- SHA-256:
b28ae9aecc867478b51ea65b52d66bccb95632181dd1ac31aa0b18eecd374401 - SHA-1:
0739fa88a6163e38a3f0ae5edf1dcff28920a1c5 - MD5:
1d34e998e6ab1e0044de660d61775dd9 - imphash:
83b45e356be38dee9f40ac165206f07f - ssdeep:
768:bX5L/v28rbBBAs4efgciryxApKd+CfbjYfou+lt/fFTujSjAsOmqeiir6u:t/db4Y4yxmCNu+r/tTujUAsOer6u - TLSH:
T10C398DFA8437856BDAF6DB33EC84AD0E646354B7127E120453D3D04F2AEA9D75830829 - Submitted as: b28ae9aecc867478b51ea65b52d66bccb95632181dd1ac31aa0b18eecd374401
- File type: pe · Size: 90174 bytes
- Verdict: malicious (91/100) · Family: Zbot
Detections (6 of 51 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Zbot-64619
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Kaspersky (KVRT): Trojan-Downloader.Win32.Necurs.d
- Microsoft Defender: Trojan:Win32/Astaroth!pz
- Emsisoft (Emergency Kit): Trojan.Downloader.JQRK
Why this verdict
The malicious score of 91/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Zbot-64619 (rule
Win.Trojan.Zbot-64619) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- C:\Users\Joe
- C:\Users\admin\Downloads\92f3dcf2059e54e1826b398cd3d628de.virus.exe
- C:\Users\Frank\Desktop\TlSTZzAw.exe
- C:\ff16c669b1d2721c19c4492fa7dad7e853cfd8fb7ed1f976f75537d8d863ba05
- C:\Users\admin\Downloads\conwur.exe
- C:\Users\george\Desktop\conwur.exe
More Zbot samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report