MALICIOUS — b2b14a21048fb49771b4f17ab4e7be2dc90fc9d39d4721df5687550ae0a2b6a4
MALICIOUS — b2b14a21048fb49771b4f17ab4e7be2dc90fc9d39d4721df5687550ae0a2b6a4 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (74/100), attributed to the Wacatac family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
b2b14a21048fb49771b4f17ab4e7be2dc90fc9d39d4721df5687550ae0a2b6a4 - SHA-1:
5a3fd0cf131ea617ca5944eb33b9da6be2c8c44b - MD5:
e055bd2e3fbfacc1e0e296546124f37d - imphash:
edc8666294af981c94d2e2ae14e7ab9a - ssdeep:
196608:j4lN2pLYG6usJ1fgjBXYYpzZl/LYLI1upLnO1I:j4lRLXgdXYuZdLf1upP - TLSH:
T11A67225B34E89E80C574315044B3A4BD83A29F1FC39A2089B4CF7B5665FA49785E03EB - Submitted as: b2b14a21048fb49771b4f17ab4e7be2dc90fc9d39d4721df5687550ae0a2b6a4
- File type: pe · Size: 7238144 bytes
- Verdict: malicious (74/100) · Family: Wacatac
Detections (5 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): Themida/VMProtect
- YARA: Yara-Rules community: YR_Packer_VMProtect
- Detect It Easy (packer/type): DIE:VMProtect 3.2.0-3.5.0
- Microsoft Defender: Trojan:Win32/Wacatac.B!ml
- Kaspersky (KVRT): UDS:Trojan.Win32.Agentb.a
Why this verdict
The malicious score of 74/100 is the fusion of 4 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Wacatac.B!ml (rule
Trojan:Win32/Wacatac.B!ml) - engine signal, weight 0.55, confidence 0.85 - YARA: Yara-Rules community flagged YR_Packer_VMProtect (rule
YR_Packer_VMProtect) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:VMProtect 3.2.0-3.5.0 (rule
DIE:VMProtect 3.2.0-3.5.0) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Themida/VMProtect, high-entropy-sections:.vmp1, VMProtect 3.2.0-3.5.0 - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- 6.ai
File paths
- r:\&I
More Wacatac samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report