MALICIOUS — b4c90512f5264108510fe12cc7d3618772c085f518472847e25691f779514874
MALICIOUS — b4c90512f5264108510fe12cc7d3618772c085f518472847e25691f779514874 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the Zbot family. 6 of 55 detection engines flagged it.
Identification
- SHA-256:
b4c90512f5264108510fe12cc7d3618772c085f518472847e25691f779514874 - SHA-1:
772ff66f6a7e6970862a75a14f02032c6490cf77 - MD5:
5d2ec97d36ff416676edfd506e513abc - imphash:
83b45e356be38dee9f40ac165206f07f - ssdeep:
768:bX5L/v28rbBBAs4efgciryxApKd+CfbjYfou+lt/fFTujSjAsOmqeiir62:t/db4Y4yxmCNu+r/tTujUAsOer62 - TLSH:
T1F0398DFA8437856BDAF6DB33EC84AD0E646354B7127E120457D3D04F2AEA9D75830828 - Submitted as: b4c90512f5264108510fe12cc7d3618772c085f518472847e25691f779514874
- File type: pe · Size: 90246 bytes
- Verdict: malicious (91/100) · Family: Zbot
Detections (6 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Zbot-64619
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): Trojan.Downloader.JQRK
- Kaspersky (KVRT): Trojan-Downloader.Win32.Necurs.d
Why this verdict
The malicious score of 91/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Zbot-64619 (rule
Win.Trojan.Zbot-64619) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- C:\Users\Joe
- C:\Users\admin\Downloads\92f3dcf2059e54e1826b398cd3d628de.virus.exe
- C:\Users\Frank\Desktop\TlSTZzAw.exe
- C:\ff16c669b1d2721c19c4492fa7dad7e853cfd8fb7ed1f976f75537d8d863ba05
- C:\Users\george\Desktop\conwur.exe
- C:\Users\admin\Downloads\conwur.exe
More Zbot samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report