MALICIOUS — b5da95062421f1fdeb755c1a24b2633039ed854c24aac424e4c1b72c25d48323
MALICIOUS — b5da95062421f1fdeb755c1a24b2633039ed854c24aac424e4c1b72c25d48323 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100), attributed to the Zusy family. 4 of 55 detection engines flagged it.
Identification
- SHA-256:
b5da95062421f1fdeb755c1a24b2633039ed854c24aac424e4c1b72c25d48323 - SHA-1:
57180296881d9086405b7523fd15eb5c0a13adf9 - MD5:
4eacd17184c8b6977737a830118cb9a8 - imphash:
95122753ea27818b35f9b51859e4c692 - ssdeep:
49152:Qoa1taC070d5m/Pb3M4KIVRPDtzdbvaxST/s2jw1Z:Qoa1taC0+aPb3yIrtzdWgT07Z - TLSH:
T1135A23862619570CE6F5C8407D2D126EC842E8E76378184B528FF00EB7D7D67B8212EB - Submitted as: b5da95062421f1fdeb755c1a24b2633039ed854c24aac424e4c1b72c25d48323
- File type: pe · Size: 1958408 bytes
- Verdict: malicious (86/100) · Family: Zusy
Detections (4 of 55 engines)
- ClamAV (daily): Win.Malware.Zusy-9764479-0
- Microsoft Defender: Trojan:Win32/Salgorea!pz
- Emsisoft (Emergency Kit): Dump:Generic.Dacic.17983.C83B492E
- Kaspersky (KVRT): Backdoor.Win32.Salgorea.ic
Why this verdict
The malicious score of 86/100 is the fusion of 1 weighted signal:
- ClamAV (daily) flagged Win.Malware.Zusy-9764479-0 (rule
Win.Malware.Zusy-9764479-0) - engine signal, weight 0.90, confidence 0.95
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
Embedded domains
- j.ir
- 5j8.es
- schemas.microsoft.com
More Zusy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report