SUSPICIOUS — ba06e9cae6710343b75550e8cf104e8e62f315acbe86903e7fc9d54b5203fd83.bin
SUSPICIOUS — ba06e9cae6710343b75550e8cf104e8e62f315acbe86903e7fc9d54b5203fd83.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (60/100), attributed to the ASPack family. 5 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ba06e9cae6710343b75550e8cf104e8e62f315acbe86903e7fc9d54b5203fd83 - SHA-1:
edbb99a664cfa1d5673e03c1f0bfc0f1d1ed6dcc - MD5:
51848f76857ccb14eaed0d5562287377 - imphash:
32b7c13bef8134ca7d65d2956fc15d52 - ssdeep:
3072:R2AFG7H0VVq7kAXidB83OJIwj4/5tl8tqLpg9GprVp/uF3elACqcLvIoIII:R5G7HCVlAXiMX/qtqC9GJVphhD - TLSH:
T1F04212DC4FA1694EF8F6B41E4951642C261154BA045EA0AEDACB422C4FFA133CD39DB3 - Submitted as: ba06e9cae6710343b75550e8cf104e8e62f315acbe86903e7fc9d54b5203fd83.bin
- File type: pe · Size: 216064 bytes
- Verdict: suspicious (60/100) · Family: ASPack
Source: MalShare · first seen 2026-08-13T03:44:48.089Z · SHA-256 verified
Detections (5 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.MPRESS1
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:MPRESS
- Microsoft Defender: Trojan:Win32/Remcos!MTB
- Kaspersky (KVRT): HEUR:Backdoor.Win32.Remcos.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 60/100 is the fusion of 4 weighted signals:
- YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:MPRESS (rule
DIE:MPRESS) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: high-entropy-sections:.MPRESS1, MPRESS - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More ASPack samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report