SUSPICIOUS — bae3d3241e4986bdc2e52ea303e93917dcf59a15ac5c6d46d958bbfca06952fc
SUSPICIOUS — bae3d3241e4986bdc2e52ea303e93917dcf59a15ac5c6d46d958bbfca06952fc is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100), attributed to the Sabsik family. 2 of 51 detection engines flagged it.
Identification
- SHA-256:
bae3d3241e4986bdc2e52ea303e93917dcf59a15ac5c6d46d958bbfca06952fc - SHA-1:
524481482b18d3b6e2b866496119bd2bf99cda05 - MD5:
049b713a5352cac048c3d274e44eb649 - imphash:
ffe3cc63e5a1efb4d2f4cc004c584646 - ssdeep:
196608:4pJf7vDbHx4yfi4NNpFV/YkE+YHDJ/SR2OuAuIDxRGBBrG+VXPWgMF:SJfjPHx474edHDoiAuxteF - TLSH:
T1706D33309F7D58B8CD8724A1C9306CAD9406F66BD7EF8655143980AB4187B3BC2706BE - Submitted as: bae3d3241e4986bdc2e52ea303e93917dcf59a15ac5c6d46d958bbfca06952fc
- File type: pe · Size: 13098776 bytes
- Verdict: suspicious (58/100) · Family: Sabsik
Detections (2 of 51 engines)
- Microsoft Defender: Trojan:Win32/Sabsik.FL.B!ml
- Kaspersky (KVRT): HEUR:Trojan-Downloader.Win32.Bitser.gen
Why this verdict
The suspicious score of 58/100 is the fusion of 2 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Sabsik.FL.B!ml (rule
Trojan:Win32/Sabsik.FL.B!ml) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: http://nsis.sf.net/NSIS_Error - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://nsis.sf.net/NSIS_Error
Embedded domains
- nsis.sf.net
- t.ml
- x.tw
- 3.ch
- 9q.tk
- 6.co
- 4.gq
- 3b.kr
File paths
- N:\(
More Sabsik samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report