MALICIOUS — baf7646505d57dd0f3d6511411a03e2bedc5f26b1a608bd2822953f6e3cb4cca
MALICIOUS — baf7646505d57dd0f3d6511411a03e2bedc5f26b1a608bd2822953f6e3cb4cca is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the Crypted family. 6 of 55 detection engines flagged it.
Identification
- SHA-256:
baf7646505d57dd0f3d6511411a03e2bedc5f26b1a608bd2822953f6e3cb4cca - SHA-1:
220335d66f59e38a476915d4d7562348f4afcf98 - MD5:
1c2fe1804d1a8facf0d64dc9f66437a2 - imphash:
62ec3dce1eba1b68f6a4511bb09f8c2c - ssdeep:
3072:KGCMWG68u1v3PPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPbPPqPPPPPPPPnPPPfP:KrMWeL/uZGZnbhR - TLSH:
T14F3C4A2AC6387A71DCE4B35C5508B81C89DAD461F3743ED0C46E63609B26D9FBB07268 - Submitted as: baf7646505d57dd0f3d6511411a03e2bedc5f26b1a608bd2822953f6e3cb4cca
- File type: pe · Size: 112640 bytes
- Verdict: malicious (87/100) · Family: Crypted
Detections (6 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): Win.Trojan.Crypted-28
- Microsoft Defender: Backdoor:Win32/Berbew.AA!MTB
- Emsisoft (Emergency Kit): GenPack:Generic.Dacic.1.Backdoor.Hangup.A.004BF035
- Trellix Stinger (McAfee): Trojan-FUGH!1C2FE1804D1A
- Kaspersky (KVRT): Trojan-Proxy.Win32.Qukart.vih
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypted-28 (rule
Win.Trojan.Crypted-28) - engine signal, weight 0.90, confidence 0.95 - Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Crypted samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report