CLEAN — bb254fcf17fdbe8aa8848d8b5c6b0735e7c1a372d1bc418ec162e518727f095a
CLEAN — bb254fcf17fdbe8aa8848d8b5c6b0735e7c1a372d1bc418ec162e518727f095a is a pe sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (25/100). 1 of 55 detection engines flagged it.
Identification
- SHA-256:
bb254fcf17fdbe8aa8848d8b5c6b0735e7c1a372d1bc418ec162e518727f095a - SHA-1:
a72c8262ac8a4814a3774a4c388a5a0a2abdaaef - MD5:
8126ef2afa041aecef0033714e8d7369 - imphash:
0ba39925cc55187335fdc1a6bb929fef - ssdeep:
384:ijk+VCgP6Uj7PZpBbFvFEefyDG7YdiL75Dgf2h521cLsqgI:inVtPRVFNhfyDG7r5Uf2hY1I - TLSH:
T1392B2B099384725FE6A3F4AC70A68D8C640976F8F57100AF5213477B69F92337D39261 - Submitted as: bb254fcf17fdbe8aa8848d8b5c6b0735e7c1a372d1bc418ec162e518727f095a
- File type: pe · Size: 23112 bytes
- Verdict: clean (25/100)
Detections (1 of 55 engines)
- LIEF (executable format parser): lief:invalid-authenticode
Why this verdict
The clean score of 25/100 is the fusion of 1 weighted signal:
- LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-cs-g1.crl05
- http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
Embedded domains
- cacerts.digicert.com
- crl4.digicert.com
- crl3.digicert.com
- www.digicert.com
File paths
- c:\jenkins\workspace\8-2-build-windows-amd64-cygwin\jdk8u261\295\build\windows-amd64\jdk\objs\jjs_objs\jjs.pdb
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report