CLEAN — bb2f88cabeff761d3bb4e720de6b494b14bddcdaeeb11258e628652ccbff4037.exe
CLEAN — bb2f88cabeff761d3bb4e720de6b494b14bddcdaeeb11258e628652ccbff4037.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (25/100). 4 of 55 detection engines flagged it.
Identification
- SHA-256:
bb2f88cabeff761d3bb4e720de6b494b14bddcdaeeb11258e628652ccbff4037 - SHA-1:
d0f3d95c63dbfcba888253f76f3a393030c151aa - MD5:
de03ab134d1cb176f26dfb57e21a4fe9 - imphash:
bb3ac2c21e02c68abcad237dc3fa6d00 - ssdeep:
3072:5qeXA/4yIbHkNPN+6H6xCYOigUE265FJ2x:5vdHkNFdaxmMElJc - TLSH:
T1D83F0769870A3321F2F6C80C5EA99DDC8D53F1AE1170954D8243F86ED49AF3399B212D - Submitted as: bb2f88cabeff761d3bb4e720de6b494b14bddcdaeeb11258e628652ccbff4037.exe
- File type: pe · Size: 152064 bytes
- Verdict: clean (25/100)
Source: MalwareBazaar · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (4 of 55 engines)
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): Trojan.GenericKD.81008409
- Kaspersky (KVRT): Trojan.Win64.Agent.smgxrs
Why this verdict
The clean score of 25/100 is the fusion of 1 weighted signal:
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://go.microsoft.com/fwlink/?linkid=798306
- https://aka.ms/dotnet-core-applaunch
- https://aka.ms/dotnet/app-launch-failed
Embedded domains
- go.microsoft.com
- aka.ms
File paths
- D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report