SUSPICIOUS — bb71186aa5e8ce286c5e8698adf22aac802615856dbab846a88e740cb5ce4316.exe
SUSPICIOUS — bb71186aa5e8ce286c5e8698adf22aac802615856dbab846a88e740cb5ce4316.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 4 of 55 detection engines flagged it.
Identification
- SHA-256:
bb71186aa5e8ce286c5e8698adf22aac802615856dbab846a88e740cb5ce4316 - SHA-1:
85df2e4cafb6310b7430f9b69ba1d40f8b255562 - MD5:
3a4457475ca594ab4a17b8158d7d63c7 - imphash:
ccfb54bcbc17e40b0f7f4733f9c91004 - ssdeep:
49152:pitrizwS/XN5k2W6LPjElRxSJUO8/gvAiMCtq45NQHkwndRKwtQyKgY4NP0W:pWrc7fc29LjSTg7uiNQldRzI4NP0W - TLSH:
T1A860339250448163F423DCC93014E92D5E11ADC86676326E2A37D6E6F9127D3378EBC7 - Submitted as: bb71186aa5e8ce286c5e8698adf22aac802615856dbab846a88e740cb5ce4316.exe
- File type: pe · Size: 3806176 bytes
- Verdict: suspicious (35/100)
Source: MalwareBazaar · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (4 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): Themida/VMProtect
- Detect It Easy (packer/type): DIE:Windows Authenticode
- Microsoft Defender: Trojan:Win32/Malgent
- Emsisoft (Emergency Kit): Trojan.Generic.40360992
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Detect It Easy (packer/type) flagged DIE:Windows Authenticode (rule
DIE:Windows Authenticode) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Themida/VMProtect, high-entropy-sections: , , , ,.boot, Windows Authenticode - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2016/WindowsSettings
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://schemas.microsoft.com/SMI/2019/WindowsSettings
- https://sectigo.com/CPS0J
- http://crl.sectigo.com/SectigoPublicTimeStampingRootR46.crl0
- http://crt.sectigo.com/SectigoPublicTimeStampingRootR46.p7c0#
- http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl05
Embedded domains
- schemas.microsoft.com
- u.su
- l.ir
- e9.uk
- 1.ch
- cacerts.digicert.com
- crl3.digicert.com
- sectigo.com
- crl.sectigo.com
- crt.sectigo.com
- crl.usertrust.com
File paths
- f:\U;
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report