MALICIOUS — bf316f51d0c345d61eaee3940791b64e81f676e3bca42bad61073227bee6653c
MALICIOUS — bf316f51d0c345d61eaee3940791b64e81f676e3bca42bad61073227bee6653c is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the Mydoom family. 7 of 52 detection engines flagged it.
Identification
- SHA-256:
bf316f51d0c345d61eaee3940791b64e81f676e3bca42bad61073227bee6653c - SHA-1:
e858c206d2d1542a79936cb00d85da853bfc95e2 - MD5:
b0fe74719b1b647e2056641931907f4a - imphash:
db53d96991d2edfe7441be1b61e466f4 - ssdeep:
192:tZWNqWKIzebvOZnzCj6juhEJS3/Uf/tpfmG62X9f3:tZ6qWTYvczfahX/UHtF6e9f3 - TLSH:
T111207B00417298ACCAD86D7278AE8ADC40B353044EEF9EC54433624F4D0A57BBF8A339 - Submitted as: bf316f51d0c345d61eaee3940791b64e81f676e3bca42bad61073227bee6653c
- File type: pe · Size: 8192 bytes
- Verdict: malicious (91/100) · Family: Mydoom
Detections (7 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Worm.Mydoom-8
- Detect It Easy (packer/type): DIE:UPX 1.24
- Kaspersky (KVRT): Email-Worm.Win32.Mydoom.ux
- Microsoft Defender: Worm:Win32/Mydoom.O!backdoor
- Emsisoft (Emergency Kit): Trojan.AgentWDCR.IXJ
- Trellix Stinger (McAfee): W32/Mydoom.i.o@MM
Why this verdict
The malicious score of 91/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Worm.Mydoom-8 (rule
Win.Worm.Mydoom-8) - engine signal, weight 0.90, confidence 0.95 - Detect It Easy (packer/type) flagged DIE:UPX 1.24 (rule
DIE:UPX 1.24) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1, UPX 1.24 - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Mydoom samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report