SUSPICIOUS — cf1fbffff73f6070e536e6e09644f9927dd53a257dc627f84f2240b22f36073f
SUSPICIOUS — cf1fbffff73f6070e536e6e09644f9927dd53a257dc627f84f2240b22f36073f is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (51/100), attributed to the VMProtect family. 6 of 55 detection engines flagged it.
Identification
- SHA-256:
cf1fbffff73f6070e536e6e09644f9927dd53a257dc627f84f2240b22f36073f - SHA-1:
c3f477254c0dde08f0eabdcbc916815a90816b4a - MD5:
0ca3a9fbc7e6edfb37f1e6ef5db5ed79 - imphash:
5e3037e8027c03026eb0d96b2c08d22d - ssdeep:
12288:WET7enAVM5Yjg8Bf+X8P9o2dI5R9WSDOqPHmTw:WpnhCgKPluJXeTw - TLSH:
T1264D236309155ED6E270C8ED6C4B4F3C07E989AE31A0BF9ECA90496D2B714C315274BD - Submitted as: cf1fbffff73f6070e536e6e09644f9927dd53a257dc627f84f2240b22f36073f
- File type: pe · Size: 576662 bytes
- Verdict: suspicious (51/100) · Family: VMProtect
Detections (6 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): Themida/VMProtect
- YARA: Yara-Rules community: YR_Packer_VMProtect
- Detect It Easy (packer/type): DIE:Turbo Linker
- Microsoft Defender: Trojan:Win32/Convagent.EM!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Barys.160809
- Kaspersky (KVRT): HEUR:Trojan.Win32.Convagent.gen
Why this verdict
The suspicious score of 51/100 is the fusion of 3 weighted signals:
- YARA: Yara-Rules community flagged YR_Packer_VMProtect (rule
YR_Packer_VMProtect) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Themida/VMProtect, high-entropy-sections:.vmp1, Turbo Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More VMProtect samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report