MALICIOUS — d0f963f80b6c53d7b5c2a8d1d09e647766bcc97db104ac95f4d25a05656fe659
MALICIOUS — d0f963f80b6c53d7b5c2a8d1d09e647766bcc97db104ac95f4d25a05656fe659 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100), attributed to the Berbew family. 3 of 25 detection engines flagged it.
Identification
- SHA-256:
d0f963f80b6c53d7b5c2a8d1d09e647766bcc97db104ac95f4d25a05656fe659 - SHA-1:
1249ad9a8e75aaae2aacbea915772ed20e3b992f - MD5:
07b488624625e42f8a4eb45a4277851c - imphash:
95e6f8741083e0c7d9a63d45e2472360 - ssdeep:
1536:JqJzQwW7PFlFEn1m0e9oGCC1nwkBinICTRG0oLz+cYAi:JqmFfMBMoGncIcRG05cYA - TLSH:
T1C23A28A399459189EFC8B7E62898A81DCFC0B14EACFD651F1974BC206C7C443641D2F6 - Submitted as: d0f963f80b6c53d7b5c2a8d1d09e647766bcc97db104ac95f4d25a05656fe659
- File type: pe · Size: 93184 bytes
- Verdict: malicious (72/100) · Family: Berbew
Detections (3 of 25 engines)
- Microsoft Defender: Backdoor:Win32/Berbew!pz
- Emsisoft (Emergency Kit): Backdoor.Hangup.B
- Kaspersky (KVRT): Trojan-Spy.Win32.Qukart.af
Why this verdict
The malicious score of 72/100 is the fusion of 2 weighted signals:
- Microsoft Defender flagged Backdoor:Win32/Berbew!pz (rule
Backdoor:Win32/Berbew!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Backdoor.Hangup.B (rule
Backdoor.Hangup.B) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- j:\L1
More Berbew samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report