MALICIOUS — single.exe
MALICIOUS — single.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100), attributed to the Obfuscator family. 2 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d1a8d74aadb10bff4bfda144e68db3e087ec4fee82cd22df22839fd5435d0d37 - SHA-1:
93473126a9aa13834413c494ae5f62eec1016fde - MD5:
32d6644c5ea66e390070d3dc3401e54b - imphash:
e119b107e7442814a9853c4b22677273 - ssdeep:
3072:ZSiWQ4Bz4nkSlLTAwCNKS6pCZ3SQRYJhRUTOLWHUUMJhOFp+K:Z6d8PhTSSQ0hRUTOLIkh - TLSH:
T1933D02C59112CB25E9E20B57FA935A4E48D1B28A56A13848EC37C01C7F66C5BDF8B073 - Submitted as: single.exe
- File type: pe · Size: 129024 bytes
- Verdict: malicious (75/100) · Family: Obfuscator
Detections (2 of 51 engines)
- Microsoft Defender: VirTool:Win32/Obfuscator.AGE
- Emsisoft (Emergency Kit): Gen:Variant.Fugrafa.112441
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 3 weighted signals:
- Microsoft Defender flagged VirTool:Win32/Obfuscator.AGE (rule
VirTool:Win32/Obfuscator.AGE) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Fugrafa.112441 (rule
Gen:Variant.Fugrafa.112441) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
9 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- none
More Obfuscator samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report