CLEAN — d3998ff200687491baefd3038f06c9b891aabb3193be52fa14070c644c00b8e0.msi
CLEAN — d3998ff200687491baefd3038f06c9b891aabb3193be52fa14070c644c00b8e0.msi is a msi sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (32/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
d3998ff200687491baefd3038f06c9b891aabb3193be52fa14070c644c00b8e0 - SHA-1:
c1977685379884b09bbaf788da96bd19a962fef2 - MD5:
d821eb73ab51a02f5852c28af4b78c3a - ssdeep:
393216:d26ctwbS3glvEv87upq4GCAKUduCu3et11G0YF0niA:dCwbps06JA7dBIeTiA - TLSH:
T1A37223C287947C40EE86A5239566A93C5D7ED41DD2C93DDE22C5F68F2A09303DE32872 - Submitted as: d3998ff200687491baefd3038f06c9b891aabb3193be52fa14070c644c00b8e0.msi
- File type: msi · Size: 20328448 bytes
- Verdict: clean (32/100)
Source: MalwareBazaar · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Kaspersky (KVRT): Trojan.Script.Zapchast.abwr
Why this verdict
The clean score of 32/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: 9.9.9.9 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://www.globalsign.com/repository/0
- http://ocsp.globalsign.com/timestamprootr450D
- http://crl.globalsign.com/timestamprootr45.crl0
- http://ocsp2.globalsign.com/rootr60
- http://secure.globalsign.com/cacert/root-r6.crt06
- http://crl.globalsign.com/root-r6.crl0G
Embedded domains
- e.io
- u6.su
- 0.fi
- 8.gq
- c.gq
- 7.br
- 07.fr
- id.se
- 3.eu
- ap.pl
- c.br
- 2d.tv
- 6.fi
- y.ua
- child-path.jsbdnlxbuz.sh
- package.jsonxjlvqc6l.in
- gyp-tests.elgyp.elpzj4zgab.sh
- process-release.jsproxy.jsi5gpthwx.cc
- changelog.js5gr7wcoa.sh
- publish-tag.jsrelease.shrelocate.shwok35xdt.sh
- ocsp.globalsign.com
- secure.globalsign.com
- crl.globalsign.com
- www.globalsign.com
- ocsp2.globalsign.com
Embedded IP addresses
- 9.9.9.9
File paths
- o:\U`
- t:\}KV
- w:\3:
- Y:\sv
- N:\Mi8p
- G:\j
- z:\E7
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report