MALICIOUS — d6189085fd58281d1e911d42360f3c7a7621e2c33dd517107c969efc7482f91a
MALICIOUS — d6189085fd58281d1e911d42360f3c7a7621e2c33dd517107c969efc7482f91a is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100). 1 of 55 detection engines flagged it.
Identification
- SHA-256:
d6189085fd58281d1e911d42360f3c7a7621e2c33dd517107c969efc7482f91a - SHA-1:
b4c60ea308b594ccf6413436d283f01d1a056f4d - MD5:
ab63220b0c6dd1b347a9e933cd174b47 - imphash:
c452b207dc65baf117f06ff09c8fad54 - ssdeep:
6144:8NhHyz3IpNnYOEJUdmLJDBKJGE/iBcjSagsvINZcsFsgLPE/hnNB6Sh:0UzKNpEqdmLT0pKBZagUa3a6q - TLSH:
T10E5E326E4F5A59A2EC95A1CE3008D43DB0D1FAD5623A554ACF91C0AF05BF2136CB0DAC - Submitted as: d6189085fd58281d1e911d42360f3c7a7621e2c33dd517107c969efc7482f91a
- File type: pe · Size: 2970800 bytes
- Verdict: malicious (89/100)
Detections (1 of 55 engines)
- ClamAV (daily): Win.Malware.Genpack-9950982-0
Why this verdict
The malicious score of 89/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Malware.Genpack-9950982-0 (rule
Win.Malware.Genpack-9950982-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://www.gnu.org/software/coreutils/, http://translationproject.org/team/, http://gnu.org/licenses/gpl.html - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.gnu.org/software/coreutils/
- http://translationproject.org/team/
- http://gnu.org/licenses/gpl.html
- http://www.gnu.org/gethelp/
Embedded domains
- www.gnu.org
- translationproject.org
- gnu.org
- cygwin.com
- acrobat.com
File paths
- C:\Users\a.monaldo\Desktop
- C:\Users\a.monaldo\AppData\Local\Microsoft\Windows
- c:\windows\system32\imageres.dll
- c:\program
- c:\windows\system32\ntshrui.dll
- c:\install.exe
- c:\windows\explorer.exe
- c:\windows\system32\tsworkspace.dll
- c:\windows\system32\wmploc.dll
- c:\windows\system32\intl.cpl
- c:\windows\system32\icardres.dll
- c:\windows\branding\shellbrd\shellbrd.dll
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report