CLEAN — db9a6212a71a30e39bc271811d30e8396530c84c14f424d314bb3f3a16c7ef6d
CLEAN — db9a6212a71a30e39bc271811d30e8396530c84c14f424d314bb3f3a16c7ef6d is a pe sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (25/100). 1 of 55 detection engines flagged it.
Identification
- SHA-256:
db9a6212a71a30e39bc271811d30e8396530c84c14f424d314bb3f3a16c7ef6d - SHA-1:
5b4cd0a20200cfff111fc26d6b8ceeab51077f2f - MD5:
8f8c9e945ac9ffdd1531ef6627e44d3f - imphash:
0ba39925cc55187335fdc1a6bb929fef - ssdeep:
384:+jk+VCAP6UWrLGBlCBbF+/+defODG7YNtnDgf2hZ+nquEe:+nV9P8vGB2FI+MfODG7gNUf2hoT - TLSH:
T1AF2B2A089381725FE2A7F8AD6153C99CA4057AB9F47400AF6313077B69BC2337D3A652 - Submitted as: db9a6212a71a30e39bc271811d30e8396530c84c14f424d314bb3f3a16c7ef6d
- File type: pe · Size: 23132 bytes
- Verdict: clean (25/100)
Detections (1 of 55 engines)
- LIEF (executable format parser): lief:invalid-authenticode
Why this verdict
The clean score of 25/100 is the fusion of 1 weighted signal:
- LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-cs-g1.crl05
- http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
Embedded domains
- cacerts.digicert.com
- crl4.digicert.com
- crl3.digicert.com
- www.digicert.com
File paths
- c:\jenkins\workspace\8-2-build-windows-amd64-cygwin\jdk8u281\880\build\windows-amd64\jdk\objs\keytool_objs\keytool.pdb
- C:\Program
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report