MALICIOUS — virussign.com_53b5b409f2149c3dff9c2f4aee088540.vir
MALICIOUS — virussign.com_53b5b409f2149c3dff9c2f4aee088540.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100), attributed to the GenericFCA family. 3 of 52 detection engines flagged it.
Identification
- SHA-256:
dbf7d677811ff72aeadf08033dc7b7825a6d24d42374199a67d226d9827c7afe - SHA-1:
ed011205d8891814a5974b4947e79774cea4261d - MD5:
53b5b409f2149c3dff9c2f4aee088540 - imphash:
2ea479b0a5177e585eafc179914babec - ssdeep:
196608:cECVg/bwXq3RG9Q82hHQW5pubUGNjUbmehng:cECuDSAGi82FF2bFG9g - TLSH:
T10A68339773812454CE2C863BAF976A6D18BF78762D2DA397709E84B2404CCD7253720E - Submitted as: virussign.com_53b5b409f2149c3dff9c2f4aee088540.vir
- File type: pe · Size: 7530702 bytes
- Verdict: malicious (88/100) · Family: GenericFCA
Detections (3 of 52 engines)
- Microsoft Defender: Trojan:Win32/Wacatac.B!ml
- Emsisoft (Emergency Kit): Trojan.GenericFCA.8747
- Kaspersky (KVRT): HEUR:Trojan-Dropper.NSIS.Agent.gen
Why this verdict
The malicious score of 88/100 is the fusion of 4 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Wacatac.B!ml (rule
Trojan:Win32/Wacatac.B!ml) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.GenericFCA.8747 (rule
Trojan.GenericFCA.8747) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan-Dropper.NSIS.Agent.gen (rule
HEUR:Trojan-Dropper.NSIS.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: http://nsis.sf.net/NSIS_Error, 5.2.5.0 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://nsis.sf.net/NSIS_Error
Embedded domains
- r.ir
- a.ly
- nsis.sf.net
Embedded IP addresses
- 5.2.5.0
File paths
- r:\00f#1
- R:\S/
- G:\]b
- K:\g
- z:\Q
More GenericFCA samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report