SUSPICIOUS — dfa9b97d309272bac217210f0a877f58734ee94945e4b2b61e9d91929b8c6a3a
SUSPICIOUS — dfa9b97d309272bac217210f0a877f58734ee94945e4b2b61e9d91929b8c6a3a is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 5 of 52 detection engines flagged it.
Identification
- SHA-256:
dfa9b97d309272bac217210f0a877f58734ee94945e4b2b61e9d91929b8c6a3a - SHA-1:
46ba33aee9771956dc538c45b42cdd4211d8eb29 - MD5:
3dd0e0281e9ac3bc9e2f52b43b6ba70f - imphash:
2e5467cba76f44a088d39f78c5e807b6 - ssdeep:
24576:3i7aWa3k6fL6mK6YNIeLxrVs9Cy48zTEwPN2SVAAwr0HR8OSRLy+E:3qad3kPSe1xs9CSzTEWNgDru8OYG9 - TLSH:
T1E65433C05FEBB76FD4E21003FF83AD6D26D8914468F8591429A188CA5F72D231294F79 - Submitted as: dfa9b97d309272bac217210f0a877f58734ee94945e4b2b61e9d91929b8c6a3a
- File type: pe · Size: 1129984 bytes
- Verdict: suspicious (35/100)
Detections (5 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:,,.xzzzzz
- Detect It Easy (packer/type): DIE:Enigma
- Microsoft Defender: Backdoor:MSIL/Bladabindi.AJ
- Emsisoft (Emergency Kit): Trojan.GenericKD.47383457
- Kaspersky (KVRT): UDS:Backdoor.MSIL.Bladabindi.bqvw
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Detect It Easy (packer/type) flagged DIE:Enigma (rule
DIE:Enigma) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:,,.xzzzzz, Enigma - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- M:\uA
- V:\8
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report