MALICIOUS — e237d433769f8f0df5e42da0f10f0bf1bb6db05f3b775f8378f9e80fedb9dc49
MALICIOUS — e237d433769f8f0df5e42da0f10f0bf1bb6db05f3b775f8378f9e80fedb9dc49 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Scar family. 6 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e237d433769f8f0df5e42da0f10f0bf1bb6db05f3b775f8378f9e80fedb9dc49 - SHA-1:
e4c908ec53ca15d9875f249860e674f1755823a4 - MD5:
e9c42481e330b040abd88f7c21f08155 - imphash:
3c0e70bfa5f73f1f1cef484e2bcb5bf8 - ssdeep:
1536:ozfMMkPZE1J7S6/PMj42VJEY4ujMepJtANuOAl0QQsIEySYndfc6QkAbtP:+fMNE1JG6XMk27EbpOthl0ZUed06QT9 - TLSH:
T1993ACF921290C331E5DB6D57E60AE7EDF987CC0E433079AE882B53796B85007E985347 - Submitted as: e237d433769f8f0df5e42da0f10f0bf1bb6db05f3b775f8378f9e80fedb9dc49
- File type: pe · Size: 99803 bytes
- Verdict: malicious (92/100) · Family: Scar
Detections (6 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:1614346,4900659
- ClamAV (daily): Win.Malware.Scar-7194361-0
- Detect It Easy (packer/type): DIE:tElock
- Microsoft Defender: Trojan:Win32/QQPass
- Emsisoft (Emergency Kit): GenPack:Generic.Dacic.AAD0835C.A.96BA6A41
- Kaspersky (KVRT): Trojan.Win32.Scar.oetk
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Malware.Scar-7194361-0 (rule
Win.Malware.Scar-7194361-0) - engine signal, weight 0.90, confidence 0.95 - Detect It Easy (packer/type) flagged DIE:tElock (rule
DIE:tElock) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: high-entropy-sections:1614346,4900659, tElock - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Scar samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report