CLEAN — e330c728bf7db08a2d5d5ea533bed31362f536a8e870d5ae448f69010bbf0e07
CLEAN — e330c728bf7db08a2d5d5ea533bed31362f536a8e870d5ae448f69010bbf0e07 is a pe sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (32/100). 2 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e330c728bf7db08a2d5d5ea533bed31362f536a8e870d5ae448f69010bbf0e07 - SHA-1:
cd51e956bebc1ec744183c78028a63b656e96b66 - MD5:
5ba61fa32144403a0611073da3979520 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
384:3o3ZSrlc7cJjq3FJVw6Zpxezkpw+JfMT2bYcphYT:CMa7SIVrZpXpw+CCbYcr2 - TLSH:
T14A28E78E925D174FC3FBCC0A3061A45D5D9270CAE9F133685B88867625268279C372DF - Submitted as: e330c728bf7db08a2d5d5ea533bed31362f536a8e870d5ae448f69010bbf0e07
- File type: pe · Size: 17408 bytes
- Verdict: clean (32/100)
Detections (2 of 52 engines)
- capa (capabilities): capability:collection/keylog
- Emsisoft (Emergency Kit): Gen:Variant.Zusy.541800
MITRE ATT&CK
Why this verdict
The clean score of 32/100 is the fusion of 1 weighted signal:
- capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://docs.microsoft.com/windows/win32/fileio/maximum-file-path-limitation
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://schemas.microsoft.com/SMI/2016/WindowsSettings
Embedded domains
- docs.microsoft.com
- schemas.microsoft.com
File paths
- C:\Users\Owner\
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report