MALICIOUS — e4a64bbd6bafe185f5ff012366ff30a3fe5ea605126b3948c278a10e0f781cbb
MALICIOUS — e4a64bbd6bafe185f5ff012366ff30a3fe5ea605126b3948c278a10e0f781cbb is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (85/100), attributed to the Tiggre family. 3 of 25 detection engines flagged it.
Identification
- SHA-256:
e4a64bbd6bafe185f5ff012366ff30a3fe5ea605126b3948c278a10e0f781cbb - SHA-1:
2a1fa1fa901fd5a8d36b789724172db5de4665f2 - MD5:
8ed08ef343ae4d13e40ed4f9c2403bef - imphash:
fcf1390e9ce472c7270447fc5c61a0c1 - ssdeep:
393216:pjw0TduZotU+7UsZeVwVatI1SZyhK+qtNECauMH4HX:pMCuZI7peVwIteSZyxq3EDDS - TLSH:
T12C70338D06797016E175EB506E426F9E409270F4C67DBE424743C8AFB6B708BA9C0A4F - Submitted as: e4a64bbd6bafe185f5ff012366ff30a3fe5ea605126b3948c278a10e0f781cbb
- File type: pe · Size: 17086159 bytes
- Verdict: malicious (85/100) · Family: Tiggre
Detections (3 of 25 engines)
- Microsoft Defender: Trojan:Win32/Tiggre!rfn
- Trellix Stinger (McAfee): PWS-FDEH!2F3DB97503A7
- Kaspersky (KVRT): HEUR:Trojan-PSW.MSIL.Disco.gen
Why this verdict
The malicious score of 85/100 is the fusion of 3 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Tiggre!rfn (rule
Trojan:Win32/Tiggre!rfn) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PWS-FDEH!2F3DB97503A7 (rule
PWS-FDEH!2F3DB97503A7) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan-PSW.MSIL.Disco.gen (rule
HEUR:Trojan-PSW.MSIL.Disco.gen) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
Embedded domains
- to9.uk
- schemas.microsoft.com
- in.gg
File paths
- D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb
- T:\:d:l:t:
- U:\b
- N:\U3
- r:\{p
- o:\,jY2
More Tiggre samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report