MALICIOUS — e5b88f166540d9ee2464df13462c72470b212c9d3531491aa38b9d74ff28358a
MALICIOUS — e5b88f166540d9ee2464df13462c72470b212c9d3531491aa38b9d74ff28358a is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100), attributed to the DarkKomet family. 3 of 52 detection engines flagged it.
Identification
- SHA-256:
e5b88f166540d9ee2464df13462c72470b212c9d3531491aa38b9d74ff28358a - SHA-1:
1d132e571d135ee30a4fc9c68c53160d1b3d6260 - MD5:
37437f6fff3069925aa2decb98070880 - imphash:
fcf1390e9ce472c7270447fc5c61a0c1 - ssdeep:
12288:IhqxSLo5C1Ps4XhiCmcF7JKTfrlzqRvCUwoJV8B:IHLmCiIh1mcnKTzRMxDJw - TLSH:
T1644E3943638CA1C5FE6A4E14D8E119ECE132A357162863A1E8A3F47D19E5C4F9F2350E - Submitted as: e5b88f166540d9ee2464df13462c72470b212c9d3531491aa38b9d74ff28358a
- File type: pe · Size: 682252 bytes
- Verdict: malicious (86/100) · Family: DarkKomet
Detections (3 of 52 engines)
- ClamAV (daily): Win.Trojan.DarkKomet-10027799-0
- Microsoft Defender: Trojan:Win32/Conteban.A!ml
- Kaspersky (KVRT): HEUR:Trojan.BAT.ForkBomb.gen
Why this verdict
The malicious score of 86/100 is the fusion of 1 weighted signal:
- ClamAV (daily) flagged Win.Trojan.DarkKomet-10027799-0 (rule
Win.Trojan.DarkKomet-10027799-0) - engine signal, weight 0.90, confidence 0.95
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
Embedded domains
- to9.uk
- schemas.microsoft.com
File paths
- D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb
- d:\;
- T:\:
- T:\:p:
More DarkKomet samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report