MALICIOUS — ebbf9b45ed59430a486d17d916cfb647e20eec494488622bcac94e47a098bfb9
MALICIOUS — ebbf9b45ed59430a486d17d916cfb647e20eec494488622bcac94e47a098bfb9 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the Mydoom family. 7 of 52 detection engines flagged it.
Identification
- SHA-256:
ebbf9b45ed59430a486d17d916cfb647e20eec494488622bcac94e47a098bfb9 - SHA-1:
2a8d2565bcb0fe5d5ce41fbf6617faf07737244c - MD5:
501d1afa6d02f293754ec71b851765c2 - imphash:
3a226e5a32d54c9874ff46ff138d22cb - ssdeep:
384:1vxBbK26lj5Id8SpHx9jLhsznnVxA1WmP5w7GGCJlqqwMyN4fHdY:Dv8IRRdsxq1DjJcqflC - TLSH:
T1CF2DE09440603CA3C1B29A819C444B7CE1624F3150BA29CCDE13B0A51BFF6EFE3B5262 - Submitted as: ebbf9b45ed59430a486d17d916cfb647e20eec494488622bcac94e47a098bfb9
- File type: pe · Size: 28864 bytes
- Verdict: malicious (91/100) · Family: Mydoom
Detections (7 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Worm.Mydoom-90
- Detect It Easy (packer/type): DIE:UPX 1.24
- Kaspersky (KVRT): Email-Worm.Win32.Mydoom.m
- Microsoft Defender: Worm:Win32/Mydoom.O@mm
- Emsisoft (Emergency Kit): Worm.Generic.24461
- Trellix Stinger (McAfee): Obfuscated-FGB!hb
Why this verdict
The malicious score of 91/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Worm.Mydoom-90 (rule
Win.Worm.Mydoom-90) - engine signal, weight 0.90, confidence 0.95 - Detect It Easy (packer/type) flagged DIE:UPX 1.24 (rule
DIE:UPX 1.24) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1, UPX 1.24 - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Mydoom samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report