MALICIOUS — f11bc43f99f2d7518365b726f3ce69ccff1d4e2ad6d2e7b3888c004efcacc80a.exe
MALICIOUS — f11bc43f99f2d7518365b726f3ce69ccff1d4e2ad6d2e7b3888c004efcacc80a.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100). 6 of 55 detection engines flagged it.
Identification
- SHA-256:
f11bc43f99f2d7518365b726f3ce69ccff1d4e2ad6d2e7b3888c004efcacc80a - SHA-1:
6cd50d34b2f5dabe1ab6e9c022bd472cff9e7fbd - MD5:
6518d397d3d18380d927cb8cbf458c22 - imphash:
6ed4f5f04d62b18d96b26d6db7c18840 - ssdeep:
6144:0S+pVt6Yh/o/k6HmX8nI6dicwKJYl4UKGaL/bgKu:P4VQFk6HddiTKJ59Ho - TLSH:
T1E746123260321422F1A6413B9D1C0C4D9EDF26C65B83CED7DA89E699A71C1435F7E12E - Submitted as: f11bc43f99f2d7518365b726f3ce69ccff1d4e2ad6d2e7b3888c004efcacc80a.exe
- File type: pe · Size: 295936 bytes
- Verdict: malicious (91/100)
Source: MalwareBazaar · first seen 2026-08-01T00:00:00.000Z · SHA-256 verified
Detections (6 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- Hash: abuse.ch ThreatFox: known-malicious-hash
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:Win32/Malgent
- Emsisoft (Emergency Kit): Gen:Variant.Vidar.79
- Kaspersky (KVRT): Trojan-PSW.Win32.Stealerc.vdn
Why this verdict
The malicious score of 91/100 is the fusion of 3 weighted signals:
- Hash: abuse.ch ThreatFox flagged known-malicious-hash (rule
known-malicious-hash) - engine signal, weight 0.90, confidence 0.95 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1, Microsoft Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report