SUSPICIOUS — f2a831e1e3f3a2f8696fb13f3c0c0d181889c729e9c8ba7555d4f8477cf60666
SUSPICIOUS — f2a831e1e3f3a2f8696fb13f3c0c0d181889c729e9c8ba7555d4f8477cf60666 is a zip sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (42/100), attributed to the Mydoom family. 5 of 24 detection engines flagged it.
Identification
- SHA-256:
f2a831e1e3f3a2f8696fb13f3c0c0d181889c729e9c8ba7555d4f8477cf60666 - SHA-1:
94c3a5e05444cc9c5a8c633ee523c884bab997dc - MD5:
b099e2171940e30a0af23eeb55aa9e18 - ssdeep:
384:tvxBbK26lj5Id8SpHx9jLhsznnVxA1WmP5w7GGCJlqqwMyN4fHdL:7v8IRRdsxq1DjJcqflV - TLSH:
T1212DE1D444603CAFC5B29A819C444A7CE1624FF150AA29CCDE1370651AFF5EFE2B5262 - Submitted as: f2a831e1e3f3a2f8696fb13f3c0c0d181889c729e9c8ba7555d4f8477cf60666
- File type: zip · Size: 29290 bytes
- Verdict: suspicious (42/100) · Family: Mydoom
Detections (5 of 24 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:Script/Wacatac.B!ml
- Emsisoft (Emergency Kit): Worm.Generic.24461
- Trellix Stinger (McAfee): W32/Mydoom.o.o@MM!zip
- Kaspersky (KVRT): Email-Worm.Win32.Mydoom.m
Why this verdict
The suspicious score of 42/100 is the fusion of 3 weighted signals:
- Embedded executable payload carved at offset 194 - static signal, weight 0.40, confidence 0.70
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 5 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Archive contents (1 executable)
This zip carries 1 extracted member, each analyzed as its own sample:
- readme.htm .pif -
ebbf9b45ed59430a486d17d916cfb647e20eec494488622bcac94e47a098bfb9
Dynamic analysis (linux)
864 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- ntp.ubuntu.com
- desktop-hsgcbep
- 250.255.255.239.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ff02::1:3
- 224.0.0.252
- 10.240.0.1
- 10.240.0.255
- 169.254.255.255
- ff02::16
- ff02::1:ff12:3456
- ff02::1
- ff02::fb
- 224.0.0.251
- 20.165.94.63 US · San Antonio · AS8075 Microsoft Corporation
- 185.125.190.58
- 224.0.0.22
Dropped files
- tmp_tmp.gIIc4qa4VT -
6a37b1f793003be7ebb46f5f54c0c7e99ad72d98f3547499aa1a630ba886e153
Embedded IP addresses
- 20.165.94.63
- 172.172.255.216
More Mydoom samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report