SUSPICIOUS — f863fab2d077573023509d6589d9a9f34d3ce5da7c9adac0fabd45ef43988a4d
SUSPICIOUS — f863fab2d077573023509d6589d9a9f34d3ce5da7c9adac0fabd45ef43988a4d is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (69/100), attributed to the Shellcode family. 5 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f863fab2d077573023509d6589d9a9f34d3ce5da7c9adac0fabd45ef43988a4d - SHA-1:
3776065fb078d5e7f0f034220a7c8f7a9195c922 - MD5:
28c58357cb463af2441d3261d9e3710d - imphash:
b556371bf3a4933eccaf19b708d3f250 - ssdeep:
24576:8pvxh4TO4OsVZRzALvx44ApeIknRC9EpXdPC+P+NvZLuksQtZaemNmWxNxxfc25b:K0TYsq24lICNPoNvtshwYzRDdYfa - TLSH:
T1526C4459B0D87530605839977888B5B77A6FB830435B3D158EEDA43980748CB2AC4FFA - Submitted as: f863fab2d077573023509d6589d9a9f34d3ce5da7c9adac0fabd45ef43988a4d
- File type: pe · Size: 11348506 bytes
- Verdict: suspicious (69/100) · Family: Shellcode
Detections (5 of 52 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): Gen:Trojan.ExplorerHijack.@xZ@aCm7D8oi
- Kaspersky (KVRT): HEUR:Trojan.Win32.Antavmu.gen
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The suspicious score of 69/100 is the fusion of 2 weighted signals:
- Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- N:\:j:x:
- P:\:x:
More Shellcode samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report