MALICIOUS — fa1384e53fd5ba303423ccb5ea09aee03bfc16ca4487e528f3b4126c0d445cf1
MALICIOUS — fa1384e53fd5ba303423ccb5ea09aee03bfc16ca4487e528f3b4126c0d445cf1 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the Salgorea family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
fa1384e53fd5ba303423ccb5ea09aee03bfc16ca4487e528f3b4126c0d445cf1 - SHA-1:
bb47363baf108a04072fc3b2afb74ef108ec1804 - MD5:
baa0567f137a920843dbbd02ec47a6d2 - imphash:
95122753ea27818b35f9b51859e4c692 - ssdeep:
98304:emhd1UryeKKRAkfLIapAfkvCSEtYNRVLUjH5oxFbxCVLUjH5oxFbx:elqQA8XAfzdKVUjZEdCVUjZEd - TLSH:
T1F56233E543364B8DE0B5C0481F26224D8816D8D826FA25C6864FF12F73FEA9B1C52667 - Submitted as: fa1384e53fd5ba303423ccb5ea09aee03bfc16ca4487e528f3b4126c0d445cf1
- File type: pe · Size: 4453888 bytes
- Verdict: malicious (96/100) · Family: Salgorea
Detections (5 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.l2
- ClamAV (daily): Win.Trojan.Finfish-9787043-0
- Microsoft Defender: Trojan:Win32/Salgorea!pz
- Emsisoft (Emergency Kit): Trojan.Agent.GIKJ
- Kaspersky (KVRT): Trojan.Win32.Agent.xaktra
Why this verdict
The malicious score of 96/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Finfish-9787043-0 (rule
Win.Trojan.Finfish-9787043-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Salgorea!pz (rule
Trojan:Win32/Salgorea!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Agent.GIKJ (rule
Trojan.Agent.GIKJ) - engine signal, weight 0.55, confidence 0.85 - Packing/obfuscation: high-entropy-sections:.l2 - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
Embedded domains
- schemas.microsoft.com
File paths
- I:\hizh
- I:\fO
- H:\z~
- m:\w\C
More Salgorea samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report