SUSPICIOUS — fccd86c3d7349d8f300aab8c197c410cef213f03ab33cce2b2a3a96051a0cc3f
SUSPICIOUS — fccd86c3d7349d8f300aab8c197c410cef213f03ab33cce2b2a3a96051a0cc3f is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (60/100), attributed to the VMProtect family. 4 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fccd86c3d7349d8f300aab8c197c410cef213f03ab33cce2b2a3a96051a0cc3f - SHA-1:
2aedd69d1a9832c71218f9be42979fc700bf4604 - MD5:
e779ce133e61dd2cf035798bd3d50040 - imphash:
1c14250e85d14e67fde181d96327c6f5 - ssdeep:
98304:6AUR8EVrUcgs6FxN+r8/6tOCvC3CMDVceldCTK7vkl3uCbv+Z5oWQ49:6AUZZUaPDT0CM+6r7vksC+Z5oa - TLSH:
T19564122F34559A60D27432800877E8FEC3526D1FC3D2119AA9CF2B0666FA85BC5D12ED - Submitted as: fccd86c3d7349d8f300aab8c197c410cef213f03ab33cce2b2a3a96051a0cc3f
- File type: pe · Size: 5454336 bytes
- Verdict: suspicious (60/100) · Family: VMProtect
Detections (4 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): Themida/VMProtect
- YARA: Yara-Rules community: YR_Packer_VMProtect
- Detect It Easy (packer/type): DIE:Microsoft C/C++ Runtime
- Kaspersky (KVRT): UDS:Trojan-PSW.Win32.Stealer.anro
MITRE ATT&CK
Why this verdict
The suspicious score of 60/100 is the fusion of 4 weighted signals:
- YARA: Yara-Rules community flagged YR_Packer_VMProtect (rule
YR_Packer_VMProtect) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft C/C++ Runtime (rule
DIE:Microsoft C/C++ Runtime) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: Themida/VMProtect, high-entropy-sections:.vmp1, Microsoft C/C++ Runtime - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- e9y.ml
- c.kr
- r.kr
File paths
- R:\@
More VMProtect samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report