MALICIOUS — VESSEL PARTICULARS - MV SM TBN_Scanned.cab
MALICIOUS — VESSEL PARTICULARS - MV SM TBN_Scanned.cab is a archive sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the Bladabindi family. 4 of 53 detection engines flagged it.
Identification
- SHA-256:
fd953bd8c8a9af2d1a3f92ced394b41b0b9dcb12809ea754c06968b02f02902c - SHA-1:
ffe58fca8e18ca506ca86b6ca563dc7ad3c79055 - MD5:
ecba8457360b2a244be3268fcc3aac94 - ssdeep:
6144:Pm8db3YnWjCdVjsIDDQu9VEQtmNonOhMFfEkp9vxELtE8LFs4x+EDx:PmujzjmKA9VX4onOhYHexVxzx - TLSH:
T1944623802655C139AB94FC7611EE442FDD93B9FC17019CDAD0ADF85D8DBC2226D28A38 - Submitted as: VESSEL PARTICULARS - MV SM TBN_Scanned.cab
- File type: archive · Size: 306777 bytes
- Verdict: malicious (87/100) · Family: Bladabindi
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Win.Packed.Bladabindi-10017208-0
- Microsoft Defender: Trojan:MSIL/AgentTesla
- Kaspersky (KVRT): HEUR:Trojan.MSIL.Agent.gen
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Packed.Bladabindi-10017208-0 (rule
Win.Packed.Bladabindi-10017208-0) - engine signal, weight 0.90, confidence 0.95 - Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Archive contents (1 executable)
This archive carries 1 extracted member, each analyzed as its own sample:
- VESSEL PARTICULARS - MV SM TBN_Scanned.exe -
69df3b19d7e8d6efdead03281f2cb9aa262a123260c56171678d592fc264df20
More Bladabindi samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report