MALICIOUS — ffc2b1bdef18377609fee5e7fc649a9bd2d44b33df44e16bbf05f24a802e381c
MALICIOUS — ffc2b1bdef18377609fee5e7fc649a9bd2d44b33df44e16bbf05f24a802e381c is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the Gamarue family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
ffc2b1bdef18377609fee5e7fc649a9bd2d44b33df44e16bbf05f24a802e381c - SHA-1:
7d8332bddc13f6d26627f96a7b5c6f0838af89c4 - MD5:
127723fb9581bb251b528d6e4e536191 - imphash:
29c4c5f8766667965cf6248336ce2ba0 - ssdeep:
3072:KW/Qc+sSxnTrGadgsFqZeo4pwkhUmZr3hPsOraS:KW/2sSxTrGvsFUejWyZr3hPswa - TLSH:
T14E4013AA665057DECDCFC761CC04C68F92A8574632F0EED40652D2E2F8389B3D2C9646 - Submitted as: ffc2b1bdef18377609fee5e7fc649a9bd2d44b33df44e16bbf05f24a802e381c
- File type: pe · Size: 172032 bytes
- Verdict: malicious (89/100) · Family: Gamarue
Detections (5 of 52 engines)
- ClamAV (daily): Win.Trojan.Gamarue-9832405-0
- Microsoft Defender: Trojan:Win32/Astaroth!pz
- Emsisoft (Emergency Kit): Trojan.Agent.EZWM
- Trellix Stinger (McAfee): Trojan-Shifu!127723FB9581
- Kaspersky (KVRT): Trojan-Banker.Win32.Shifu.eph
Why this verdict
The malicious score of 89/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Gamarue-9832405-0 (rule
Win.Trojan.Gamarue-9832405-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: 2.1.0.3 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded IP addresses
- 2.1.0.3
More Gamarue samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report