MALICIOUS — 988d34095634001755ccca00ade9a279d2b43583e96c716e2aaa14d34a4a5704
MALICIOUS — 988d34095634001755ccca00ade9a279d2b43583e96c716e2aaa14d34a4a5704 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the Fileinfector family. 8 of 52 detection engines flagged it.
Identification
- SHA-256:
988d34095634001755ccca00ade9a279d2b43583e96c716e2aaa14d34a4a5704 - SHA-1:
2484085bd589c3d825d3c2e8fa411750a473c8b0 - MD5:
ddfac8d721d8f65102da678c085cbbe1 - imphash:
895fbb56c02c3d2bca3125cef5da8730 - File type: pe · Size: 3496328 bytes
- Verdict: malicious (96/100) · Family: Fileinfector
Detections (8 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Fileinfector-9832954-0
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: Trellix/McAfee ATR: ATR_Conti_Ransomware
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Detect It Easy (packer/type): DIE:UPX 3.96
- Kaspersky (KVRT): Virus.Win32.Lamer.ks
- Microsoft Defender: Trojan:Win32/Vindor!pz
Embedded URLs
- http://schemas.microsoft.com/windows/2014/11/printing/generatedkeywords
- http://schemas.microsoft.com/windows/2013/05/printing/printschemakeywordsv11
- http://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords
- http://www.w3.org/2001/XMLSchema
- http://www.w3.org/2001/XMLSchema-instance
- http://schemas.microsoft.com/2002/print/gdl/1.0
- http://schemas.microsoft.com/windows/2003/08/printing/printschemakeywordsW
- http://schemas.microsoft.com/windows/2003/08/printing/printschemaframework
- http://schemas.microsoft.com/windows/2013/12/printing/printschemaframework2
- http://schemas.microsoft.com/windows/2013/12/printing/printschemakeywordsv12
- http://schemas.microsoft.com/windows/2018/04/printing/printschemakeywords/Ipp
- http://schemas.microsoft.com/windows/2005/03/printing/bidi
- http://schemas.microsoft.com/windows/2011/08/printing/devmodemap
- http://schemas.microsoft.com/2003/print/asyncui/v1/request
- http://schemas.microsoft.com/windows/2011/08/printing/queueproperties
- http://schemas.microsoft.com/windows/2025/06/printing/printschemakeywordsv13
- http://www.w3.org/XML/1998/namespace
- http://schemas.microsoft.com/windows/printing/oemdriverpt
Embedded domains
- schemas.microsoft.com
- www.w3.org
- tartalmazhat.ua
File paths
- X:\:`:d:h:l:p:t:x:
- X:\:l:p:
- T:\:d:l:t:
- L:\:`:d:x:
- X:\:d:h:p:t:
- X:\:`:d:h:l:t:
- T:\:d:h:l:t:x:
- X:\:l:p:t:x:
- X:\:`:d:l:p:t:x:
- X:\:`:d:h:l:p:x:
- X:\:h:l:p:t:x:
- V:\:b:h:l:
- B:\:h:
- L:\:h:p:
- T:\:d:l:x:
- T:\:d:l:
- L:\:l:
More Fileinfector samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report