MALICIOUS — 00f41782b7ffda43f48a632433f8d70d2363600af03b02182009d72d825ec650.exe
MALICIOUS — 00f41782b7ffda43f48a632433f8d70d2363600af03b02182009d72d825ec650.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Egairtigado family. 7 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
00f41782b7ffda43f48a632433f8d70d2363600af03b02182009d72d825ec650 - SHA-1:
10c82fb76c490fc5970d71b603f99c4be7975d6f - MD5:
41d9eba31f341c2c2a4cfd6af4a94023 - imphash:
1aae8bf580c846f39c71c05898e57e88 - ssdeep:
49152:zykgwh4Y4/fCIPX9fH9N/MrbQp89ms4c7:uChH4/v5M4phk - TLSH:
T17D5E8DE16B9AB7E0CFF0F5E4D42087AC556B6D4293760DCD0793CC2152D6BA3083A686 - Submitted as: 00f41782b7ffda43f48a632433f8d70d2363600af03b02182009d72d825ec650.exe
- File type: pe · Size: 2910072 bytes
- Verdict: malicious (100/100) · Family: Egairtigado
Source: MalwareBazaar · first seen 2026-07-28T00:00:00.000Z · SHA-256 verified
Detections (7 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): Go
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Hash: abuse.ch ThreatFox: known-malicious-hash
- Detect It Easy (packer/type): DIE:Go
- Microsoft Defender: Trojan:Win32/Egairtigado!rfn
- Emsisoft (Emergency Kit): Trojan.GenericKD.80965681
- Kaspersky (KVRT): Trojan-PSW.Win32.Lumma.aduz
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- Hash: abuse.ch ThreatFox flagged known-malicious-hash (rule
known-malicious-hash) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Egairtigado!rfn (rule
Trojan:Win32/Egairtigado!rfn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.GenericKD.80965681 (rule
Trojan.GenericKD.80965681) - engine signal, weight 0.55, confidence 0.85 - Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - Contacted 35 external host(s) at runtime (6 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Go (rule
DIE:Go) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://go.dev/issue/66821 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: Go - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
15904 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 252.0.0.224.in-addr.arpa.
- milezcv.cyou
- 209.52.40.23.in-addr.arpa.
- 173.161.89.64.in-addr.arpa.
- desktop-hsgcbep
- www.msftconnecttest.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 251.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 1.0.240.10.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 209.52.40.23.in-addr.arpa
- 173.161.89.64.in-addr.arpa
- ctldl.windowsupdate.com
- 111.52.40.23.in-addr.arpa
- 250.255.255.239.in-addr.arpa
- config.edge.skype.com
Embedded URLs
- https://go.dev/issue/66821
Embedded domains
- abi.name
- godebugs.info
- go.dev
- 7.no
- atomic.store
- runtime.link
- unicode.to
- eq.io
- go.shape.int
- runtime.work
- unicode.cc
- unicode.cf
- unicode.cn
- unicode.co
- unicode.me
- unicode.nl
- unicode.no
- slifa.dev
- milezcv.cyou
Embedded IP addresses
- 23.40.52.85
- 23.40.52.209
- 104.208.16.94
- 150.171.22.17
- 57.155.104.224
- 23.40.52.111
- 72.145.35.96
- 52.148.114.188
- 20.190.142.167
- 151.101.30.172
- 23.221.133.182
- 52.168.117.169
- 72.154.7.96
- 52.182.143.212
- 85.210.196.11
- 40.84.97.4
- 4.247.188.224
- 172.172.255.218
- 4.150.223.106
- 52.178.17.3
- 85.210.193.152
- 64.89.161.173
- 172.215.188.225
- 20.42.179.204
- 4.247.188.233
File paths
- p:\d
- e:\fR
- i:\Dksv]
- X:\:
- X:\:`:d:h:l:p:t:x:
- P:\:p:
More Egairtigado samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report