MALICIOUS — 022590d85dbc435ab9087ae0d741e8675aa46adec1a01b314e1689f7297c3025.exe
MALICIOUS — 022590d85dbc435ab9087ae0d741e8675aa46adec1a01b314e1689f7297c3025.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Aotera family. 7 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
022590d85dbc435ab9087ae0d741e8675aa46adec1a01b314e1689f7297c3025 - SHA-1:
bf00aeba99ab8afa468ff05d03cb7969334b7325 - MD5:
5e1372e7ebd1af23d561404f5292a3cc - imphash:
b1c022f21e313c400a3bd74350a836c9 - ssdeep:
98304:x4FImRLNQts597c+wizw7kNh44dLCgTiilznbt3fva62TrFkL+dycuVbM939blc:x4FPQts59wddUL9OEznRvtArFkL+Qb6 - TLSH:
T12261C03A022F3490F0FFA9A4BC4C6E8CD0E571799433AB558543DF0E5801967AEE646E - Submitted as: 022590d85dbc435ab9087ae0d741e8675aa46adec1a01b314e1689f7297c3025.exe
- File type: pe · Size: 3879936 bytes
- Verdict: malicious (97/100) · Family: Aotera
Source: MalwareBazaar · first seen 2026-07-28T00:00:00.000Z · SHA-256 verified
Detections (7 of 53 engines)
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): Microsoft Visual C/C++
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:Microsoft Visual C/C++
- Microsoft Defender: Trojan:Win64/Aotera.DSY!MTB
- Emsisoft (Emergency Kit): Trojan.Generic.40339359
- Kaspersky (KVRT): UDS:Trojan.Win64.Agent
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 11 weighted signals:
- Memory forensics: 3 finding(s), e.g. RWX/private injected region in rundll32.exe (pid 7628) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Win64/Aotera.DSY!MTB (rule
Trojan:Win64/Aotera.DSY!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Generic.40339359 (rule
Trojan.Generic.40339359) - engine signal, weight 0.55, confidence 0.85 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Visual C/C++ (rule
DIE:Microsoft Visual C/C++) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 4.2.1.0 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: Microsoft Visual C/C++ - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
131 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- searchapp.bundleassets.example
- onedsblobvmssprdcus03.centralus.cloudapp.azure.com
- onedsblobvmssprdcus04.centralus.cloudapp.azure.com
- www.msftconnecttest.com
- svc.ms-acdc-teams.office.com
- mr-b01.tm-azurefd.net
- onedscolprdwus52.westus.cloudapp.azure.com
- onedscolprdweu17.westeurope.cloudapp.azure.com
- onedscolprdweu00.westeurope.cloudapp.azure.com
- onedscolprdwus57.westus.cloudapp.azure.com
- onedscolprdeus05.eastus.cloudapp.azure.com
- onedscolprdcus67.centralus.cloudapp.azure.com
- onedscolprdneu51.northeurope.cloudapp.azure.com
- onedscolprdweu14.westeurope.cloudapp.azure.com
- onedscolprdwus68.westus.cloudapp.azure.com
- onedscolprdcus50.centralus.cloudapp.azure.com
- settings-prod-scus-2-tagged.southcentralus.cloudapp.azure.com
- onedscolprdeus15.eastus.cloudapp.azure.com
- onedscolprdwus73.westus.cloudapp.azure.com
- bg.microsoft.map.fastly.net
Embedded URLs
- https://aka.ms/nativeaot-compatibilit
Embedded domains
- aka.ms
- mr-b01.tm-azurefd.net
- aefd.nelreports.net
- ts-frontend.trafficmanager.net
Embedded IP addresses
- 4.2.1.0
- 23.33.238.102
More Aotera samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report