MALICIOUS — 02479b50896ebe3d90514056603edb2ba16394bfe2249e1eca795667f8ca1508.exe
MALICIOUS — 02479b50896ebe3d90514056603edb2ba16394bfe2249e1eca795667f8ca1508.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the Sabsik family. 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
02479b50896ebe3d90514056603edb2ba16394bfe2249e1eca795667f8ca1508 - SHA-1:
23a2658314925b0415ca5d0d1ace75dcd46afed9 - MD5:
d20a462ee82fc009d69338c62a759272 - imphash:
83fa772670ac674cd68ff73f3ef04802 - ssdeep:
768:NpM+/0vaXDiTLlGCI0App3vWSph6koM3R+qsq:LCEiTLXA3/fp4koUR+v - TLSH:
T12C34FDCE95227750D72D6935574BD6FE9020B0E42A71BA0E5C11C07A28D2033FDF69AE - Submitted as: 02479b50896ebe3d90514056603edb2ba16394bfe2249e1eca795667f8ca1508.exe
- File type: pe · Size: 55296 bytes
- Verdict: malicious (93/100) · Family: Sabsik
Detections (3 of 53 engines)
- Microsoft Defender: Trojan:Win32/Sabsik.EN.A!ml
- Emsisoft (Emergency Kit): Gen:Variant.Worm.Phorpiex.90
- Kaspersky (KVRT): HEUR:Trojan-Banker.Win32.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 93/100 is the fusion of 7 weighted signals:
- Memory forensics: 5 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 7704) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Win32/Sabsik.EN.A!ml (rule
Trojan:Win32/Sabsik.EN.A!ml) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Worm.Phorpiex.90 (rule
Gen:Variant.Worm.Phorpiex.90) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: 178.16.54.109 - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
14243 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- searchapp.bundleassets.example
- desktop-hsgcbep
- dns.msftncsi.com
- config.edge.skype.com
- www.bing.com
- msedge.api.cdp.microsoft.com
- aps.prod.windows.com
- edge.microsoft.com
- ecs.office.com
- g.live.com
- fs.microsoft.com
- self.events.data.microsoft.com
- www.msftncsi.com
- geo.prod.do.dsp.mp.microsoft.com
- geover.prod.do.dsp.mp.microsoft.com
- settings-win.data.microsoft.com
- watson.events.data.microsoft.com
- 192.168.122.108
- 192.168.122.255
Embedded domains
- www.msftconnecttest.com
- searchapp.bundleassets.example
- dns.msftncsi.com
- config.edge.skype.com
- www.bing.com
- msedge.api.cdp.microsoft.com
- aps.prod.windows.com
- edge.microsoft.com
- ecs.office.com
- g.live.com
- fs.microsoft.com
- self.events.data.microsoft.com
- www.msftncsi.com
- geo.prod.do.dsp.mp.microsoft.com
- geover.prod.do.dsp.mp.microsoft.com
- settings-win.data.microsoft.com
- watson.events.data.microsoft.com
Embedded IP addresses
- 178.16.54.109
File paths
- X:\:`:d:h:l:p:t:x:
More Sabsik samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report