MALICIOUS — 068fa74e4843dd0a7fd1488f262281e9b6b0e19d67eb8d52b20d63fda158fd3e.exe
MALICIOUS — 068fa74e4843dd0a7fd1488f262281e9b6b0e19d67eb8d52b20d63fda158fd3e.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100), attributed to the LODEINFO family. 6 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
068fa74e4843dd0a7fd1488f262281e9b6b0e19d67eb8d52b20d63fda158fd3e - SHA-1:
96ff9e92dc4d60b8f00d743e0d2614fbff612788 - MD5:
4b81cbcc057d46aa660722301d59efb5 - imphash:
d42595b695fc008ef2c56aabd8efd68e - ssdeep:
196608:KID6ZjzrBZgrXnbxnV6mrRBVXeVTZy+YYs5V6:KID6ZDBirrtV6mFBVXeVly+Zs5V6 - TLSH:
T1DF6CBFA456572111E1F4C808F031C0DCD87BB88AD6769F8D4387E57540EAFBFAAE10A9 - Submitted as: 068fa74e4843dd0a7fd1488f262281e9b6b0e19d67eb8d52b20d63fda158fd3e.exe
- File type: pe · Size: 11588680 bytes
- Verdict: malicious (94/100) · Family: LODEINFO
Source: MalwareBazaar · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (6 of 55 engines)
- YARA: JPCERT/CC: JPCERT_LODEINFO
- Hash: abuse.ch ThreatFox: known-malicious-hash
- LIEF (executable format parser): lief:invalid-authenticode
- Microsoft Defender: Trojan:Win32/Malgent
- Emsisoft (Emergency Kit): Trojan.GenericKD.81008367
- Kaspersky (KVRT): Trojan-PSW.Win64.Salat.pcb
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- Hash: abuse.ch ThreatFox flagged known-malicious-hash (rule
known-malicious-hash) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_LODEINFO (rule
JPCERT_LODEINFO) - engine signal, weight 0.35, confidence 0.70 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://go.dev/issue/66821, https://go.dev/pkg/crypto/rsa#hdr-Minimum_key_size, 5.4.62.5 - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://go.dev/issue/66821
- https://go.dev/pkg/crypto/rsa#hdr-Minimum_key_size
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/windows0
Embedded domains
- big.int
- abi.name
- pkix.name
- godebugs.info
- golang.org
- github.com
- 2github.com
- go.dev
- runtime.link
- reflectlite.name.name
- reflectlite.rtype.name
- unicode.to
- unicode.to
- eq.io
- go.shape.int
- eq.net
- hash.net
- exec.in
- eq.github.com
- eq.golang.org
- ny.uk
- www.microsoft.com
- crl.microsoft.com
Embedded IP addresses
- 5.4.62.5
- 4.32.5.4
- 52.5.4.72
- 5.4.82.5
- 5.4.102.5
- 4.112.5.4
- 1.1.1.1
File paths
- t:\Jkm
More LODEINFO samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report