SUSPICIOUS — pp.exe
SUSPICIOUS — pp.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (57/100). 1 of 55 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
078163d5c16f64caa5a14784323fd51451b8c831c73396b967b4e35e6879937b - SHA-1:
3e2272b916da4be3c120d17490423230ab62c174 - MD5:
24a648a48741b1ac809e47b9543c6f12 - imphash:
89355c53da2bc6afb328de6ce50876e6 - ssdeep:
12288:LOO6oMlKDdwPDMlkw6Pph0lhSMXle+eO1HK+meynh5yRX3oRG72:LD9McwPDCkw6Bh0lhSMXlemqth5yRX3E - TLSH:
T1BE4F8DCE130DA765E976CB642D404E5E906AF0E661FD380C0ED7C13F66B2857E8B106A - Submitted as: pp.exe
- File type: pe · Size: 716176 bytes
- Verdict: suspicious (57/100)
Detections (1 of 55 engines)
- capa (capabilities): capability:credential-access
MITRE ATT&CK
Why this verdict
The suspicious score of 57/100 is the fusion of 3 weighted signals:
- access stored credentials (rule
access stored credentials) - capa signal, weight 0.50, confidence 0.80 - capa (capabilities) flagged capability:credential-access (rule
capability:credential-access) - engine signal, weight 0.35, confidence 0.70 - encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.microsoft.com/exporting
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
Embedded domains
- www.microsoft.com
- crl.microsoft.com
- technet.microsoft.com
- agreement.in
- change.to
- www.sysinternals.com
File paths
- c:\long
- R:\2
- D:\a\1\s\psexec\exe\Win32\Release\psexec.pdb
- D:\a\1\s\psexec\svc\Win32\Release\psexesvc.pdb
- G:\:f:
- T:\:d:l:t:
- R:\:
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report