MALICIOUS — 0801cc4027f04d3c76685aa353e5b362b8ce2f0578e4d2f7b8420ecca74e6ef3
MALICIOUS — 0801cc4027f04d3c76685aa353e5b362b8ce2f0578e4d2f7b8420ecca74e6ef3 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Aenjaris family. 8 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
0801cc4027f04d3c76685aa353e5b362b8ce2f0578e4d2f7b8420ecca74e6ef3 - SHA-1:
266d3ca39f938744df6f08d1ca6a469edea97629 - MD5:
045ef870b1b0652d3a83bf0b1f7ddb19 - imphash:
9eaf507f35950059e03270d84d93e868 - ssdeep:
98304:oQtc40et4RF3NRc95rZBabIpVAUZSErPhJZYu7jXbwcp136Wv3Q8+xv6N74GvSLH:vlCb2B86AiPrZJSu7bbwQ136Q3Q8+hsq - TLSH:
T15364333E27E58B8BD6F1F2354C8592CD51E764A182FE18C7049BC516A7C2D83E43A3A1 - Submitted as: 0801cc4027f04d3c76685aa353e5b362b8ce2f0578e4d2f7b8420ecca74e6ef3
- File type: pe · Size: 5101616 bytes
- Verdict: malicious (99/100) · Family: Aenjaris
Detections (8 of 53 engines)
- capa (capabilities): capability:collection/keylog
- MalwareAnalyser heuristics (entropy/packer): PureBasic
- ClamAV (daily): Win.Trojan.Agent-351851
- Detect It Easy (packer/type): DIE:PureBasic
- Microsoft Defender: TrojanDropper:Win32/Aenjaris.CL!bit
- Emsisoft (Emergency Kit): Trojan.Dropper.XWT
- Trellix Stinger (McAfee): Trojan-FKZY!045EF870B1B0
- Kaspersky (KVRT): Trojan-Dropper.Win32.Agent.fqvk
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Agent-351851 (rule
Win.Trojan.Agent-351851) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 4 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 6500) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged TrojanDropper:Win32/Aenjaris.CL!bit (rule
TrojanDropper:Win32/Aenjaris.CL!bit) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Dropper.XWT (rule
Trojan.Dropper.XWT) - engine signal, weight 0.55, confidence 0.85 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Detect It Easy (packer/type) flagged DIE:PureBasic (rule
DIE:PureBasic) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: PureBasic - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
960 behavior events · 1 ATT&CK techniques · 7 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- www.bing.com
- config.edge.skype.com
- dns.msftncsi.com
- to-do.microsoft.com
- ctldl.windowsupdate.com
- settings-win.data.microsoft.com
- tas02.sls.update.microsoft.com
- staging.to-do.microsoft.com
- edge.microsoft.com
- watson.events.data.microsoft.com
- aps.prod.windows.com
- ecs.office.com
Dropped files
- /opt/CAPEv2/storage/analyses/4600/files/454392960264b7e3cacde193b351bea75ba951b0fa0d8fb4cb652f962865c344 -
454392960264b7e3cacde193b351bea75ba951b0fa0d8fb4cb652f962865c344 - /opt/CAPEv2/storage/analyses/4600/files/df897f4bbf419b19e54fc4c69b415bd673abdfe20be28cab757916deecdbe927 -
df897f4bbf419b19e54fc4c69b415bd673abdfe20be28cab757916deecdbe927 - /opt/CAPEv2/storage/analyses/4600/files/a5e1c433dcce0bd6a3b6ed776b710a1b52a87e26615a342c560e0457be455604 -
a5e1c433dcce0bd6a3b6ed776b710a1b52a87e26615a342c560e0457be455604 - /opt/CAPEv2/storage/analyses/4600/files/bf8dfe0ff0e56358567083838178e079f1f3fd3cd87a84ffdce7902e97288bc8 -
bf8dfe0ff0e56358567083838178e079f1f3fd3cd87a84ffdce7902e97288bc8 - /opt/CAPEv2/storage/analyses/4600/files/8e11d297b28fe4dc73eed0d37ddca4d420d1ed6517431eed242eab728de78835 -
8e11d297b28fe4dc73eed0d37ddca4d420d1ed6517431eed242eab728de78835 - /opt/CAPEv2/storage/analyses/4600/files/23daec57e17f25ccf62cb0806579d54b27921b3009745e5d72b90cab1ff3f31f -
23daec57e17f25ccf62cb0806579d54b27921b3009745e5d72b90cab1ff3f31f - /opt/CAPEv2/storage/analyses/4600/files/e2dc30d6705e0d094fbc9e77c9e9b971ac99e09b507cffcd16fded0c1cbea452 -
e2dc30d6705e0d094fbc9e77c9e9b971ac99e09b507cffcd16fded0c1cbea452
Embedded domains
- 7.fr
- z.fi
- staging.to-do.officeppe.com
File paths
- P:\}~
- a:\d^a)
- m:\d
More Aenjaris samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report