MALICIOUS — 722_WMIGhost.bin
MALICIOUS — 722_WMIGhost.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the DangerousObject family. 5 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0dc2ab0ccf783fb39028326a7e8b0ba4eaa148020ec05fc26313ef2bf70f700f - SHA-1:
e3637e3c2275661047397365fb7bc7a8e7971777 - MD5:
77b645ef1c599f289f3d462a09048c49 - imphash:
20d9181db1cc5831c1bc73eca705cbd2 - ssdeep:
384:PdWYcnO5PQYnip9EYHmouy1y4dKKlUv6kHj:Pd481i7EYHmoFyGUvvj - TLSH:
T1D22C178976182E14E47FDB17C8C28E1E2553A7F034B20449F1C6D88AAB61CEB5C4D26E - Submitted as: 722_WMIGhost.bin
- File type: pe · Size: 24576 bytes
- Verdict: malicious (100/100) · Family: DangerousObject
Detections (5 of 52 engines)
- ClamAV (daily): Win.Trojan.Syndicasec-1
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
- Emsisoft (Emergency Kit): Gen:Variant.Graftor.372098
- Trellix Stinger (McAfee): Generic Trojan.hh
- Kaspersky (KVRT): UDS:DangerousObject.Multi.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Syndicasec-1 (rule
Win.Trojan.Syndicasec-1) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Syndicasec): 0dc2ab0ccf783fb39028326a7e8b0ba4eaa148020ec05fc26313ef2bf70f700f - dynamic signal, weight 0.80, confidence 0.90
- Memory forensics: 3 finding(s), e.g. RWX/private injected region in WebExperienceH (pid 6196) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Graftor.372098 (rule
Gen:Variant.Graftor.372098) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Generic Trojan.hh (rule
Generic Trojan.hh) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:DangerousObject.Multi.Generic (rule
UDS:DangerousObject.Multi.Generic) - engine signal, weight 0.55, confidence 0.85 - YARA: delivr.to detections flagged DLV_Maldoc_VBA_AutoExec (rule
DLV_Maldoc_VBA_AutoExec) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://127.0.0.1/sosblogs.xml - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- none
Dropped files
- /opt/CAPEv2/storage/analyses/6128/files/0e7f23cd1eb272af19a14fda7dd9763d6753c09ccb8f086413ac541843c97e8a -
0e7f23cd1eb272af19a14fda7dd9763d6753c09ccb8f086413ac541843c97e8a - /opt/CAPEv2/storage/analyses/6128/files/0dc2ab0ccf783fb39028326a7e8b0ba4eaa148020ec05fc26313ef2bf70f700f -
0dc2ab0ccf783fb39028326a7e8b0ba4eaa148020ec05fc26313ef2bf70f700f
Embedded URLs
- http://127.0.0.1/sosblogs.xml
Registry keys
- HKLM\\software\\microsoft\\windows\\currentVersion\\Explorer\\Shell
File paths
- C:\Server.log
More DangerousObject samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report