MALICIOUS — 104_EarthKrahang_20240404.bin
MALICIOUS — 104_EarthKrahang_20240404.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Shadowpad family. 5 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0ff80e4db32d1d45a0c2afdfd7a1be961c0fbd9d43613a22a989f9024cc1b1e9 - SHA-1:
4826fe7edbbfe546253c168e0f652e1500bb70bc - MD5:
549d5b936e77f1067feb4e395f6f7b61 - imphash:
6a407cef00572710348b8f1c81e1baa3 - ssdeep:
3072:DBIcU80AlD88l7B4bddN05CYDXtMAkRY2d:DdU80AlDvlmdMid - TLSH:
T14E3ABE52C82A8254F2F6D440AD044F0F9071E1AFA6FE58AC06D7ED2D76E38EBA473055 - Submitted as: 104_EarthKrahang_20240404.bin
- File type: pe · Size: 100352 bytes
- Verdict: malicious (100/100) · Family: Shadowpad
Detections (5 of 51 engines)
- ClamAV (daily): {MD5}bin.loader.shadowpad.7431.UNOFFICIAL
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Cyble Vision: Cyble Vision: Deed RAT
- Microsoft Defender: Trojan:Win32/Malgent!MSR
- Emsisoft (Emergency Kit): Gen:Variant.Shadowpad.18
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged {MD5}bin.loader.shadowpad.7431.UNOFFICIAL (rule
{MD5}bin.loader.shadowpad.7431.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Cyble Vision flagged Cyble Vision: Deed RAT (rule
Cyble Vision: Deed RAT) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Malgent!MSR (rule
Trojan:Win32/Malgent!MSR) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Shadowpad.18 (rule
Gen:Variant.Shadowpad.18) - engine signal, weight 0.55, confidence 0.85 - Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
35 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- none
More Shadowpad samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report