MALICIOUS — cygwin1.dll
MALICIOUS — cygwin1.dll is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100), attributed to the Container family. 6 of 55 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
103104a52e5293ce418944725df19e2bf81ad9269b9a120d71d39028e821499b - SHA-1:
52f26fa1aee39476f1c13438aec8bf969c78da45 - MD5:
a1c82ed072dc079dd7851f82d9aa7678 - imphash:
8f21c12c4e790805822951d4e4dcad1c - ssdeep:
49152:hGniafRcs02/oSqCmB5RMiCwDjUZQjuhKv+TLRlURxKc+tKaZrpu8dhcy1u7MHz:YniGRcsVJqCmB5RMiCwDIS4TBrppUy1J - TLSH:
T1135E4A72015B2351E6F5EE10A02988DCB063F154B1716EDE420B996D81D83F7FAF88E6 - Submitted as: cygwin1.dll
- File type: pe · Size: 2954293 bytes
- Verdict: malicious (94/100) · Family: Container
Detections (6 of 55 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- capa (capabilities): capability:credential-access
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- YARA: Yara-Rules community: YR_AntiDebug_Checks
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 94/100 is the fusion of 7 weighted signals:
- Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - access stored credentials (rule
access stored credentials) - capa signal, weight 0.50, confidence 0.80 - YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://cygwin.com/, https://cygwin.com/problems.html - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cygwin.com/
- https://cygwin.com/problems.html
Embedded domains
- dlfcn.cc
- environ.cc
- flock.cc
- fork.cc
- grp.cc
- hookapi.cc
- mount.cc
- ntea.cc
- path.cc
- cygwin.com
- pinfo.cc
- thread.cc
- quotactl.cc
- resource.cc
- setlsapwd.cc
- shm.cc
- signal.cc
- sigproc.cc
- spawn.cc
- syscalls.cc
- sysconf.cc
- uinfo.cc
- base.cc
- clipboard.cc
- console.cc
File paths
- x:\cygwin\bin,
More Container samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report