MALICIOUS — 10ff5772b6e9eaab24f54ac4a09cbc71d96c573b8d07e84891af0a2f1c08a35d
MALICIOUS — 10ff5772b6e9eaab24f54ac4a09cbc71d96c573b8d07e84891af0a2f1c08a35d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the STRATO family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
10ff5772b6e9eaab24f54ac4a09cbc71d96c573b8d07e84891af0a2f1c08a35d - SHA-1:
ef18c3c66f8000c3b5e6c355b3bb81cb54d33eea - MD5:
705b11fb377c26ac4e9af6de602f9675 - imphash:
fe7079d1e5599342ee2ef4d058c64043 - ssdeep:
196608:VZ/A0AcFn1YxOv5wANkZGFrxGOybiHmUBbSd/maDOOOs:VWcLZ+OrIOybiHmUBmd/mqOb - TLSH:
T10568330E15FEBAD4EEF59A931CF0519C68F8748BB06045B8C2FC0366418165B7ADE60E - Submitted as: 10ff5772b6e9eaab24f54ac4a09cbc71d96c573b8d07e84891af0a2f1c08a35d
- File type: pe · Size: 7919109 bytes
- Verdict: malicious (91/100) · Family: STRATO
Detections (5 of 52 engines)
- ClamAV (daily): Win.Trojan.Agent-1139220
- YARA: Stratosphere IPS: STRATO_Malicious_UserAgent
- Microsoft Defender: Backdoor:Win32/Shiz.DF!MTB
- Emsisoft (Emergency Kit): Trojan.GenericKD.38816690
- Kaspersky (KVRT): Trojan.Win32.Biws.b
Why this verdict
The malicious score of 91/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Agent-1139220 (rule
Win.Trojan.Agent-1139220) - engine signal, weight 0.90, confidence 0.95 - YARA: Stratosphere IPS flagged STRATO_Malicious_UserAgent (rule
STRATO_Malicious_UserAgent) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.baidu.com - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.baidu.com
Embedded domains
- www.baidu.com
- w.ru
- vv.ru
- 2g.it
- s.pw
- 7.su
- a.ua
File paths
- C:\Temp
- X:\:`:d:h:l:p:t:x:
- x:\X
- a:\wm
- R:\!oj
- q:\ZO
- l:\zu
- G:\_9)
- A:\b
- B:\Fy
- C:\EY=
More STRATO samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report