MALICIOUS — 852_Win32.SofacyCarberp.bin
MALICIOUS — 852_Win32.SofacyCarberp.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Seduploader family. 8 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
12e6642cf6413bdf5388bee663080fa299591b2ba023d069286f3be9647547c8 - SHA-1:
5bb9f53636efafdd30023d44be1be55bf7c7b7d5 - MD5:
aa2cd9d9fc5d196caa6f8fd5979e3f14 - imphash:
91664671ee9c9cbe1fcbff9834f2d858 - ssdeep:
384:sVi4NHKBw6368eO2R/c70lH6rD9wWi/4zg4b7Kv0fu5pvYw2Djo0EwAtmtA4gWH:sL0us2R/c7AHoniSg4buv3pwwgjWap - TLSH:
T1F62E6C1D8A24EB44E757EB404C908CCDA0A86C5BB5BD2F5C44A28EEE73E94C7E15E058 - Submitted as: 852_Win32.SofacyCarberp.bin
- File type: pe · Size: 31744 bytes
- Verdict: malicious (100/100) · Family: Seduploader
Detections (8 of 52 engines)
- ClamAV (daily): {MD5}bin.trojan.seduploader.9263.UNOFFICIAL
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- Cyble Vision: Cyble Vision: Karagany
- Microsoft Defender: Trojan:Win32/Sofacy.B!dha
- Emsisoft (Emergency Kit): Gen:Variant.Sednit.62
- Trellix Stinger (McAfee): Seduploader!AA2CD9D9FC5D
- Kaspersky (KVRT): Trojan.Win32.Sofacy.ct
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged {MD5}bin.trojan.seduploader.9263.UNOFFICIAL (rule
{MD5}bin.trojan.seduploader.9263.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Cyble Vision flagged Cyble Vision: Karagany (rule
Cyble Vision: Karagany) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 3 finding(s), e.g. RWX/private injected region in WebExperienceH (pid 2568) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Win32/Sofacy.B!dha (rule
Trojan:Win32/Sofacy.B!dha) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Sednit.62 (rule
Gen:Variant.Sednit.62) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Seduploader!AA2CD9D9FC5D (rule
Seduploader!AA2CD9D9FC5D) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Sofacy.ct (rule
Trojan.Win32.Sofacy.ct) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- none
Dropped files
- /opt/CAPEv2/storage/analyses/6157/files/52e77fd8a0c1520b25ac84e6a054bbb375606a25febbb884ccd1bd0454444bc5 -
52e77fd8a0c1520b25ac84e6a054bbb375606a25febbb884ccd1bd0454444bc5
More Seduploader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report