MALICIOUS — 15c04c40236e4b8a2892e086fdcd296016de38a8a5284a13f2e1fdb0df949ed3
MALICIOUS — 15c04c40236e4b8a2892e086fdcd296016de38a8a5284a13f2e1fdb0df949ed3 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (81/100), attributed to the Wacatac family. 4 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
15c04c40236e4b8a2892e086fdcd296016de38a8a5284a13f2e1fdb0df949ed3 - SHA-1:
d51db0b4a1c134d5f0557f1b98e475204526ef04 - MD5:
7db8da17c12422be03717f3ee0784483 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
12288:xdyO4dSek4z5JWMLAm9MtpombcFftOTZH:PyO4nVDG3omwUH - TLSH:
T16C4AD1E5E63507E7CB5219071C05940FFA9700E890F927DC6912A252F8E1DEB2DA27BC - Submitted as: 15c04c40236e4b8a2892e086fdcd296016de38a8a5284a13f2e1fdb0df949ed3
- File type: pe · Size: 431616 bytes
- Verdict: malicious (81/100) · Family: Wacatac
Detections (4 of 55 engines)
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:Win32/Wacatac.B!ml
MITRE ATT&CK
Why this verdict
The malicious score of 81/100 is the fusion of 5 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Wacatac.B!ml (rule
Trojan:Win32/Wacatac.B!ml) - engine signal, weight 0.55, confidence 0.85 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 4.0.1.0, 70.52.71.222 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-sections:.text, Microsoft Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://docs.microsoft.com/windows/win32/fileio/maximum-file-path-limitation
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://schemas.microsoft.com/SMI/2016/WindowsSettings
Embedded domains
- docs.microsoft.com
- schemas.microsoft.com
Embedded IP addresses
- 4.0.1.0
- 70.52.71.222
File paths
- C:\Users\15813\source\repos\TakeMeIn\TakeMeIn\bin\Release\Dotfuscated\TakeMeIn.pdb
- C:\Windows\update.exe
- C:\file.png
- C:\Users\15813\AppData\Local\Google\Chrome\User
More Wacatac samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report