MALICIOUS — 003_All.ElectroRAT.bin
MALICIOUS — 003_All.ElectroRAT.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the ElectroRAT family. 7 of 51 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
18fd6b193be1d5416a3188f5d9e4047cca719fa067d7d0169cf2df5c7fed54c0 - SHA-1:
95fb90137086c731b84db0a1ce3f0d74d6931534 - MD5:
2a3b92f6180367306d750e59c9b6446b - imphash:
37feaa2c735711635bed71303ba0b945 - ssdeep:
3072:GK0YqBB9mUQ13o2vM2tD81JI0MBkuomh87I3pBSpvVFLm:GnrB9mUWdk26DIquom2dN - TLSH:
T120415DF8D7169144EB724E743A696D9DA1D6A0AE11FE4C0C1FA3F06E2343C8F94B0265 - Submitted as: 003_All.ElectroRAT.bin
- File type: pe · Size: 182784 bytes
- Verdict: malicious (100/100) · Family: ElectroRAT
Detections (7 of 51 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- Cyble Vision: Cyble Vision: ElectroRAT
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:Win32/Amadey.A!MTB
- Emsisoft (Emergency Kit): Trojan-Downloader.Agent
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- Cyble Vision flagged Cyble Vision: ElectroRAT (rule
Cyble Vision: ElectroRAT) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - Microsoft Defender flagged Trojan:Win32/Amadey.A!MTB (rule
Trojan:Win32/Amadey.A!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan-Downloader.Agent (rule
Trojan-Downloader.Agent) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 2 behavioral detection(s): Scheduled Task / Job [medium] (rule
tl-scheduled-task) - dynamic signal, weight 0.40, confidence 0.90 - Extracted Amadey config (0 C2) - engine signal, weight 0.45, confidence 0.60
- YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
18267 behavior events · 2 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- searchapp.bundleassets.example
- mynexa.io
- desktop-hsgcbep
- v10.events.data.microsoft.com
- settings-win.data.microsoft.com
- config.edge.skype.com
- login.live.com
- fd.api.iris.microsoft.com
- www.bing.com
- windows.msn.com
- officeclient.microsoft.com
- licensing.mp.microsoft.com
- dns.msftncsi.com
- watson.events.data.microsoft.com
- assets.msn.com
- g.live.com
- ecs.office.com
- edge.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/5854/files/b71ca022aff29fb8de24e20c1bc3bfa5e162e7a21d90019e666597b55818dc64 -
b71ca022aff29fb8de24e20c1bc3bfa5e162e7a21d90019e666597b55818dc64
Embedded domains
- inference.location.live.net
- mynexa.io
- aefd.nelreports.net
File paths
- D:\Mktmp\NL1\Release\NL1.pdb
- D:\:a:m:r:
- T:\:d:l:
- T:\:d:p:
More ElectroRAT samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report