MALICIOUS — EquationDrug_4556CE5EB007AF1DE5BD3B457F0B216D
MALICIOUS — EquationDrug_4556CE5EB007AF1DE5BD3B457F0B216D is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the EQUATIONDRUG family. 7 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1b0eb1a1591140175d1ac111a98c89472b196599baf13ef67ee7f63d0052b00e - SHA-1:
61fab1b8451275c7fd580895d9c68e152ff46417 - MD5:
4556ce5eb007af1de5bd3b457f0b216d - imphash:
a13f7af5e7f1875615725d3be04d90ca - ssdeep:
6144:AAFu9SAEL40YPY1fD8oqA3okebXYrOG7nbxaf4kKAT0UAUEgEzgxZ4xCo:AysSAEL4qfNOG7damAT0ALEE4ko - TLSH:
T1F7481210C20AA794F562696E3803AC4CF48B53FEDB8054A61D93EBBD3DDA9273135C25 - Submitted as: EquationDrug_4556CE5EB007AF1DE5BD3B457F0B216D
- File type: pe · Size: 380928 bytes
- Verdict: malicious (100/100) · Family: EQUATIONDRUG
Detections (7 of 51 engines)
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- ClamAV feed: SaneSecurity foxhole_generic: Sanesecurity.Rogue.EquationAPT.6.UNOFFICIAL
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Cyble Vision: Cyble Vision: EQUATIONDRUG
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:Win32/Eqtonapt.A!rfn
- Emsisoft (Emergency Kit): Gen:Variant.Jaik.88210
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 10 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Sanesecurity.Rogue.EquationAPT.6.UNOFFICIAL (rule
Sanesecurity.Rogue.EquationAPT.6.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Cyble Vision flagged Cyble Vision: EQUATIONDRUG (rule
Cyble Vision: EQUATIONDRUG) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 6 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 7768) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Win32/Eqtonapt.A!rfn (rule
Trojan:Win32/Eqtonapt.A!rfn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Jaik.88210 (rule
Gen:Variant.Jaik.88210) - engine signal, weight 0.55, confidence 0.85 - Contacted 44 external host(s) at runtime (24 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
399 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- www.bing.com
- tas02.sls.update.microsoft.com
- settings-win.data.microsoft.com
- config.edge.skype.com
- ctldl.windowsupdate.com
- to-do.microsoft.com
- dns.msftncsi.com
- officeclient.microsoft.com
- ocsp.digicert.com
- v20.events.data.microsoft.com
- oneocsp.microsoft.com
- odc.officeapps.live.com
- aps.prod.windows.com
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/92621512-d997-4742-9ae0-db0593ed93c6/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/92621512-d997-4742-9ae0-db0593ed93c6?P1=1785976274&P2=404&P3=2&P4=aVG%2fsdcwWPubf6n3tspYP9SfOZ7e00yPGdeFNvKoZrtHLVeBe6VWaokmMzcUz44R3hLuzImEk3bAf9UQGSUF6w%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/095b6cce-5952-42aa-a19f-9268ce8ce016/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/095b6cce-5952-42aa-a19f-9268ce8ce016?P1=1785976359&P2=404&P3=2&P4=V7SURw%2bfKsl0UaKTfVB90Z9T7sbbRAyS3P%2f87rM2vUQhB5R1rZnc4Z3LSWgSvErKiBPgMxW3PhNM9bjLITHb1g%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://192.168.122.112:64188/>V]\x00U
Embedded domains
- staging.to-do.officeppe.com
- oneclient.sfx.ms
Embedded IP addresses
- 135.232.92.137
- 23.33.238.104
- 48.211.4.16
- 150.171.22.17
- 23.40.52.85
- 4.150.223.113
- 20.231.239.246
- 13.69.116.108
- 40.99.133.210
- 52.123.128.14
- 52.98.140.18
- 131.253.33.203
- 52.98.143.114
- 23.11.37.157
- 135.234.160.245
- 74.178.240.51
- 104.208.16.94
- 4.150.223.112
- 203.26.79.13
- 52.123.252.247
- 150.171.28.11
- 172.64.154.167
- 135.233.95.80
- 151.101.30.172
- 57.155.101.212
More EQUATIONDRUG samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report