MALICIOUS — 255ef1d6f1da0b68446f349349d966c43ecbc96dca378836b9cc37abc013d671.exe
MALICIOUS — 255ef1d6f1da0b68446f349349d966c43ecbc96dca378836b9cc37abc013d671.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Egairtigado family. 6 of 53 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
255ef1d6f1da0b68446f349349d966c43ecbc96dca378836b9cc37abc013d671 - SHA-1:
a0c93473e81e9a37cc58fdc92f270a45b6898149 - MD5:
f7d8cd211e82f28a4ed52e1eef63a924 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
3072:spi9gspoKv2ayRbgn7lBW3Q/eb+/DE9LnC0eM+lmsolAIrRuw+mqv9j1MWLQ6:O+oKv2HCT/eboY9zf9+lDAA - TLSH:
T10F434F7E94095F22DFD33B21812574CC3B8EE8B5FDE51F1A576B52225A846BB00830E9 - Submitted as: 255ef1d6f1da0b68446f349349d966c43ecbc96dca378836b9cc37abc013d671.exe
- File type: pe · Size: 222208 bytes
- Verdict: malicious (98/100) · Family: Egairtigado
Source: MalwareBazaar · first seen 2026-07-29T00:00:00.000Z · SHA-256 verified
Detections (6 of 53 engines)
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:Win32/Egairtigado!rfn
- Emsisoft (Emergency Kit): Trojan.GenericKD.80987954
- Kaspersky (KVRT): UDS:Backdoor.MSIL.XWorm.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 11 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Egairtigado!rfn (rule
Trojan:Win32/Egairtigado!rfn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.GenericKD.80987954 (rule
Trojan.GenericKD.80987954) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Extracted XWorm config (0 C2) - engine signal, weight 0.45, confidence 0.60
- Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 9.0.1.4 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
17631 behavior events · 2 ATT&CK techniques · 1 dropped files.
Runtime network
- none
Dropped files
- /opt/CAPEv2/storage/analyses/5695/files/96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7 -
96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7
Embedded domains
- www.skyextractor.com
Embedded IP addresses
- 9.0.1.4
More Egairtigado samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report