MALICIOUS — 2f949a35bbec9867113832b21638f1105f2f5c2dd1eb13d19501f0d7a09d6edb
MALICIOUS — 2f949a35bbec9867113832b21638f1105f2f5c2dd1eb13d19501f0d7a09d6edb is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Porcupine family. 8 of 51 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
2f949a35bbec9867113832b21638f1105f2f5c2dd1eb13d19501f0d7a09d6edb - SHA-1:
0038ef9332b538883b216b13713718f1c3e9b5f4 - MD5:
8a9fdd6df5b091caa5e4769d64b1bf10 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
49152:BeAY/ypVWhpL4Ra1+f+O3B+vHRoeAqWgaSxgIb9mKshlgJQ5CtWBGtjB:bY/ypkToRmOR+vpAsaSqjvhlK/tWBG - TLSH:
T18D60CF3CDC72D6FEFF7F47E758020ACE2176782C18507883901D6B40D24965B2AB56AA - Submitted as: 2f949a35bbec9867113832b21638f1105f2f5c2dd1eb13d19501f0d7a09d6edb
- File type: pe · Size: 3777536 bytes
- Verdict: malicious (98/100) · Family: Porcupine
Detections (8 of 51 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:/%<q @
- ClamAV feed: SaneSecurity foxhole_generic: Porcupine.Malware.58887.UNOFFICIAL
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- Microsoft Defender: Trojan:Win32/Tiggre!rfn
- Emsisoft (Emergency Kit): Gen:Variant.Strictor.265545
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Porcupine.Malware.58887.UNOFFICIAL (rule
Porcupine.Malware.58887.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:/%<q @ - static signal, weight 0.25, confidence 0.55
- inject code into another process (rule
inject code into another process) - capa signal, weight 0.12, confidence 0.60
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
Embedded domains
- j.in
- schemas.microsoft.com
File paths
- d:\P
- S:\l
More Porcupine samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report