MALICIOUS — 373cd79b66b23f65fd93e10807b5217897e603c268ea14f8d8f3fc7806c66322.exe
MALICIOUS — 373cd79b66b23f65fd93e10807b5217897e603c268ea14f8d8f3fc7806c66322.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the PyInstaller family. 6 of 26 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
373cd79b66b23f65fd93e10807b5217897e603c268ea14f8d8f3fc7806c66322 - SHA-1:
98b0f6cd253a5abdfe2beeb0f078ed54b592f484 - MD5:
70ea4da4ecde228556d84c1e9df5d561 - imphash:
4ba3f97ab4d7908411ad46e497198ac7 - ssdeep:
393216:LlfJ4yaNJ39EGOPmMzeXnGXMCHWUjXBcuI3/PGTAI:LINdw9zeWXMb8XWH/O7 - TLSH:
T1166E3353264B7120D9F3E2A4DC204C9CD053F1591D32D4ED9D83E81FB48A97B88F6A6A - Submitted as: 373cd79b66b23f65fd93e10807b5217897e603c268ea14f8d8f3fc7806c66322.exe
- File type: pe · Size: 14313653 bytes
- Verdict: malicious (98/100) · Family: PyInstaller
Source: MalwareBazaar · first seen 2026-07-26T00:00:00.000Z · SHA-256 verified
Detections (6 of 26 engines)
- capa (capabilities): beacon to command-and-control
- MalwareAnalyser heuristics (entropy/packer): PyInstaller
- Detect It Easy (packer/type): DIE:PyInstaller
- Microsoft Defender: Trojan:Win32/Wacatac.B!ml
- Emsisoft (Emergency Kit): Gen:Variant.Yogi.14068
- Kaspersky (KVRT): HEUR:Trojan.Python.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 10 weighted signals:
- Memory forensics: 6 finding(s), e.g. RWX/private injected region in powershell.exe (pid 2612) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Win32/Wacatac.B!ml (rule
Trojan:Win32/Wacatac.B!ml) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Yogi.14068 (rule
Gen:Variant.Yogi.14068) - engine signal, weight 0.55, confidence 0.85 - beacon to command-and-control (rule
beacon to command-and-control) - capa signal, weight 0.45, confidence 0.80 - Contacted 32 external host(s) at runtime (17 HTTP) - network signal, weight 0.40, confidence 0.80
- Contacted 32 external host(s) at runtime (17 HTTP) - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:PyInstaller (rule
DIE:PyInstaller) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: PyInstaller - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
5238 behavior events · 1 ATT&CK techniques · 27 dropped files.
Runtime network
- www.msftconnecttest.com
- www.bing.com
- config.edge.skype.com
- desktop-hsgcbep
- officeclient.microsoft.com
- ctldl.windowsupdate.com
- v20.events.data.microsoft.com
- ocsp.digicert.com
- oneocsp.microsoft.com
- settings-win.data.microsoft.com
- odc.officeapps.live.com
- edge.microsoft.com
- v10.events.data.microsoft.com
- aps.prod.windows.com
- watson.events.data.microsoft.com
- dns.msftncsi.com
- tas02.sls.update.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- slscr.update.microsoft.com
- ecs.office.com
Dropped files
- /opt/CAPEv2/storage/analyses/3317/files/36585912e5eaf83ba9fea0631534f690ccdc2d7ba91537166fe53e56c221e153 -
36585912e5eaf83ba9fea0631534f690ccdc2d7ba91537166fe53e56c221e153 - /opt/CAPEv2/storage/analyses/3317/files/6435c679a3a3ff4f16708ebc43f7ca62456c110ac1ea94f617d8052c90c143c7 -
6435c679a3a3ff4f16708ebc43f7ca62456c110ac1ea94f617d8052c90c143c7 - /opt/CAPEv2/storage/analyses/3317/files/39f0fb52f42689f465b8a19f79ba8a07b198de5c10e8adc240745f6fdd835dc7 -
39f0fb52f42689f465b8a19f79ba8a07b198de5c10e8adc240745f6fdd835dc7 - /opt/CAPEv2/storage/analyses/3317/files/fc3b481684b926350057e263622a2a5335b149a0498a8d65c4f37e39dd90b640 -
fc3b481684b926350057e263622a2a5335b149a0498a8d65c4f37e39dd90b640 - /opt/CAPEv2/storage/analyses/3317/files/7e19f273192e0f5f7954e51e8799002d97bc2a480c08f6ab29d291ce79b38824 -
7e19f273192e0f5f7954e51e8799002d97bc2a480c08f6ab29d291ce79b38824 - /opt/CAPEv2/storage/analyses/3317/files/8463a42a1fbf907792849c4ebc62d94b959d341e754f86bf122a721b510a2844 -
8463a42a1fbf907792849c4ebc62d94b959d341e754f86bf122a721b510a2844 - /opt/CAPEv2/storage/analyses/3317/files/0108c1030c8aab8a7f6d43f2fa8c8f6bc3058b85f11a1a02d468e18bde0dea42 -
0108c1030c8aab8a7f6d43f2fa8c8f6bc3058b85f11a1a02d468e18bde0dea42 - /opt/CAPEv2/storage/analyses/3317/files/66a02016b64cc3da0cf6f5cd2df33abb08111afc641fa5e7ad668846acdb75f4 -
66a02016b64cc3da0cf6f5cd2df33abb08111afc641fa5e7ad668846acdb75f4 - /opt/CAPEv2/storage/analyses/3317/files/2693c7ee4fba55dc548f641c0cb94485d0e18596ffef16541bd43a5104c28b20 -
2693c7ee4fba55dc548f641c0cb94485d0e18596ffef16541bd43a5104c28b20 - /opt/CAPEv2/storage/analyses/3317/files/78e5994c29d8851f28b5b12d59d742d876683aea58eceea1fb895b2036cdcdeb -
78e5994c29d8851f28b5b12d59d742d876683aea58eceea1fb895b2036cdcdeb - /opt/CAPEv2/storage/analyses/3317/files/5b2561a572548139b00679b78010272af90f17e8d4ec9819ca32b267b8fa4eb6 -
5b2561a572548139b00679b78010272af90f17e8d4ec9819ca32b267b8fa4eb6 - /opt/CAPEv2/storage/analyses/3317/files/f63c6c7e71c342084d8f1a108786ca6975a52cefef8be32cc2589e6e2fe060c8 -
f63c6c7e71c342084d8f1a108786ca6975a52cefef8be32cc2589e6e2fe060c8 - /opt/CAPEv2/storage/analyses/3317/files/a5c6a329698490a035133433928d04368ce6285bb91a9d074fc285de4c9a32a4 -
a5c6a329698490a035133433928d04368ce6285bb91a9d074fc285de4c9a32a4 - /opt/CAPEv2/storage/analyses/3317/files/eff52743773eb550fcc6ce3efc37c85724502233b6b002a35496d828bd7b280a -
eff52743773eb550fcc6ce3efc37c85724502233b6b002a35496d828bd7b280a - /opt/CAPEv2/storage/analyses/3317/files/d9054ca1de232835741bd13f1149002ff921f9d4504819bb7b4ac1ba03c24c27 -
d9054ca1de232835741bd13f1149002ff921f9d4504819bb7b4ac1ba03c24c27
Embedded URLs
- http://schemas.microsoft.com/SMI/2016/WindowsSettings
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- schemas.microsoft.com
- 9.br
- 6.ga
- e.ru
- k.es
- 6.me
- i.us
- 8.ru
- oneclient.sfx.ms
- www.msftconnecttest.com
- www.bing.com
- config.edge.skype.com
- officeclient.microsoft.com
- ctldl.windowsupdate.com
- v20.events.data.microsoft.com
- ocsp.digicert.com
- oneocsp.microsoft.com
- settings-win.data.microsoft.com
- odc.officeapps.live.com
- edge.microsoft.com
- v10.events.data.microsoft.com
- aps.prod.windows.com
- watson.events.data.microsoft.com
- dns.msftncsi.com
- tas02.sls.update.microsoft.com
Embedded IP addresses
- 23.33.238.115
- 52.123.252.197
- 20.184.175.16
- 4.150.223.114
- 150.171.27.11
- 135.233.45.222
- 40.84.97.4
- 23.40.52.209
- 52.168.117.171
- 20.42.65.94
- 74.178.76.128
- 135.232.92.97
- 135.233.95.144
- 151.101.30.172
- 23.40.52.69
- 150.171.109.17
- 20.190.167.18
- 131.253.33.203
- 150.171.109.24
- 23.11.37.157
- 4.144.132.114
- 204.79.197.203
- 150.171.109.25
- 23.221.133.185
- 23.40.52.211
File paths
- u:\J4
- N:\:;
- y:\+,9
- B:\x;
More PyInstaller samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report