MALICIOUS — 398e9138de13eaa5fb1c0370b8fe35289bd162139ff4aa41da0903608889ed1d
MALICIOUS — 398e9138de13eaa5fb1c0370b8fe35289bd162139ff4aa41da0903608889ed1d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the Dinwod family. 8 of 55 detection engines flagged it.
Identification
- SHA-256:
398e9138de13eaa5fb1c0370b8fe35289bd162139ff4aa41da0903608889ed1d - SHA-1:
6800e9809c25d5dc9296b21907f2e8aa5bc13aa3 - MD5:
c6e0d374ff12e41fe12e98ed21ca0966 - imphash:
406c785a6e2c6970c1e8ed62877e197b - ssdeep:
1536:+vQBeOGtrYS3srx93UBWfwC6Ggnouy8aGzwAAE:+hOmTsF93UYfwC6GIoutRhR - TLSH:
T1E634E17491E36B49DF38B0AE2A59D2EF7A106C11583B4ED433ADE11E9BAF01B41C7084 - Submitted as: 398e9138de13eaa5fb1c0370b8fe35289bd162139ff4aa41da0903608889ed1d
- File type: pe · Size: 53427 bytes
- Verdict: malicious (93/100) · Family: Dinwod
Detections (8 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Dinwod-9828955-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:UPX
- Microsoft Defender: Backdoor:MSIL/Bladabindi!pz
- Emsisoft (Emergency Kit): Trojan.Agent.EZHO
- Trellix Stinger (McAfee): Trojan-FPCQ!816035E0404F
- Kaspersky (KVRT): Trojan-Dropper.Win32.Dinwod.acqn
Why this verdict
The malicious score of 93/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Malware.Dinwod-9828955-0 (rule
Win.Malware.Dinwod-9828955-0) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:UPX (rule
DIE:UPX) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Dinwod samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report