MALICIOUS — libwinpthread-1.dll
MALICIOUS — libwinpthread-1.dll is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (78/100), attributed to the execute family. 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3b9a3369e4fbc9f4336247ea11cf5df3b4c44066987ff20f5f6895addb052036 - SHA-1:
9b8bfbb4cb8bd2ba0e9b0c16957bf54936ee254a - MD5:
9e4d0677fa7e5996bb0558558f8250e0 - imphash:
b1c022f21e313c400a3bd74350a836c9 - ssdeep:
49152:TCKosFyJxIG5oPVWk12JVB6iPQTUrrzAP11xy1rBLcyRGzaFjKWE5wtpFCzro1/:CmOVnPQTUrrzAP11xy1rBLcyRGzaFjK - TLSH:
T11C5EC07A012F30A0E0FEA9D4BC4C6FCCC0E1706D9433AB598543DF1E5841567AEE65AA - Submitted as: libwinpthread-1.dll
- File type: pe · Size: 3116032 bytes
- Verdict: malicious (78/100) · Family: execute
Detections (5 of 53 engines)
- capa (capabilities): execute via PowerShell
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Trojan:Win64/Aotera.DSY!MTB
- Emsisoft (Emergency Kit): Trojan.GenericKD.80950125
- Kaspersky (KVRT): UDS:Trojan.Win64.Agent
MITRE ATT&CK
Why this verdict
The malicious score of 78/100 is the fusion of 4 weighted signals:
- Emsisoft (Emergency Kit) flagged Trojan.GenericKD.80950125 (rule
Trojan.GenericKD.80950125) - engine signal, weight 0.55, confidence 0.85 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 4.2.1.0 - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://aka.ms/nativeaot-compatibilit
Embedded domains
- aka.ms
Embedded IP addresses
- 4.2.1.0
More execute samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report