MALICIOUS — 371_EquationGroup.bin
MALICIOUS — 371_EquationGroup.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the Alhw family. 1 of 35 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
40dfbc9be43f7342f026b47285e6f5c020563fcadf4558e3c1b602e04e16c71d - SHA-1:
6e08ccb85193b3617f5b6d4d9627d8ee8f1a791f - MD5:
1cb7ae1bc76e139c89684f7797f520a1 - imphash:
6c22181c4a122990e7c1d1ef45848e30 - ssdeep:
3072:TtnUNALmVZvvGBeQY+jpgIAq2tz2TBfki43y97FozS4Oq1sqH73oGC:p4Lvkw+jp6quz2TB8i4i0zLOosqHkG - TLSH:
T1FE419D178330A544D2E6EB717482BC0CE167F5CDB2B2BADB40E582BC6EE44277425A17 - Submitted as: 371_EquationGroup.bin
- File type: pe · Size: 184320 bytes
- Verdict: malicious (87/100) · Family: Alhw
Detections (1 of 35 engines)
- ClamAV (daily): Win.Malware.Alhw-9909682-0
MITRE ATT&CK
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Malware.Alhw-9909682-0 (rule
Win.Malware.Alhw-9909682-0) - engine signal, weight 0.90, confidence 0.95 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
File paths
- c:\windows\system32\kernel32.dll
- d:\fanny.bmp
- x:\fanny.bmp
- Q:\__
More Alhw samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report