MALICIOUS — 676_VolatileCedar.Explosion.bin
MALICIOUS — 676_VolatileCedar.Explosion.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Explosive family. 9 of 52 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
41dd95533d85a0fd099ee79fbb4c8699ae6f9299b74034b8bafa3b0ea4a1fb3a - SHA-1:
e35fb64a4d94749c87890243d9cfb4f8366ccfbe - MD5:
306d243745ba53d09353b3b722d471b8 - imphash:
666fd537989a3f1748e8bdffd1ac33f7 - ssdeep:
1536:bVeZF9KCRSM81O3J+VUJJDrLnfMescmDc/a9HagqvKRfSGz26lnl4:b0KCE1kNR+CnyfSG9lnl4 - TLSH:
T15C3B7D420537A704F3E1CB90AC429D1E80A1F4EB567D659C07E7C97F5EB6CA314A81AC - Submitted as: 676_VolatileCedar.Explosion.bin
- File type: pe · Size: 106496 bytes
- Verdict: malicious (100/100) · Family: Explosive
Detections (9 of 52 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Trojan.Explosive-6538491-1
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: MalwareAnalyser community pack: TL_Windows_Persistence_RunKey
- Cyble Vision: Cyble Vision: Malicious
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): Gen:Variant.Barys.326790
- Trellix Stinger (McAfee): Generic.dgg
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 13 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Explosive-6538491-1 (rule
Win.Trojan.Explosive-6538491-1) - engine signal, weight 0.90, confidence 0.95 - Cyble Vision flagged Cyble Vision: Malicious (rule
Cyble Vision: Malicious) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged flagged (rule
flagged) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Barys.326790 (rule
Gen:Variant.Barys.326790) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Generic.dgg (rule
Generic.dgg) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win32.Generic (rule
HEUR:Trojan.Win32.Generic) - engine signal, weight 0.55, confidence 0.85 - Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Windows_Persistence_RunKey (rule
TL_Windows_Persistence_RunKey) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
111 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- searchapp.bundleassets.example
- desktop-hsgcbep
- v10.events.data.microsoft.com
- config.edge.skype.com
- login.live.com
- settings-win.data.microsoft.com
- fd.api.iris.microsoft.com
- officeclient.microsoft.com
- licensing.mp.microsoft.com
- windows.msn.com
- www.bing.com
- sdx.microsoft.com
- nav.smartscreen.microsoft.com
- assets.msn.com
- dns.msftncsi.com
- tas02.sls.update.microsoft.com
- watson.events.data.microsoft.com
- 192.168.122.108
Embedded domains
- inference.location.live.net
Registry keys
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
More Explosive samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report