MALICIOUS — 4485e638e43e37eb05c7ce5dcc795b1d9c80efd4020d8cfad1ff4cf68e116eb2
MALICIOUS — 4485e638e43e37eb05c7ce5dcc795b1d9c80efd4020d8cfad1ff4cf68e116eb2 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the Johnnie family. 4 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4485e638e43e37eb05c7ce5dcc795b1d9c80efd4020d8cfad1ff4cf68e116eb2 - SHA-1:
37f386807737bd4a7925a0f6912369b61441f53f - MD5:
06d84f9c392041bab01bc345acb15145 - imphash:
e8536c65f22247632517858ee5f4588e - ssdeep:
384:/TTmwDS0v0ezVRgDlpYmQ3YUuDUyGpW1:/Xpm+0oVRghGmQ3YUEL91 - TLSH:
T1052D5FCA4E758C66C875CD83E080D89C00E3F8B2776E145CA656E13A6BD2CA7343557E - Submitted as: 4485e638e43e37eb05c7ce5dcc795b1d9c80efd4020d8cfad1ff4cf68e116eb2
- File type: pe · Size: 28690 bytes
- Verdict: malicious (91/100) · Family: Johnnie
Detections (4 of 55 engines)
- ClamAV (daily): Win.Malware.Johnnie-9839209-0
- Microsoft Defender: Adware:Win32/Multiverze!rfn
- Emsisoft (Emergency Kit): Gen:Variant.Worm.VB.112
- Kaspersky (KVRT): Trojan.Win32.Agentb.anqa
MITRE ATT&CK
Why this verdict
The malicious score of 91/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Malware.Johnnie-9839209-0 (rule
Win.Malware.Johnnie-9839209-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: 183.61.189.91 - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded IP addresses
- 183.61.189.91
File paths
- d:\Program
More Johnnie samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report