MALICIOUS — 368_EquationGroup.bin
MALICIOUS — 368_EquationGroup.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the Alhw family. 1 of 35 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
45ac93f3cffdd6d6013bb4b371a607ff42b38a2832af4769031b71cffacd0593 - SHA-1:
e9f15d8d2da2aa844362ab7dad6b1ac4803b81ae - MD5:
2c6595834dd5528235e8a9815276563e - imphash:
6c22181c4a122990e7c1d1ef45848e30 - ssdeep:
3072:TtnUNALmVZvvGBerYejp1IAq2tn2TBfki43y97FozS4Oq1sqbi3oGC:p4Lvktejp7qun2TB8i4i0zLOosqb3G - TLSH:
T157419D178330A548D2E6EB7174827C0CD167F9CDB2B2BADB40E582BC6EE44277425A17 - Submitted as: 368_EquationGroup.bin
- File type: pe · Size: 184320 bytes
- Verdict: malicious (87/100) · Family: Alhw
Detections (1 of 35 engines)
- ClamAV (daily): Win.Malware.Alhw-9909682-0
MITRE ATT&CK
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Malware.Alhw-9909682-0 (rule
Win.Malware.Alhw-9909682-0) - engine signal, weight 0.90, confidence 0.95 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
File paths
- c:\windows\system32\kernel32.dll
- d:\fanny.bmp
- x:\fanny.bmp
- Q:\__
More Alhw samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report