MALICIOUS — 47619d7345812a0d9238054398fb88bc1679562a7421c1b59927fa67768df03a.exe
MALICIOUS — 47619d7345812a0d9238054398fb88bc1679562a7421c1b59927fa67768df03a.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Egairtigado family. 7 of 53 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
47619d7345812a0d9238054398fb88bc1679562a7421c1b59927fa67768df03a - SHA-1:
de7058158b7d66c52628a644de65948e95319409 - MD5:
ee9b4e39dc11f3d69fcaa4cadb4d5877 - imphash:
d42595b695fc008ef2c56aabd8efd68e - ssdeep:
49152:/gKAMQbvPKXreAAi9KHYZ3GebHT43pmuEqLKAHM08jx5Z+cCk8nozL:/n/UsGmuEaKAHM08jTZ+cT8nc - TLSH:
T18E609DB819073151DAF9DD5CA831C0DCD8BB3C4692B5AA9C0387D87601EAFBBD6E0059 - Submitted as: 47619d7345812a0d9238054398fb88bc1679562a7421c1b59927fa67768df03a.exe
- File type: pe · Size: 3776872 bytes
- Verdict: malicious (100/100) · Family: Egairtigado
Detections (7 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): Go
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Hash: abuse.ch ThreatFox: known-malicious-hash
- Detect It Easy (packer/type): DIE:Go
- Microsoft Defender: Trojan:Win32/Egairtigado!rfn
- Emsisoft (Emergency Kit): Trojan.GenericKD.80914989
- Kaspersky (KVRT): Backdoor.Win64.Gsb.dka
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- Hash: abuse.ch ThreatFox flagged known-malicious-hash (rule
known-malicious-hash) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 5 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 8152) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Win32/Egairtigado!rfn (rule
Trojan:Win32/Egairtigado!rfn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.GenericKD.80914989 (rule
Trojan.GenericKD.80914989) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Go (rule
DIE:Go) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://go.dev/issue/66821 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: Go - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
919 behavior events · 2 ATT&CK techniques · 1 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- teams.cloud.microsoft
- t.me
- steamcommunity.com
- www.bing.com
- aps.prod.windows.com
- desktop-hsgcbep
- config.edge.skype.com
- dns.msftncsi.com
- tas02.sls.update.microsoft.com
- to-do.microsoft.com
- settings-win.data.microsoft.com
- ctldl.windowsupdate.com
- staging.to-do.microsoft.com
- watson.events.data.microsoft.com
- edge.microsoft.com
- g.live.com
- ecs.office.com
- self.events.data.microsoft.com
Dropped files
- 8a713cffc9a4e4257be77222467585daa32f4868dc722e4a40d68db1d2af79d6 -
8a713cffc9a4e4257be77222467585daa32f4868dc722e4a40d68db1d2af79d6
Embedded URLs
- https://go.dev/issue/66821
Embedded domains
- abi.name
- godebugs.info
- json.name
- go.dev
- runtime.link
- reflectlite.rtype.name
- unicode.to
- eq.io
- go.shape.int
- runtime.work
- sale.com
- t.me
- steamcommunity.com
File paths
- j:\YF
More Egairtigado samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report