MALICIOUS — 47673b30b57b963e029159141bc026111e18526818b3b4397f13d8f7ed270296
MALICIOUS — 47673b30b57b963e029159141bc026111e18526818b3b4397f13d8f7ed270296 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100), attributed to the Hoax family. 7 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
47673b30b57b963e029159141bc026111e18526818b3b4397f13d8f7ed270296 - SHA-1:
c0caefa6bac99d96f561245e854ea262f0355ccc - MD5:
2621276ac9a548c8574fce420e70b19d - imphash:
0818438d729451edf8c455424695687b - ssdeep:
768:vCru/f9Iw/E6zy4n8uZ5tUXMJ+fROUmELY2glEbM3j+rd+fpRiTWNReOOg:71Tzy48untU8fOMEI3jyYfPiuOg - TLSH:
T175353B4DCE90CD4AE5A8AAA3B0249C4D4071A4F3FEFB329930D1F56A1CE0C973459769 - Submitted as: 47673b30b57b963e029159141bc026111e18526818b3b4397f13d8f7ed270296
- File type: pe · Size: 59987 bytes
- Verdict: malicious (94/100) · Family: Hoax
Detections (7 of 55 engines)
- capa (capabilities): capability:collection/keylog
- MalwareAnalyser heuristics (entropy/packer): PureBasic
- ClamAV (daily): Win.Malware.Hoax-10019944-0
- Detect It Easy (packer/type): DIE:PureBasic
- Microsoft Defender: Trojan:Win32/Lazy.AB!MTB
- Emsisoft (Emergency Kit): Trojan.Generic.32454626
- Kaspersky (KVRT): Hoax.Win32.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Malware.Hoax-10019944-0 (rule
Win.Malware.Hoax-10019944-0) - engine signal, weight 0.90, confidence 0.95 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Detect It Easy (packer/type) flagged DIE:PureBasic (rule
DIE:PureBasic) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: PureBasic - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- www.signs101.com
File paths
- C:\Windows\System32\
- C:\\popupe.exe
- C:\Raiden\Goat\FTP\Sample\popupe.exe
- C:\WINDOWS\system32\popupe.exe
- C:\Documents
- C:\Users\luser\Desktop\popupe.exe
- C:\Users\Frank\Desktop\popupe.exe
- C:\Users\Lisa\Desktop\popupe.exe
- c:\\popupe.exe
- C:\Users\george\Desktop\popupe.exe
More Hoax samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report