MALICIOUS — 4ce3dea7cf03c1855d92ab1df296fc43d3b58abd6c8f5bbcfb042f01f84d0786
MALICIOUS — 4ce3dea7cf03c1855d92ab1df296fc43d3b58abd6c8f5bbcfb042f01f84d0786 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the AB9A06E4 family. 7 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
4ce3dea7cf03c1855d92ab1df296fc43d3b58abd6c8f5bbcfb042f01f84d0786 - SHA-1:
aa1f0ee60a73d0609609ed5e0673c1f252d55d09 - MD5:
32d0ca612484fa809b7a7315e5d322da - imphash:
532816589b7c9c3bed0fbcc3d1503ba1 - ssdeep:
12288:TNodBiTI+TprA6EZO7KUQRZ66z24VZbdrpgrXN2LWzmidN:ZoPD+Tpr3vKU6Z66z24VZbFpgJ2LWzm - TLSH:
T1B24B295DCA22A281D06286706CC2DDFD60113AE573A8988F7533F0FD76F7917A94029E - Submitted as: 4ce3dea7cf03c1855d92ab1df296fc43d3b58abd6c8f5bbcfb042f01f84d0786
- File type: pe · Size: 495384 bytes
- Verdict: malicious (99/100) · Family: AB9A06E4
Detections (7 of 52 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Worm.Nupik-1
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- Microsoft Defender: Worm:Win32/Delf.BE!MTB
- Emsisoft (Emergency Kit): Dropped:Generic.Malware.SV!p2p!u34.AB9A06E4
- Kaspersky (KVRT): P2P-Worm.Win32.VB.dz
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Worm.Nupik-1 (rule
Win.Worm.Nupik-1) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Worm:Win32/Delf.BE!MTB (rule
Worm:Win32/Delf.BE!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Dropped:Generic.Malware.SV!p2p!u34.AB9A06E4 (rule
Dropped:Generic.Malware.SV!p2p!u34.AB9A06E4) - engine signal, weight 0.55, confidence 0.85 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: 3.6.1.0, 5.0.3.6 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2016/WindowsSettings
Embedded domains
- schemas.microsoft.com
Embedded IP addresses
- 3.6.1.0
- 5.0.3.6
File paths
- C:\Programme\eMule
- V:\:a:f:k:p:v:~:
More AB9A06E4 samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report