MALICIOUS — 54c4778de6b667b1bc8d747c5825ed252f24f0e0e0f37c76ddcbcfee8c9b9f9e
MALICIOUS — 54c4778de6b667b1bc8d747c5825ed252f24f0e0e0f37c76ddcbcfee8c9b9f9e is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Viking family. 8 of 52 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
54c4778de6b667b1bc8d747c5825ed252f24f0e0e0f37c76ddcbcfee8c9b9f9e - SHA-1:
1d437ac8ad36e644e8a96e939dfd35ea2e295f87 - MD5:
9d240fe6efece14abdf973c3d9077494 - imphash:
5124cd999a2e4c567a9a25b581fe72b3 - ssdeep:
3072:I0v4Yb2eruGgAaeXWhTj+fVM6uMff1wsT/Ct:bvrb22uGLbWhTjYVMK1LCt - TLSH:
T1A13DF16246171609EFFBF9106560C8CC6933380AB5799AC9A303C1BBE1B4D7F943719A - Submitted as: 54c4778de6b667b1bc8d747c5825ed252f24f0e0e0f37c76ddcbcfee8c9b9f9e
- File type: pe · Size: 130088 bytes
- Verdict: malicious (99/100) · Family: Viking
Detections (8 of 52 engines)
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Lmir-24
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:UPX 1.20
- Microsoft Defender: Virus:Win32/Viking.KI
- Emsisoft (Emergency Kit): Trojan.Agent.CGVL
- Kaspersky (KVRT): Trojan-GameThief.Win32.Lmir.oa
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Lmir-24 (rule
Win.Trojan.Lmir-24) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Virus:Win32/Viking.KI (rule
Virus:Win32/Viking.KI) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Agent.CGVL (rule
Trojan.Agent.CGVL) - engine signal, weight 0.55, confidence 0.85 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:UPX 1.20 (rule
DIE:UPX 1.20) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: UPX, high-entropy-sections:UPX1, UPX 1.20 - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
Embedded domains
- crl.microsoft.com
- www.microsoft.com
More Viking samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report