MALICIOUS — 56cc93be915c0d59943d0bf3c91dc1956b0af95939b812679197d3607829713f.exe
MALICIOUS — 56cc93be915c0d59943d0bf3c91dc1956b0af95939b812679197d3607829713f.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Egairtigado family. 7 of 53 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
56cc93be915c0d59943d0bf3c91dc1956b0af95939b812679197d3607829713f - SHA-1:
9d0c78e7d08e01fe65858d1e2c690af0c79cc209 - MD5:
5fae196b68afca48ce650acc79e25126 - imphash:
1aae8bf580c846f39c71c05898e57e88 - ssdeep:
49152:NAdz+FsK1yiGyRNF06CvdHr+6bsJPJ1M:qYFsK9TBUdr+1JXM - TLSH:
T10C5C8D916B99FAA0DFF4F9B0E0108BAC5D6B1D1153721ACD4396CC2192DBBB3052E193 - Submitted as: 56cc93be915c0d59943d0bf3c91dc1956b0af95939b812679197d3607829713f.exe
- File type: pe · Size: 2483552 bytes
- Verdict: malicious (99/100) · Family: Egairtigado
Detections (7 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): Go
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Hash: abuse.ch ThreatFox: known-malicious-hash
- Detect It Easy (packer/type): DIE:Go
- Microsoft Defender: Trojan:Win32/Egairtigado!rfn
- Emsisoft (Emergency Kit): Trojan.GenericKD.80954775
- Kaspersky (KVRT): Trojan-PSW.Win32.Lumma.aduu
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 11 weighted signals:
- Hash: abuse.ch ThreatFox flagged known-malicious-hash (rule
known-malicious-hash) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Egairtigado!rfn (rule
Trojan:Win32/Egairtigado!rfn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.GenericKD.80954775 (rule
Trojan.GenericKD.80954775) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Go (rule
DIE:Go) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Go - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 8 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (windows)
656 behavior events · 2 ATT&CK techniques · 2 dropped files.
Runtime network
- mr-b02.tm-azurefd.net
- ln-0007.ln-msedge.net
- cl-glcb907925.gcdn.co
- settings-prod-eus-1-tagged.eastus.cloudapp.azure.com
- staging.to-do.officeppe.com
- s-0005.dual-s-msedge.net
- teams.cloud.microsoft
- outlook.office.com
- atm.outlook.mira.tm.svc.cloud.microsoft
- outlook.office365.com
- outlook.cloud.microsoft
- www.msftconnecttest.com
- onedsblobvmssprdeus02.eastus.cloudapp.azure.com
- onedsblobvmssprdwus03.westus.cloudapp.azure.com
- searchapp.bundleassets.example
- milezcv.cyou
- starzone.cyou
- mr-b01.tm-azurefd.net
- onedscolprdeus01.eastus.cloudapp.azure.com
- onedscolprdcus51.centralus.cloudapp.azure.com
Dropped files
- 84ecc5c4ea263d6273295b124c2686060091a130784850d6b90194fbe590b390 -
84ecc5c4ea263d6273295b124c2686060091a130784850d6b90194fbe590b390 - 25f9c065af36d8ada14e563027a443ae1dbf69db0b5a2c218c9783cbb9aa501e -
25f9c065af36d8ada14e563027a443ae1dbf69db0b5a2c218c9783cbb9aa501e
Embedded domains
- abi.name
- godebugs.info
- atomic.store
- runtime.link
- eq.io
- runtime.work
- mr-b02.tm-azurefd.net
- ln-0007.ln-msedge.net
- glb.sls.prod.dcat.dsp.trafficmanager.net
- cl-glcb907925.gcdn.co
- reroute443.trafficmanager.net
- staging.to-do.officeppe.com
- s-0005.dual-s-msedge.net
- glb.api.prod.dcat.dsp.trafficmanager.net
- milezcv.cyou
- starzone.cyou
- mr-b01.tm-azurefd.net
- creaflow.cyou
- trendion.cyou
- businway.cyou
- visioint.cyou
- smaridge.cyou
Embedded IP addresses
- 52.110.12.11
- 52.110.12.32
- 23.11.36.157
- 23.214.54.132
- 23.40.52.69
- 23.40.52.148
- 23.40.52.123
- 23.33.238.102
File paths
- T:\:`:
- X:\:d:h:p:t:
- X:\:d:h:
- X:\:`:d:h:l:p:t:x:
More Egairtigado samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report