MALICIOUS — 128_EarthKrahang_20240404.bin
MALICIOUS — 128_EarthKrahang_20240404.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Doina family. 5 of 51 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
57f64f170dfeaa1150493ed3f63ea6f1df3ca71ad1722e12ac0f77744fb1a829 - SHA-1:
aad782a5fe3d99a52970b1978874b232c54baa5b - MD5:
a7c2e87e9f947afdfe9e6a18f5e7c17b - imphash:
4978b08e1d7ec77c712250821a7548ef - ssdeep:
6144:CLeDtkdGtg+GQHYNnZou+dS+SgtMRDDyHSJxXzJl0TZDFihfQR7rmkzniAudl:6erkouCS+SIsyYrQkkA - TLSH:
T15249396241173812F9B7AA74AC504CEC9C93B42DB031425E6743EE6D80D3E7793F61AA - Submitted as: 128_EarthKrahang_20240404.bin
- File type: pe · Size: 401920 bytes
- Verdict: malicious (100/100) · Family: Doina
Detections (5 of 51 engines)
- ClamAV (daily): {MD5}bin.trojan.doina.7887.UNOFFICIAL
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- Cyble Vision: Cyble Vision: DinodasRAT
- Microsoft Defender: Trojan:Win64/Doina.ALP!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Doina.63318
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged {MD5}bin.trojan.doina.7887.UNOFFICIAL (rule
{MD5}bin.trojan.doina.7887.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Cyble Vision flagged Cyble Vision: DinodasRAT (rule
Cyble Vision: DinodasRAT) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win64/Doina.ALP!MTB (rule
Trojan:Win64/Doina.ALP!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Doina.63318 (rule
Gen:Variant.Doina.63318) - engine signal, weight 0.55, confidence 0.85 - YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 8.8.8.8 - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
80 behavior events · 1 ATT&CK techniques · 2 dropped files.
Runtime network
- none
Dropped files
- /opt/CAPEv2/storage/analyses/5927/files/8a1d56897dbc546536d780ce4001debe2b11df29cc19cf0a37631ddf911811a4 -
8a1d56897dbc546536d780ce4001debe2b11df29cc19cf0a37631ddf911811a4 - /opt/CAPEv2/storage/analyses/5927/files/99262fa6b26b09a90b6525e46143ae6bb725e0ae5f3ca5fdf6b86aed3367dd3f -
99262fa6b26b09a90b6525e46143ae6bb725e0ae5f3ca5fdf6b86aed3367dd3f
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
Embedded domains
- update.microsoft-setting.com
- schemas.microsoft.com
Embedded IP addresses
- 8.8.8.8
File paths
- Z:\newmm_v1\client\CallDll\x64\Release\1.pdb
More Doina samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report