MALICIOUS — 132_EarthKrahang_20240404.bin
MALICIOUS — 132_EarthKrahang_20240404.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the Doina family. 3 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5a32bf21904387d469d4f8cdaff46048e99666fc9b4d74872af9379df7979bfe - SHA-1:
6c71657aa9ad1214d332117da138459aa30e42f3 - MD5:
eb0d8b3f95da58aa7ea35502907de953 - imphash:
4031dc2e8268cb3797743afdc50b9cd4 - ssdeep:
6144:Mx9dr+RP7zg6kUNSfYLTSdX7JooKoRcJiE3TFdBp3Sn9tSSKre:JRYUQfYLTUoxMEre - TLSH:
T11849496641172812F9B7B2749C008DEC8C93B46DB131465E2743DE2E80D3EB7A7F619A - Submitted as: 132_EarthKrahang_20240404.bin
- File type: pe · Size: 408240 bytes
- Verdict: malicious (96/100) · Family: Doina
Detections (3 of 51 engines)
- ClamAV (daily): {MD5}bin.trojan.doina.7898.UNOFFICIAL
- Microsoft Defender: Trojan:Win32/Malgent!MSR
- Emsisoft (Emergency Kit): Gen:Variant.Doina.63318
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged {MD5}bin.trojan.doina.7898.UNOFFICIAL (rule
{MD5}bin.trojan.doina.7898.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Malgent!MSR (rule
Trojan:Win32/Malgent!MSR) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Doina.63318 (rule
Gen:Variant.Doina.63318) - engine signal, weight 0.55, confidence 0.85 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- none
Dropped files
- /opt/CAPEv2/storage/analyses/5928/files/edfd3c2575f90dbe324e55a11f6f3fe25acd6fdb59794c626e57b5a0b9651a44 -
edfd3c2575f90dbe324e55a11f6f3fe25acd6fdb59794c626e57b5a0b9651a44 - /opt/CAPEv2/storage/analyses/5928/files/bafd0b48b10f152b487897837cfac7dc7cc5c2d1c4d48da682042313945c79d6 -
bafd0b48b10f152b487897837cfac7dc7cc5c2d1c4d48da682042313945c79d6
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://ocsp.globalsign.com/rootr103
- http://crl.globalsign.com/root.crl0Y
- https://www.globalsign.com/repository/0
- http://ocsp2.globalsign.com/gscodesigng30V
- http://crl.globalsign.com/gs/gscodesigng3.crl0
- https://www.digicert.com/CPS0
- http://www.digicert.com/ssl-cps-repository.htm0
Embedded domains
- www.security-microsoft.net
- schemas.microsoft.com
- ocsp.globalsign.com
- crl.globalsign.com
- www.globalsign.com
- secure.globalsign.com
- ocsp2.globalsign.com
- crl.microsoft.com
- www.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- cacerts.digicert.com
More Doina samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report