MALICIOUS — 5a49b31f84002a128f1cd0272619ae3aac4bc4b3065d567daee4300b6ac27a05.exe
MALICIOUS — 5a49b31f84002a128f1cd0272619ae3aac4bc4b3065d567daee4300b6ac27a05.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (82/100), attributed to the Clipbanker family. 6 of 25 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
5a49b31f84002a128f1cd0272619ae3aac4bc4b3065d567daee4300b6ac27a05 - SHA-1:
c463b7913a6e7b03d9c6f9d98a070cd5b97fdd78 - MD5:
5fbf5f42ced3d876ae021839bcc00069 - imphash:
75c721f1755f04cc47f7598bb55e4e6f - ssdeep:
98304:yzIus6efPUIdoaxcp8wy5c3trGOlkQ5DUOgJ9zl:yhfefPtHxcp9ym3nltDUJV - TLSH:
T14F6502CD8A12A360EAF0F910785589DD3453B0D8A1BE1C9C0B83D57D21E99FFB47A14A - Submitted as: 5a49b31f84002a128f1cd0272619ae3aac4bc4b3065d567daee4300b6ac27a05.exe
- File type: pe · Size: 5641488 bytes
- Verdict: malicious (82/100) · Family: Clipbanker
Source: MalwareBazaar · first seen 2026-08-01T00:00:00.000Z · SHA-256 verified
Detections (6 of 25 engines)
- capa (capabilities): capability:execution/powershell
- YARA: bartblaze: BB_Clipbanker
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Trellix/McAfee ATR: ATR_LockBit_Ransomware
- Microsoft Defender: Trojan:Win32/Suschil!rfn
- Kaspersky (KVRT): not-a-virus:RemoteAdmin.MSIL.ConnectWise.b
MITRE ATT&CK
Why this verdict
The malicious score of 82/100 is the fusion of 7 weighted signals:
- execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: bartblaze flagged BB_Clipbanker (rule
BB_Clipbanker) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Trellix/McAfee ATR flagged ATR_LockBit_Ransomware (rule
ATR_LockBit_Ransomware) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://feedback.screenconnect.com/Feedback.axd, 45.88.186.163 - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.digicert.com/CPS0
- https://feedback.screenconnect.com/Feedback.axd
Embedded domains
- cacerts.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- feedback.screenconnect.com
Embedded IP addresses
- 45.88.186.163
File paths
- C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb
- C:\builds\cc\cwcontrol\Product\Core\obj\Release\net20\ScreenConnect.Core.pdb
- X:\:b:f:l:p:
- X:\:`:d:h:l:p:t:x:
- T:\:d:l:t:
- T:\:d:
- C:\builds\cc\cwcontrol\Product\Windows\obj\Release\net20\ScreenConnect.Windows.pdb
- C:\builds\cc\cwcontrol\Product\WindowsInstaller\obj\Release\net20\ScreenConnect.WindowsInstaller.pdb
- F:\r
- E:\delivery\Dev\wix37_public\build\ship\x86\SfxCA.pdb
- X:\:`:d:h:x:
- C:\build\work\eca3d12b\wix3\build\ship\x86\wixca.pdb
- X:\:
- Q:\:a:f:
- C:\builds\cc\cwcontrol\Product\ClientInstallerRunner\obj\Release\ScreenConnect.ClientInstallerRunner.pdb
- C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\DotNetResolver\obj\Debug\DotNetResolver.pdb
More Clipbanker samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report