SUSPICIOUS — sample
SUSPICIOUS — sample is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (52/100). 4 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
6738463df6799b8fd8f92f8deae1e57e7a9a034eeb0273411a56bae9469757e2 - SHA-1:
0b1cd1dfea13fa1f60f408a09ff28a2ea9817fb8 - MD5:
f604c05ee25c90a64fabbfabf4b96cd6 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
768:ArqOBsTgjD+Apv6GFlYmtDsSLaYd7lCo50tOwc:ArqOOTgfT7G/SOYd7l/7 - TLSH:
T1FA34F7DD17BF230AE022CC15BC48C5DD6C48AA8AE87D73D83B5442AA3484E3F9936175 - Submitted as: sample
- File type: pe · Size: 53760 bytes
- Verdict: suspicious (52/100)
Detections (4 of 52 engines)
- capa (capabilities): capability:execution/powershell
- Microsoft Defender: Trojan:MSIL/Asyncrat!AMTB
- Emsisoft (Emergency Kit): Gen:Variant.AsyncRAT.23
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 52/100 is the fusion of 3 weighted signals:
- execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: https://i.ibb.co/d4vFMPrQ/6368b64a-e9ca-4b2e-9a76-3df6c9f1aa7b-removebg-preview.png, https://www.youtube.com/@BacteriaGroup - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://i.ibb.co/d4vFMPrQ/6368b64a-e9ca-4b2e-9a76-3df6c9f1aa7b-removebg-preview.png
- https://www.youtube.com/@BacteriaGroup
Embedded domains
- i.ibb.co
- www.youtube.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report