MALICIOUS — 696a1e26da1c4badc5dec7475b7b822da7064035e72ddf899d502d3ffe27fd79
MALICIOUS — 696a1e26da1c4badc5dec7475b7b822da7064035e72ddf899d502d3ffe27fd79 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (74/100), attributed to the Wacatac family. 4 of 53 detection engines flagged it.
Identification
- SHA-256:
696a1e26da1c4badc5dec7475b7b822da7064035e72ddf899d502d3ffe27fd79 - SHA-1:
fb08e2460bc9697a86a10aafbc736271ae933063 - MD5:
49c813eb6ea4306c5431204e94e8d453 - imphash:
e3b0608c77da16fba682bb1eff56431a - ssdeep:
6144:BuVUUjwolg4owroOvHlq1t423ykka8dX+wWAZF5ULT0pny+6BTXQ02kAfpkKu/T:BuVUpob/8OvHs3tbP0pvxkep5ZN - TLSH:
T1894C7D441502D763D4E2EAB46C8D8E8CA0B3E8E3207F0A9C7793D86DD2D7D4755860BA - Submitted as: 696a1e26da1c4badc5dec7475b7b822da7064035e72ddf899d502d3ffe27fd79
- File type: pe · Size: 535040 bytes
- Verdict: malicious (74/100) · Family: Wacatac
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:Win32/Wacatac.B!ml
Why this verdict
The malicious score of 74/100 is the fusion of 4 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Wacatac.B!ml (rule
Trojan:Win32/Wacatac.B!ml) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
More Wacatac samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report