MALICIOUS — 70242ca59fb99a60c79b7c50d61b5277f1e4d1edcb3d0a4b2be550bafeef1134
MALICIOUS — 70242ca59fb99a60c79b7c50d61b5277f1e4d1edcb3d0a4b2be550bafeef1134 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 3 of 55 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
70242ca59fb99a60c79b7c50d61b5277f1e4d1edcb3d0a4b2be550bafeef1134 - SHA-1:
fe8f8ef3679368d462a2d2ed5411a295e9939ae9 - MD5:
d9c665f4a9b7cfdfd51d1699bc9283ac - imphash:
042382557bc9dcce20b9a7e3c941a67b - ssdeep:
1536:uSMNMWdEFuNWFrfYSvG1Q16SA7O95dvXQ5KN4:vMHdJN0fhFXbi - TLSH:
T1B3414FCE87192327C57AC9766C219C9DC46BB07A1CBB756C0E49A13F01F61BB8CB2416 - Submitted as: 70242ca59fb99a60c79b7c50d61b5277f1e4d1edcb3d0a4b2be550bafeef1134
- File type: pe · Size: 196608 bytes
- Verdict: malicious (92/100)
Detections (3 of 55 engines)
- capa (capabilities): capability:credential-access
- ClamAV (daily): Win.Malware.Generic-9880918-0
- Microsoft Defender: Trojan:Win32/Downloader!pz
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Malware.Generic-9880918-0 (rule
Win.Malware.Generic-9880918-0) - engine signal, weight 0.90, confidence 0.95 - access stored credentials (rule
access stored credentials) - capa signal, weight 0.50, confidence 0.80 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Registry keys
- HKEY_CLASSES_ROOT\%s)
File paths
- C:\c_code\helper\windows\executer\Release\executer.pdb
- C:\sample.exe
- C:\SnapshotPath
- C:\Sample.exe
- C:\Windows\System32\svchost.exe
- C:\Windows\system32\svchost.exe
- C:\Windows\system32\lsass.exe
- C:\Windows\system32\userinit.exe,
- C:\Windows\System32\spoolsv.exe
- C:\Program
- C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE
- C:\Windows\system32\ctfmon.exe
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start
- C:\Windows\system32\SearchIndexer.exe
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report