SUSPICIOUS — 75a26b461d44869648ec31cfe16441de4e41ae7a258013f27f85191bbf2f2f02
SUSPICIOUS — 75a26b461d44869648ec31cfe16441de4e41ae7a258013f27f85191bbf2f2f02 is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (67/100). 2 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
75a26b461d44869648ec31cfe16441de4e41ae7a258013f27f85191bbf2f2f02 - SHA-1:
61ddc3d16a7bb6f2ba3fdbcc1e9591c325cd4341 - MD5:
a35fff7e12b2b1a317868eac883ebc16 - imphash:
6461d5defee95ff0f6ebee3685607b03 - ssdeep:
768:mkkR5rX4kPltX6IOcmOnYo89TSY1hjXVYdhDOzr1vCxN2uKQpz3lRmZoPbpz1Ub:mk+9scmOnYooS6LKXKdCHMgbpz1UbS+ - TLSH:
T1923B10A76E140A35CAAACED6486190CD12FB127427FD05F9B7B1537DF77A8C308A0426 - Submitted as: 75a26b461d44869648ec31cfe16441de4e41ae7a258013f27f85191bbf2f2f02
- File type: pe · Size: 102400 bytes
- Verdict: suspicious (67/100)
Detections (2 of 55 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- Microsoft Defender: Trojan:Win32/Wacatac.B!ml
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The suspicious score of 67/100 is the fusion of 2 weighted signals:
- Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - Embedded network infrastructure: https://duckduckgo.com - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://duckduckgo.com
Embedded domains
- duckduckgo.com
File paths
- C:\Program
- C:\Windows\SysWow64\MSWINSCK.oca
- C:\Windows\SysWow64\MSVBVM60.DLL\3
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report