MALICIOUS — 656_VolatileCedar.Explosion.bin
MALICIOUS — 656_VolatileCedar.Explosion.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Explosive family. 7 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
78201fd42dfc65e94774d8a9b87293c19044ad93edf59d3ff6846766ed4c3e2e - SHA-1:
f1d4492e61d7216b837cbb3ca37c358e1c7beff6 - MD5:
29eca6286a01c0b684f7d5f0bfe0c0e6 - imphash:
232612b77c6784f36e446795fb8fc0e1 - ssdeep:
1536:FDohbS1VelsaPmXcHWELG/jn715ycQf6Wlp:NohbSKtlUbw1lp - TLSH:
T187398E148327B606F3D7DF904C522C0D90E2B67FB2B85A4857E6C38F35E286F6664528 - Submitted as: 656_VolatileCedar.Explosion.bin
- File type: pe · Size: 90112 bytes
- Verdict: malicious (100/100) · Family: Explosive
Detections (7 of 52 engines)
- ClamAV (daily): {MD5}bin.trojan.explosive.7944.UNOFFICIAL
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Cyble Vision: Cyble Vision: Malicious
- Microsoft Defender: Trojan:Win32/Explosive.A
- Emsisoft (Emergency Kit): Gen:Variant.Doina.27784
- Trellix Stinger (McAfee): Trojan-FGBJ!29ECA6286A01
- Kaspersky (KVRT): Trojan.Win32.Explosive.ah
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged {MD5}bin.trojan.explosive.7944.UNOFFICIAL (rule
{MD5}bin.trojan.explosive.7944.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Cyble Vision flagged Cyble Vision: Malicious (rule
Cyble Vision: Malicious) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Explosive.A (rule
Trojan:Win32/Explosive.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Doina.27784 (rule
Gen:Variant.Doina.27784) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Trojan-FGBJ!29ECA6286A01 (rule
Trojan-FGBJ!29ECA6286A01) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (windows)
94 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- searchapp.bundleassets.example
- desktop-hsgcbep
- v10.events.data.microsoft.com
- settings-win.data.microsoft.com
- login.live.com
- config.edge.skype.com
- fd.api.iris.microsoft.com
- licensing.mp.microsoft.com
- windows.msn.com
- officeclient.microsoft.com
- sdx.microsoft.com
- nav.smartscreen.microsoft.com
- www.bing.com
- fe3cr.delivery.mp.microsoft.com
- dns.msftncsi.com
- assets.msn.com
- watson.events.data.microsoft.com
- 192.168.122.111
Embedded domains
- inference.location.live.net
Embedded IP addresses
- 162.159.36.2
More Explosive samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report