MALICIOUS — 79b0b54b9210b13630c71a37822c0061cdc8a8934bc6aec949061b48c395a89a
MALICIOUS — 79b0b54b9210b13630c71a37822c0061cdc8a8934bc6aec949061b48c395a89a is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (85/100), attributed to the Disstl family. 4 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
79b0b54b9210b13630c71a37822c0061cdc8a8934bc6aec949061b48c395a89a - SHA-1:
6550053f34fe62a65e34389c05f5a844426251e3 - MD5:
73be8b2aeb288b86c742a5e8bf855ebe - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
192:vTQli+bg+3/DaASal1CqRX8jzsJZl1T0c0P:vbsHveASaKyX8/ul1oc0 - TLSH:
T14922D6CE095CEB41DAD9E9062521C97DB0D2B1E578F4354C0A84CA3325A9433BD3BBA7 - Submitted as: 79b0b54b9210b13630c71a37822c0061cdc8a8934bc6aec949061b48c395a89a
- File type: pe · Size: 9728 bytes
- Verdict: malicious (85/100) · Family: Disstl
Detections (4 of 52 engines)
- capa (capabilities): capability:execution/powershell
- Microsoft Defender: Trojan:MSIL/Disstl.OM!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Zusy.537596
- Kaspersky (KVRT): UDS:Trojan.MSIL.Bingoml.gen
MITRE ATT&CK
Why this verdict
The malicious score of 85/100 is the fusion of 4 weighted signals:
- Microsoft Defender flagged Trojan:MSIL/Disstl.OM!MTB (rule
Trojan:MSIL/Disstl.OM!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Zusy.537596 (rule
Gen:Variant.Zusy.537596) - engine signal, weight 0.55, confidence 0.85 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Embedded network infrastructure: https://discord.com/api/webhooks/908965161971363860/2tZR1_zHdb0Wi_3IzRmMNmUfntn_lLCIfehbksDO6DL_UgFrHUaue-K3h0P82mPJ6aTW, http://myexternalip.com/raw - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://discord.com/api/webhooks/908965161971363860/2tZR1_zHdb0Wi_3IzRmMNmUfntn_lLCIfehbksDO6DL_UgFrHUaue-K3h0P82mPJ6aTW
- http://myexternalip.com/raw
Embedded domains
- discord.com
- myexternalip.com
More Disstl samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report