MALICIOUS — virussign.com_eca1c40019f47353a76f168134e337a0.vir
MALICIOUS — virussign.com_eca1c40019f47353a76f168134e337a0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Allegato family. 6 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7c1b267db7d698a897d572cd41f2e5746a06bb1a512a69f1c629c7852b99c459 - SHA-1:
872f036331248b4077e73ff8aa6a20469c490f16 - MD5:
eca1c40019f47353a76f168134e337a0 - imphash:
4d8e0e9b3cda0ac531fc1f3753cc7ad5 - ssdeep:
49152:04xat1/oBHcOwimtZHt4xat1/oBHcOwimtZHt4xat1/oBHcOwimtZHt4xat1/oB:0y5YnNy5YnNy5YnNy5Yn - TLSH:
T12864027E137FB603D93FCE2008057E4E4025B86A107E7C8866A7947CE7F5CAB6941629 - Submitted as: virussign.com_eca1c40019f47353a76f168134e337a0.vir
- File type: pe · Size: 5349376 bytes
- Verdict: malicious (99/100) · Family: Allegato
Detections (6 of 52 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Malware.Zusy-9917110-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Trojan:Win32/Allegato!pz
- Emsisoft (Emergency Kit): Gen:Variant.Genie.477
- Kaspersky (KVRT): Trojan.Win32.Agent.xosy
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Malware.Zusy-9917110-0 (rule
Win.Malware.Zusy-9917110-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Allegato!pz (rule
Trojan:Win32/Allegato!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Genie.477 (rule
Gen:Variant.Genie.477) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Agent.xosy (rule
Trojan.Win32.Agent.xosy) - engine signal, weight 0.55, confidence 0.85 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 11.0.02.0 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded IP addresses
- 11.0.02.0
File paths
- C:\Users\Win7\Desktop\Unique
- X:\:l:
- T:\:`:h:l:t:x:
- T:\:d:l:t:
More Allegato samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report