SUSPICIOUS — 7c3de04e7a1d7a44f84994244470f05faca7fd22fd80376414c0c0a596b696f4
SUSPICIOUS — 7c3de04e7a1d7a44f84994244470f05faca7fd22fd80376414c0c0a596b696f4 is a unknown sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (40/100), attributed to the STRATO family. 1 of 50 detection engines flagged it.
Identification
- SHA-256:
7c3de04e7a1d7a44f84994244470f05faca7fd22fd80376414c0c0a596b696f4 - SHA-1:
f940c2db3c21f1264b05191dabf6dc41d6fb3561 - MD5:
a614ebc98430a25bc689615a8d71a613 - ssdeep:
96:MdSZDBrxmsH6CHchhCCMpky9ftREdUTY+dWYRqHvp34STr75Mup3eyUl:2ODHchLE9FIUTYiWrJzT13eL - TLSH:
T1211CA852A31017B641F92CCA1C82CD1AA342941E32680D7AD7F18FD87C7867EE4395BB - Submitted as: 7c3de04e7a1d7a44f84994244470f05faca7fd22fd80376414c0c0a596b696f4
- File type: unknown · Size: 5832 bytes
- Verdict: suspicious (40/100) · Family: STRATO
Detections (1 of 50 engines)
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
Why this verdict
The suspicious score of 40/100 is the fusion of 2 weighted signals:
- YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://vkvsgl7lhipjirmz6j5ubp3w3bwvxgcdbpi3fsbqngfynetqtw4w5hyd.onion/, https://www.torproject.org/download/, http://brain4zoadgr6clxecixffvxjsw43cflyprnpfeak72nfh664kqqriyd.onion - static signal, weight 0.35, confidence 0.60
Embedded URLs
- http://vkvsgl7lhipjirmz6j5ubp3w3bwvxgcdbpi3fsbqngfynetqtw4w5hyd.onion/
- https://www.torproject.org/download/
- http://brain4zoadgr6clxecixffvxjsw43cflyprnpfeak72nfh664kqqriyd.onion
Embedded domains
- www.torproject.org
- cyberfear.com
- vkvsgl7lhipjirmz6j5ubp3w3bwvxgcdbpi3fsbqngfynetqtw4w5hyd.onion
- brain4zoadgr6clxecixffvxjsw43cflyprnpfeak72nfh664kqqriyd.onion
More STRATO samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report