MALICIOUS — 7ddd2cd11202fe011564f5b7853abca6ba9b18c40e2ed2aa62dc4609d59ef0f9
MALICIOUS — 7ddd2cd11202fe011564f5b7853abca6ba9b18c40e2ed2aa62dc4609d59ef0f9 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (90/100), attributed to the STRATO family. 2 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7ddd2cd11202fe011564f5b7853abca6ba9b18c40e2ed2aa62dc4609d59ef0f9 - SHA-1:
698397cd6631d88d26cafdd67b9f838d817e0441 - MD5:
2e921dc5e72237513e6d3c89e0901c2c - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
6144:hGC43NaVy8bDQ8bDQ8bDQ8bDQ8bDQ8bDQ8bDQ8bDQ8bDQ8bDQ8bDQ8bDQ8bDQ8b:hA - TLSH:
T19E4CD5BD83771D94D0EFE2398272702F40EB8D636465CF95806F8AB19B0D51302A69E7 - Submitted as: 7ddd2cd11202fe011564f5b7853abca6ba9b18c40e2ed2aa62dc4609d59ef0f9
- File type: pe · Size: 524320 bytes
- Verdict: malicious (90/100) · Family: STRATO
Detections (2 of 52 engines)
- ClamAV (daily): Win.Trojan.Generic-9907673-0
- YARA: Stratosphere IPS: STRATO_IRC_Botnet
MITRE ATT&CK
Why this verdict
The malicious score of 90/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Generic-9907673-0 (rule
Win.Trojan.Generic-9907673-0) - engine signal, weight 0.90, confidence 0.95 - YARA: Stratosphere IPS flagged STRATO_IRC_Botnet (rule
STRATO_IRC_Botnet) - engine signal, weight 0.35, confidence 0.70 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- irc.librenet.net
File paths
- C:\Surat
More STRATO samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report