MALICIOUS — 813f79fc29c6511b8f53984277028db875c1f4331ac8275777593a8ca6da35d9
MALICIOUS — 813f79fc29c6511b8f53984277028db875c1f4331ac8275777593a8ca6da35d9 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Viking family. 9 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
813f79fc29c6511b8f53984277028db875c1f4331ac8275777593a8ca6da35d9 - SHA-1:
57578cf90c0b35d8b92062e4623c127f5f6e0c56 - MD5:
07761fe0962b3d99d1f1674351cb557e - imphash:
4847bea2fab2ae7b3c2596a2782272f9 - ssdeep:
1536:qjMqxL2Q3qOLj5MtVlyEeRupqYYQe4X4xy/AfgLdQAQfcfymNG+Kx+:sAyL9W0ElYKXGMAftffjmNox+ - TLSH:
T1AA418D392F2B6B9FEE26C32258403B5D4872F4FA34654489576794AC77EDC139A8032C - Submitted as: 813f79fc29c6511b8f53984277028db875c1f4331ac8275777593a8ca6da35d9
- File type: pe · Size: 181760 bytes
- Verdict: malicious (99/100) · Family: Viking
Detections (9 of 52 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- MalwareAnalyser heuristics (entropy/packer): Borland Delphi
- ClamAV (daily): Win.Worm.Gavir-1
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- Detect It Easy (packer/type): DIE:Borland Delphi
- Microsoft Defender: Virus:Win32/Viking.H
- Emsisoft (Emergency Kit): Win32.Worm.Viking.NDL
- Kaspersky (KVRT): Worm.Win32.Viking.j
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Win.Worm.Gavir-1 (rule
Win.Worm.Gavir-1) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - Microsoft Defender flagged Virus:Win32/Viking.H (rule
Virus:Win32/Viking.H) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Worm.Viking.NDL (rule
Win32.Worm.Viking.NDL) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Borland Delphi (rule
DIE:Borland Delphi) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Borland Delphi - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Viking samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report