SUSPICIOUS — 855ab4ee2a1e479fb1584e50fcc6847fa9d3da36100b2379d9feaab7442bf679
SUSPICIOUS — 855ab4ee2a1e479fb1584e50fcc6847fa9d3da36100b2379d9feaab7442bf679 is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (40/100), attributed to the STRATO family. 3 of 55 detection engines flagged it.
Identification
- SHA-256:
855ab4ee2a1e479fb1584e50fcc6847fa9d3da36100b2379d9feaab7442bf679 - SHA-1:
7c08b8af79fa93e055dc073e43c9a6d47f2fd89e - MD5:
dff8b0b739c5c6d4fa10affe8db819a0 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
96:X478k13N5kIDGT5YBAEr3nr6M/OzNtTX:X47TN5XDiYBAErb6MIxX - TLSH:
T1E41DA6CE01182746CAE6CC572161853DB8C174AD1AB2250E46088A37757D573AC3B6AE - Submitted as: 855ab4ee2a1e479fb1584e50fcc6847fa9d3da36100b2379d9feaab7442bf679
- File type: pe · Size: 6242 bytes
- Verdict: suspicious (40/100) · Family: STRATO
Detections (3 of 55 engines)
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- Emsisoft (Emergency Kit): IL:Trojan.MSILZilla.10345
- Kaspersky (KVRT): UDS:Trojan-PSW.MSIL.Disco.gen
Why this verdict
The suspicious score of 40/100 is the fusion of 2 weighted signals:
- YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://cdn.discordapp.com/attachments/906967913821511721/909359256090849340/Stub_Creator.exe - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cdn.discordapp.com/attachments/906967913821511721/909359256090849340/Stub_Creator.exe
Embedded domains
- cdn.discordapp.com
File paths
- C:\Users\THRAX\source\repos\ConsoleApp3\ConsoleApp3\obj\Debug\ConsoleApp3.pdb
More STRATO samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report