MALICIOUS — 86a8ed57cbc2e850c5c3206b169c98c9211708477563a5fd57da5cdfc953e59e
MALICIOUS — 86a8ed57cbc2e850c5c3206b169c98c9211708477563a5fd57da5cdfc953e59e is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the DCOM family. 7 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
86a8ed57cbc2e850c5c3206b169c98c9211708477563a5fd57da5cdfc953e59e - SHA-1:
07db2925caccd92acbe9d3e5e2cbf410c4e468df - MD5:
972e5eec8abb7b0770effbfc84a0f4bc - imphash:
c4998075f1324ce0f644f12a548d76b1 - ssdeep:
6144:IpMM6Vg/fSD+MD6VguDRFULI0PHBWN0tNcl4rTHu:XyqXDuoRPHBWN0bclj - TLSH:
T1D0498CCC551AA745E2F2D5241D248E8C2063B4FE227E3ACE96C3C17F72E6477583819A - Submitted as: 86a8ed57cbc2e850c5c3206b169c98c9211708477563a5fd57da5cdfc953e59e
- File type: pe · Size: 398811 bytes
- Verdict: malicious (95/100) · Family: DCOM
Detections (7 of 52 engines)
- ClamAV (daily): Win.Exploit.DCOM-5
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Exploit:Win32/RpcDcom!pz
- Emsisoft (Emergency Kit): Trojan.Agent.FRPG
- Trellix Stinger (McAfee): Agent-FQX!972E5EEC8ABB
- Kaspersky (KVRT): Virus.Win32.Lamer.kp
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Win.Exploit.DCOM-5 (rule
Win.Exploit.DCOM-5) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: 212.33.237.86 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/windows0
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
Embedded domains
- www.microsoft.com
- crl.microsoft.com
- iana.org
Embedded IP addresses
- 212.33.237.86
File paths
- C:\Program
- C:\\Program
- C:\\$SysReset\Scratch\csrss.exe
- C:\\data\executer.exe
- C:\\cygwin64\usr\sbin\zdump.exe
- C:\\DLLS\CorFlags.exe
- T:\:d:l:t:
- X:\:`:d:h:l:p:t:x:
- C:\sample.exe
- C:\SnapshotPath
More DCOM samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report