MALICIOUS — 320_EquationGroup.bin
MALICIOUS — 320_EquationGroup.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the Alhw family. 1 of 36 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8b05efa5c156a466c3da3b30bf9cd87178d635f51cdaf5f83eda4004a6007194 - SHA-1:
914e79a3a36c48eb74f68615c08054d37a869337 - MD5:
ac50c31d680c763cce26b4d979a11a5c - imphash:
6c22181c4a122990e7c1d1ef45848e30 - ssdeep:
3072:TKnUNALmVZvvGBeQYejpCIAq2tn2TBfki43y97FozS4Oq1sqH73oGC:M4LvkwejpIqun2TB8i4i0zLOosqHkG - TLSH:
T1FA418D178330A548D2E6EB7574827C0CD167F9CDB2B2BADB40E182BC6EE44277425A17 - Submitted as: 320_EquationGroup.bin
- File type: pe · Size: 184320 bytes
- Verdict: malicious (87/100) · Family: Alhw
Detections (1 of 36 engines)
- ClamAV (daily): Win.Malware.Alhw-9909682-0
MITRE ATT&CK
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Malware.Alhw-9909682-0 (rule
Win.Malware.Alhw-9909682-0) - engine signal, weight 0.90, confidence 0.95 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
File paths
- c:\windows\system32\kernel32.dll
- d:\fanny.bmp
- x:\fanny.bmp
- Q:\__
More Alhw samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report