MALICIOUS — 8cac078a2e5accbdb5f1b1bdad9060bda5154b8522dcc5697446e25e133ea26d
MALICIOUS — 8cac078a2e5accbdb5f1b1bdad9060bda5154b8522dcc5697446e25e133ea26d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Oetk family. 8 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8cac078a2e5accbdb5f1b1bdad9060bda5154b8522dcc5697446e25e133ea26d - SHA-1:
c6e272a3de5bcabe132b77baa167e512d63f472a - MD5:
dd06d69985573df21f8f6ae21c31a1a7 - imphash:
435ddb61824cf7b0d9a2eafc9fb30194 - ssdeep:
1536:HYjIyeC1eUfKjkhBYJ7mTCbqODiC1ZsyHZK0FjlqsS5eHyG9LU3YG8nh:4dEUfKj8BYbDiC1ZTK7sxtLUIGo - TLSH:
T1C43BDE881691D7B9E1C74D2BD920C7EEF987EC9E2734395D881313B20B68017D918B6B - Submitted as: 8cac078a2e5accbdb5f1b1bdad9060bda5154b8522dcc5697446e25e133ea26d
- File type: pe · Size: 102002 bytes
- Verdict: malicious (97/100) · Family: Oetk
Detections (8 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Generic-9856964-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:UPX 3.03
- Kaspersky (KVRT): Trojan.Win32.Scar.oetk
- Microsoft Defender: Trojan:Win32/QQPass!pz
- Emsisoft (Emergency Kit): Gen:Variant.Stealer.229
- Trellix Stinger (McAfee): Trojan-FFZL!EF941ED0000A
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Malware.Generic-9856964-0 (rule
Win.Malware.Generic-9856964-0) - engine signal, weight 0.90, confidence 0.95 - Kaspersky (KVRT) flagged Trojan.Win32.Scar.oetk (rule
Trojan.Win32.Scar.oetk) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:UPX 3.03 (rule
DIE:UPX 3.03) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: UPX, high-entropy-sections:UPX1, UPX 3.03 - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded domains
- ietuku.com
More Oetk samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report