MALICIOUS — 8dc76b26a57b33449daa302c1907c3c203876ea21872e053b8d4a4fbfa6993bb
MALICIOUS — 8dc76b26a57b33449daa302c1907c3c203876ea21872e053b8d4a4fbfa6993bb is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Bulz family. 9 of 51 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
8dc76b26a57b33449daa302c1907c3c203876ea21872e053b8d4a4fbfa6993bb - SHA-1:
48ea1e7122d083c159d404e2cdb8e471b1985c77 - MD5:
d87032e2b7ab7e5d02a8933c58d056e3 - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
393216:TY2erMlalAQu/AK4wYneoSUPe0gBEMxtrds1GMDFQ/huFXsI9EGOpDp4vs+6x:NJa/fnNPPgDxMGanFczGOt20 - TLSH:
T1747733D946907F26C9BBAD645EA5C4CB6356A22ED0BDC840503871F3F93CD823568BE0 - Submitted as: 8dc76b26a57b33449daa302c1907c3c203876ea21872e053b8d4a4fbfa6993bb
- File type: pe · Size: 31139328 bytes
- Verdict: malicious (98/100) · Family: Bulz
Detections (9 of 51 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): Win.Packed.Bulz-9897681-0
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- Microsoft Defender: Trojan:MSIL/Injectgen.MA!MTB
- Emsisoft (Emergency Kit): IL:Trojan.Stealer.536
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Packed.Bulz-9897681-0 (rule
Win.Packed.Bulz-9897681-0) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- h95.ga
- bw.ml
- nj.in
- 5.tw
- yg.de
- ve.eu
- 1.sg
- y2e.tw
- p2.fr
- s.pl
- 2.ch
- r.ai
- a.to
- 4.be
File paths
- X:\Z~
- F:\/
- Z:\jM
- j:\/
- g:\[-
- h:\YJ
- K:\:
- v:\~
More Bulz samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report