MALICIOUS — 92baf0856fb02488b0b764f29b51dc76aa60cdb0eba3355a1bd395f0b008bd56.exe
MALICIOUS — 92baf0856fb02488b0b764f29b51dc76aa60cdb0eba3355a1bd395f0b008bd56.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (76/100), attributed to the Clipbanker family. 5 of 29 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
92baf0856fb02488b0b764f29b51dc76aa60cdb0eba3355a1bd395f0b008bd56 - SHA-1:
32304df03f427ba7675efd314bf7f9f3d4e8113b - MD5:
5044e89dda33f28743b3b9e79d6f6572 - imphash:
75c721f1755f04cc47f7598bb55e4e6f - ssdeep:
98304:kzs6efPhFFNUhJFF3s+BoiGg1Gc977zbt:0fefPCFF3bBR1H9773 - TLSH:
T1476501CA8B06B350EEF0E910789089DD3853B099A5BD1D9C4A83D57D21D88BFB47B14B - Submitted as: 92baf0856fb02488b0b764f29b51dc76aa60cdb0eba3355a1bd395f0b008bd56.exe
- File type: pe · Size: 5626744 bytes
- Verdict: malicious (76/100) · Family: Clipbanker
Detections (5 of 29 engines)
- capa (capabilities): capability:execution/powershell
- YARA: bartblaze: BB_Clipbanker
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Trojan:Win32/Sabsik.EN.A!ml
- Kaspersky (KVRT): not-a-virus:RemoteAdmin.Win32.ConnectWise.ajg
MITRE ATT&CK
Why this verdict
The malicious score of 76/100 is the fusion of 6 weighted signals:
- execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: bartblaze flagged BB_Clipbanker (rule
BB_Clipbanker) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://feedback.screenconnect.com/Feedback.axd, 217.60.241.27 - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.digicert.com/CPS0
- https://feedback.screenconnect.com/Feedback.axd
Embedded domains
- 1.it
- cacerts.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- feedback.screenconnect.com
Embedded IP addresses
- 217.60.241.27
File paths
- C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb
- C:\builds\cc\cwcontrol\Product\Core\obj\Release\net20\ScreenConnect.Core.pdb
- X:\:b:f:l:p:
- X:\:`:d:h:l:p:t:x:
- T:\:d:l:t:
- T:\:d:
- C:\builds\cc\cwcontrol\Product\Windows\obj\Release\net20\ScreenConnect.Windows.pdb
- C:\builds\cc\cwcontrol\Product\WindowsInstaller\obj\Release\net20\ScreenConnect.WindowsInstaller.pdb
- E:\delivery\Dev\wix37_public\build\ship\x86\SfxCA.pdb
- X:\:`:d:h:x:
- R:\rt
- C:\build\work\eca3d12b\wix3\build\ship\x86\wixca.pdb
- X:\:
- Q:\:a:f:
- C:\builds\cc\cwcontrol\Product\ClientInstallerRunner\obj\Release\ScreenConnect.ClientInstallerRunner.pdb
- C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\DotNetResolver\obj\Debug\DotNetResolver.pdb
More Clipbanker samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report