MALICIOUS — 941aa5800fada925a3e685567faf4478b59537328384f403d2e6f8c229b016ae
MALICIOUS — 941aa5800fada925a3e685567faf4478b59537328384f403d2e6f8c229b016ae is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the IRCBot family. 7 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
941aa5800fada925a3e685567faf4478b59537328384f403d2e6f8c229b016ae - SHA-1:
3bd082c62efcb995da9424848247b8af2fa1edcf - MD5:
5e97e447fefcc929be1dc2b47f234f68 - imphash:
b8b949414a1cbbc9af7d834ae8be805f - ssdeep:
3072:WqAzqdIchnR8jaQIy5XjbbrMbvT0q8O1cZPzQ7IXMBc+AMP+QfQEhxFyVU7hZM:jrdzSIyRwvP6bQ7yMP+DE827hZM - TLSH:
T14B3F12722867A2E5FF889C5A7210827E70279F24700118E79D62D3B740ED293B7E8756 - Submitted as: 941aa5800fada925a3e685567faf4478b59537328384f403d2e6f8c229b016ae
- File type: pe · Size: 159744 bytes
- Verdict: malicious (96/100) · Family: IRCBot
Detections (7 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:,,
- ClamAV (daily): Win.Trojan.IRCBot-3175
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Backdoor:Win32/IRCbot.gen!Z
- Emsisoft (Emergency Kit): GenPack:Generic.Sdbot.F35DD628
- Kaspersky (KVRT): Packed.Win32.Black.d
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Trojan.IRCBot-3175 (rule
Win.Trojan.IRCBot-3175) - engine signal, weight 0.90, confidence 0.95 - Contacted 21 external host(s) at runtime (21 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:,,, Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded IP addresses
- 4.150.223.97
- 52.253.84.76
- 20.42.179.192
- 4.230.171.124
- 135.232.92.137
- 74.178.76.54
- 52.168.112.67
- 20.165.94.63
- 52.123.128.14
- 20.112.250.133
- 40.99.134.18
- 40.79.163.154
- 172.178.240.161
- 203.26.79.13
- 74.179.71.159
- 172.66.2.5
- 85.210.193.152
- 52.148.114.188
- 72.153.5.141
- 52.110.12.16
- 52.110.12.25
More IRCBot samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report