MALICIOUS — wlogon.dll

MALICIOUS — wlogon.dll is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Somhoveran family. 5 of 55 detection engines flagged it, exhibiting 3 ATT&CK techniques.

Identification

Detections (5 of 55 engines)

MITRE ATT&CK

Why this verdict

The malicious score of 97/100 is the fusion of 7 weighted signals:

Dynamic analysis (windows)

315 behavior events · 2 ATT&CK techniques · 4 dropped files.

Runtime network

Dropped files

Embedded URLs

Embedded IP addresses

More Somhoveran samples · Latest analyzed threats · ATT&CK coverage

Analyzed on MalwareAnalyzer by Cyble · Open interactive report