MALICIOUS — 550_PotaoExpress.bin
MALICIOUS — 550_PotaoExpress.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the Potao family. 4 of 52 detection engines flagged it.
Identification
- SHA-256:
97afe4b12a9fed40ad20ab191ba0a577f5a46cbfb307e118a7ae69d04adc2e2d - SHA-1:
4332a5ad314616d9319c248d41c7d1a709124db2 - MD5:
6ba88e8e74b12c914483c026ae92eb42 - imphash:
0ccd2d423dfdb09fd81be9ae98a678f1 - ssdeep:
3072:r4EIMCxF9VD0Zvi+jCTcIglTI4JUN05a:qlxF9VDaO7gloN9 - TLSH:
T1CE3EBE8C040D7647D2BBEA107D525F4DE437F08D853CE959AD93C46F3A9792B8AB0809 - Submitted as: 550_PotaoExpress.bin
- File type: pe · Size: 136704 bytes
- Verdict: malicious (89/100) · Family: Potao
Detections (4 of 52 engines)
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: TrojanDropper:Win32/Potao.D!dha
- Emsisoft (Emergency Kit): Gen:Variant.Potao.14
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
Why this verdict
The malicious score of 89/100 is the fusion of 4 weighted signals:
- Microsoft Defender flagged TrojanDropper:Win32/Potao.D!dha (rule
TrojanDropper:Win32/Potao.D!dha) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Potao.14 (rule
Gen:Variant.Potao.14) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win32.Generic (rule
HEUR:Trojan.Win32.Generic) - engine signal, weight 0.55, confidence 0.85 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- none
Dropped files
- /opt/CAPEv2/storage/analyses/6077/files/afae77fba3bb2e4e8f77ae044920eb3cd1415bec05f9830ef1ea69e42feed3ba -
afae77fba3bb2e4e8f77ae044920eb3cd1415bec05f9830ef1ea69e42feed3ba
File paths
- T:\:d:l:t:
More Potao samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report