MALICIOUS — 99eae3c904882be5ffe456421a80ffcdfcfd743958ebdbf83c4e46a7bc3f525a.exe
MALICIOUS — 99eae3c904882be5ffe456421a80ffcdfcfd743958ebdbf83c4e46a7bc3f525a.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Phorpiex family. 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
99eae3c904882be5ffe456421a80ffcdfcfd743958ebdbf83c4e46a7bc3f525a - SHA-1:
58d0501f33a9eaaef0daafea1707df9d84177a58 - MD5:
d8336b1ff9bb24fe0e116f909e3c9fc7 - imphash:
719d712c22fbec5fb6a81de733780c50 - ssdeep:
384:K/Jh/MnJbr75EEFS8S/9kWhuvDZAfLUOQPcjDw:IEfFSbmWhuvD2fLUoc - TLSH:
T1D729191EE3387165F0A1DB136082495C9533C88A96FA082DD2C3C35667FADBB643492F - Submitted as: 99eae3c904882be5ffe456421a80ffcdfcfd743958ebdbf83c4e46a7bc3f525a.exe
- File type: pe · Size: 19968 bytes
- Verdict: malicious (99/100) · Family: Phorpiex
Source: MalwareBazaar · first seen 2026-07-26T00:00:00.000Z · SHA-256 verified
Detections (5 of 53 engines)
- YARA: delivr.to detections: DLV_LNK_PowerShell_Launcher
- Hash: abuse.ch ThreatFox: known-malicious-hash
- Microsoft Defender: Trojan:Win32/Phorpiex.APX!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Worm.Phorpiex.127
- Kaspersky (KVRT): not-a-virus:RemoteAdmin.Win32.WinVNC.bwm
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 13 weighted signals:
- Hash: abuse.ch ThreatFox flagged known-malicious-hash (rule
known-malicious-hash) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 4 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 7684) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Win32/Phorpiex.APX!MTB (rule
Trojan:Win32/Phorpiex.APX!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Worm.Phorpiex.127 (rule
Gen:Variant.Worm.Phorpiex.127) - engine signal, weight 0.55, confidence 0.85 - YARA: delivr.to detections flagged DLV_LNK_PowerShell_Launcher (rule
DLV_LNK_PowerShell_Launcher) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://178.16.54.109/v.exe, 178.16.54.109 - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 1202 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Contacted 1202 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (2 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Extracted generic config (2 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
8132 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- staging.to-do.officeppe.com
- www.bing.com
- desktop-hsgcbep
- config.edge.skype.com
- tas02.sls.update.microsoft.com
- dns.msftncsi.com
- to-do.microsoft.com
- settings-win.data.microsoft.com
- ctldl.windowsupdate.com
- staging.to-do.microsoft.com
- edge.microsoft.com
- watson.events.data.microsoft.com
- teams.microsoft.com
- aps.prod.windows.com
- ecs.office.com
- g.live.com
- www.msftncsi.com
- fs.microsoft.com
Embedded URLs
- http://178.16.54.109/v.exe
Embedded domains
- staging.to-do.officeppe.com
- searchapp.bundleassets.example
- www.msftconnecttest.com
- www.bing.com
- config.edge.skype.com
- tas02.sls.update.microsoft.com
- dns.msftncsi.com
- to-do.microsoft.com
- settings-win.data.microsoft.com
- ctldl.windowsupdate.com
- staging.to-do.microsoft.com
- edge.microsoft.com
- watson.events.data.microsoft.com
- teams.microsoft.com
- aps.prod.windows.com
- ecs.office.com
- g.live.com
- www.msftncsi.com
- fs.microsoft.com
- self.events.data.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
- geover.prod.do.dsp.mp.microsoft.com
Embedded IP addresses
- 178.16.54.109
- 54.22.145.16
- 79.114.10.104
- 209.213.241.49
- 75.249.38.65
- 21.206.143.181
- 79.101.242.48
- 86.83.151.121
- 36.136.71.158
- 131.204.118.230
- 219.177.8.239
- 126.6.198.9
- 84.243.82.73
- 155.22.212.158
- 113.182.180.136
- 129.203.167.134
- 190.183.91.12
- 102.152.182.172
- 71.246.5.98
- 55.214.48.86
- 60.108.228.3
- 108.189.73.214
- 76.129.11.154
- 67.188.236.229
- 6.144.146.16
More Phorpiex samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report