MALICIOUS — 9b4fc704f7a53929ab614c2fc68bb63b85f901043375914a4e92cd0a8d32d643.bin
MALICIOUS — 9b4fc704f7a53929ab614c2fc68bb63b85f901043375914a4e92cd0a8d32d643.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (90/100), attributed to the Wacatac family. 6 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
9b4fc704f7a53929ab614c2fc68bb63b85f901043375914a4e92cd0a8d32d643 - SHA-1:
b88ab0fbf814ed90523ae152caff3046f5863e66 - MD5:
55086caf39129a111ae656fed7976469 - imphash:
e2f14db9ebed773579f096bfcc8c1e6c - ssdeep:
24576:QnTY4LWrzJEdOPl3EuMaPn8C5FAAojYunEPAsc1g1pVhUCBglF1VSk0qEIwdC:ckPrM8ujswg1pVhQTVF0qf - TLSH:
T1285823AD42EABE01D1B5F26B6840CB6EC801BF656578A5CC8E43C6271DD09274CF3A5C - Submitted as: 9b4fc704f7a53929ab614c2fc68bb63b85f901043375914a4e92cd0a8d32d643.bin
- File type: pe · Size: 1619456 bytes
- Verdict: malicious (90/100) · Family: Wacatac
Source: MalShare · first seen 2026-07-30T10:09:44.964Z · SHA-256 verified
Detections (6 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- Detect It Easy (packer/type): DIE:Microsoft Linker
- LIEF (executable format parser): lief:invalid-authenticode
- Microsoft Defender: Trojan:Win32/Wacatac.B!ml
- Emsisoft (Emergency Kit): Trojan.Generic.40351835
- Kaspersky (KVRT): Backdoor.Win32.Agent.myxhxt
MITRE ATT&CK
Why this verdict
The malicious score of 90/100 is the fusion of 8 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Wacatac.B!ml (rule
Trojan:Win32/Wacatac.B!ml) - engine signal, weight 0.55, confidence 0.85 - Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (windows)
3217 behavior events · 1 ATT&CK techniques · 5 dropped files.
Runtime network
- onedsblobvmssprdeus04.eastus.cloudapp.azure.com
- searchapp.bundleassets.example
- www.msftconnecttest.com
- FxabOlQYTyWEamArKiqMobFsX.FxabOlQYTyWEamArKiqMobFsX
- microsoft.com
- svc.ms-acdc-teams.office.com
- mr-b01.tm-azurefd.net
- onedscolprdwus62.westus.cloudapp.azure.com
- onedscolprduks05.uksouth.cloudapp.azure.com
- onedscolprdfrc09.francecentral.cloudapp.azure.com
- onedscolprdeus09.eastus.cloudapp.azure.com
- www.bing.com
- config.edge.skype.com
- watson.events.data.microsoft.com
- desktop-hsgcbep
- aefd.nelreports.net
- dns.msftncsi.com
- a39.d.akamai.net
- fxabolqytyweamarkiqmobfsx.fxabolqytyweamarkiqmobfsx
- ecs.office.com
Dropped files
- /opt/CAPEv2/storage/analyses/5253/files/92c6531a09180fae8b2aae7384b4cea9986762f0c271b35da09b4d0e733f9f45 -
92c6531a09180fae8b2aae7384b4cea9986762f0c271b35da09b4d0e733f9f45 - /opt/CAPEv2/storage/analyses/5253/files/69a51b227f1d0b3990f681ad3fe59f9c0b5c812061040ad4ed1f7efc8642afcf -
69a51b227f1d0b3990f681ad3fe59f9c0b5c812061040ad4ed1f7efc8642afcf - 0e67363a4f33a1ab07eedd8f7bac82b29e35a685617916b60a2a9b610b9df9e7 -
0e67363a4f33a1ab07eedd8f7bac82b29e35a685617916b60a2a9b610b9df9e7 - 6566e1c5985e6ed127d1d212ffcabc9dac7c6bf507bcbd39db8e2b3550e39f33 -
6566e1c5985e6ed127d1d212ffcabc9dac7c6bf507bcbd39db8e2b3550e39f33 - a93c6614b49c5a38dc9321423b4b45f5188fefe35a0672e1127bea23525a239e -
a93c6614b49c5a38dc9321423b4b45f5188fefe35a0672e1127bea23525a239e
Embedded URLs
- http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
- https://sectigo.com/CPS0
- http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl05
- http://crl.sectigo.com/SectigoPublicTimeStampingRootR46.crl0
- http://crt.sectigo.com/SectigoPublicTimeStampingRootR46.p7c0#
Embedded domains
- crl.comodoca.com
- crl.sectigo.com
- crt.sectigo.com
- sectigo.com
- crl.usertrust.com
- aefd.nelreports.net
- fxabolqytyweamarkiqmobfsx.fxabolqytyweamarkiqmobfsx
- mr-b01.tm-azurefd.net
Embedded IP addresses
- 23.33.238.116
File paths
- q:\HfGaH
More Wacatac samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report