MALICIOUS — 9bae68e13c60e8908b606ff059c717587b1fc78c7cce6d32270413279b281985
MALICIOUS — 9bae68e13c60e8908b606ff059c717587b1fc78c7cce6d32270413279b281985 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the Vobfus family. 7 of 52 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
9bae68e13c60e8908b606ff059c717587b1fc78c7cce6d32270413279b281985 - SHA-1:
eb014fa201a3ee444f720c8d449149368abd15cc - MD5:
f3475b2fad2116689b181133f44b7969 - imphash:
3f92177474a00f02451a855b96e05f57 - ssdeep:
3072:3Hjk+0oLnWFnzBHv/xWFsg8WatFBGFVWPE5ac0pG/1z+QVMbg1:Xo/BHng5HaVG4G/1z+QVMbg1 - TLSH:
T14B428D8B3A29EE42E2E7DA075D04FDBD208F5897263AF5682AD9D51E44C327B043113D - Submitted as: 9bae68e13c60e8908b606ff059c717587b1fc78c7cce6d32270413279b281985
- File type: pe · Size: 204800 bytes
- Verdict: malicious (96/100) · Family: Vobfus
Detections (7 of 52 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Worm.Vobfus-7513439-0
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Worm:Win32/Cambot.A
- Emsisoft (Emergency Kit): Trojan.GenericKD.50020741
- Kaspersky (KVRT): Trojan.Win32.Llac.llzl
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Worm.Vobfus-7513439-0 (rule
Win.Worm.Vobfus-7513439-0) - engine signal, weight 0.90, confidence 0.95 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: delivr.to detections flagged DLV_Maldoc_VBA_AutoExec (rule
DLV_Maldoc_VBA_AutoExec) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://www.facebook.com/?ref=home, http://www.facebook.com - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.facebook.com/?ref=home
- http://www.facebook.com
Embedded domains
- www.facebook.com
- bankofamerica.com
Registry keys
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
File paths
- C:\Program
- C:\Windows\SysWOW64\ieframe.dll
More Vobfus samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report