MALICIOUS — 9cc9dc3c5ef6e3b251e424fb9a50bc89cf0d5381f988b150b74454bf6249b5ad
MALICIOUS — 9cc9dc3c5ef6e3b251e424fb9a50bc89cf0d5381f988b150b74454bf6249b5ad is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Bulz family. 7 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
9cc9dc3c5ef6e3b251e424fb9a50bc89cf0d5381f988b150b74454bf6249b5ad - SHA-1:
20e6b1bf70321610bcfa634d19a6843b1ee27116 - MD5:
1110633173fb2eaf47432c143c1d669c - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
786432:PE/vkBTmwh/FirPqk9wqdgRtz8vRmSP6xpo80442Vmh4X:0vpVrXz+t8xP6xpo8c4 - TLSH:
T1B7773348288CD126C03E30EDE53BD94F2662B11B8E7D95E86EF45474B4EDB075C2A239 - Submitted as: 9cc9dc3c5ef6e3b251e424fb9a50bc89cf0d5381f988b150b74454bf6249b5ad
- File type: pe · Size: 31170560 bytes
- Verdict: malicious (100/100) · Family: Bulz
Detections (7 of 55 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): Win.Packed.Bulz-9897681-0
- Microsoft Defender: Trojan:MSIL/Injectgen.MA!MTB
- Emsisoft (Emergency Kit): IL:Trojan.Stealer.536
- Kaspersky (KVRT): HEUR:Trojan.MSIL.Zapchast.gen
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 100/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Win.Packed.Bulz-9897681-0 (rule
Win.Packed.Bulz-9897681-0) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - Microsoft Defender flagged Trojan:MSIL/Injectgen.MA!MTB (rule
Trojan:MSIL/Injectgen.MA!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged IL:Trojan.Stealer.536 (rule
IL:Trojan.Stealer.536) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.MSIL.Zapchast.gen (rule
HEUR:Trojan.MSIL.Zapchast.gen) - engine signal, weight 0.55, confidence 0.85 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: MalwareAnalyser built-in flagged Windows_Injection_Api_Combo (rule
Windows_Injection_Api_Combo) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-sections:.text (rule
high-entropy-sections:.text) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded domains
- b.de
- uu.za
- bo.ly
- 8.br
- d.us
- 4.ly
- 3.nl
- c.de
- zm.tw
- x.co
- 1.tw
- b.de
- t.sh
File paths
- e:\nK)
- p:\/
- W:\.
- k:\~4
- F:\8
- d:\/G
- g:\5
- e:\t3A
More Bulz samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report