MALICIOUS — 9cd9554b9ed38e97489067c0a0cba8569fac605c2f1477e1cd6bc0cf61533d4d
MALICIOUS — 9cd9554b9ed38e97489067c0a0cba8569fac605c2f1477e1cd6bc0cf61533d4d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Mansabo family. 6 of 56 detection engines flagged it.
Identification
- SHA-256:
9cd9554b9ed38e97489067c0a0cba8569fac605c2f1477e1cd6bc0cf61533d4d - SHA-1:
1b0bf6b338cfa5222ddbdbb0bd94a87b45dce298 - MD5:
12ff087658021ebd9068469d4942fb14 - imphash:
500dc0c0888bd55c4e50048a30cd52d7 - ssdeep:
49152:GezaTF8FcNkNdfE0pZ9oztFwIRMmSdbbUGsy/m:GemTLkNdfE0pZaF - TLSH:
T1BE59E0B940535460E4F9DCD8ADA0DCEE9255F4AC69328C5CF26BDE8CC0D82BF99D0498 - Submitted as: 9cd9554b9ed38e97489067c0a0cba8569fac605c2f1477e1cd6bc0cf61533d4d
- File type: pe · Size: 1872118 bytes
- Verdict: malicious (99/100) · Family: Mansabo
Detections (6 of 56 engines)
- ClamAV (daily): Win.Malware.Mansabo-7102049-0
- YARA: Intezer community: INTEZER_Linux_XMRig_Miner
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Trojan:Win64/CoinMiner
- Kaspersky (KVRT): Trojan.Win32.Mansabo.btu
Why this verdict
The malicious score of 99/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Malware.Mansabo-7102049-0 (rule
Win.Malware.Mansabo-7102049-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win64/CoinMiner (rule
Trojan:Win64/CoinMiner) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Mansabo.btu (rule
Trojan.Win32.Mansabo.btu) - engine signal, weight 0.55, confidence 0.85 - YARA: Intezer community flagged INTEZER_Linux_XMRig_Miner (rule
INTEZER_Linux_XMRig_Miner) - engine signal, weight 0.65, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 3.120.209.58 - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded domains
- donate.v2.xmrig.com
Embedded IP addresses
- 3.120.209.58
File paths
- C:\Windows\System\
- C:\Program
More Mansabo samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report