MALICIOUS — 129_EarthKrahang_20240404.bin
MALICIOUS — 129_EarthKrahang_20240404.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Doina family. 3 of 35 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
9d4e18ae979bdf6b57e685896b350b23c428d911eee14af133c3ee7d208f8a82 - SHA-1:
19da27f2ab24e5a9a3a08cdfa6461f0a1fceef2e - MD5:
ed7f22e1cc435c1d6ed7f20bd57d3962 - imphash:
fa041661526f5e4a92b502e172a4567b - ssdeep:
3072:Q3flkgIylqdMsfT80SCxuskKuVLUqlX/Pb70:Q3flkFeq3fT8Uxusk9LDbQ - TLSH:
T12D3C6B59861B3622F1B7EA0CBC608EDD8822F45CA472914E6703D9BD90F2E33D8F6155 - Submitted as: 129_EarthKrahang_20240404.bin
- File type: pe · Size: 123056 bytes
- Verdict: malicious (97/100) · Family: Doina
Detections (3 of 35 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- capa (capabilities): inject code into another process
- ClamAV (daily): Win.Malware.Doina-10025202-0
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 97/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Malware.Doina-10025202-0 (rule
Win.Malware.Doina-10025202-0) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - inject code into another process (rule
inject code into another process) - capa signal, weight 0.50, confidence 0.80 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://ocsp.globalsign.com/rootr103
- http://crl.globalsign.com/root.crl0Y
- https://www.globalsign.com/repository/0
- http://ocsp2.globalsign.com/gscodesigng30V
- http://crl.globalsign.com/gs/gscodesigng3.crl0
- https://www.digicert.com/CPS0
- http://ocsp.digicert.com0A
- http://www.digicert.com/ssl-cps-repository.htm0
- http://ocsp.digicert.com0C
Embedded domains
- schemas.microsoft.com
- ocsp.globalsign.com
- crl.globalsign.com
- www.globalsign.com
- secure.globalsign.com
- ocsp2.globalsign.com
- crl.microsoft.com
- www.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- cacerts.digicert.com
- ocsp.digicert.com0a
- ocsp.digicert.com0c
More Doina samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report