MALICIOUS — 774_Win32.Cutwail.bin
MALICIOUS — 774_Win32.Cutwail.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Cutwail family. 6 of 52 detection engines flagged it.
Identification
- SHA-256:
a9e167f6ca25c8660a7571bc8d628c397407478a1cea1c8764ba43ec61724bbf - SHA-1:
2a219237d184a9b6dbfe44fcb90174ccc27d5a3b - MD5:
4644e2527025331e7f2107730aab9bbe - imphash:
cadb1fc8f06478e8597f01b0f5c528c3 - ssdeep:
384:hdqL2Uwbgo4hH7PEUzjp1FGcz2PZubotzX0N/0SjyWde2jWTMdL1a:M2U8VAva6GjGFjyWdR6IdL1 - TLSH:
T19E2CBFF5272A1396C899F5150CC1E22C86D5FB6167BC2C51C232F6341A6647FE8B3A0E - Submitted as: 774_Win32.Cutwail.bin
- File type: pe · Size: 26624 bytes
- Verdict: malicious (99/100) · Family: Cutwail
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): {MD5}bin.trojan.agent.7529.UNOFFICIAL
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: TrojanDownloader:Win32/Cutwail.gen!C
- Emsisoft (Emergency Kit): Gen:Variant.Razy.676361
- Kaspersky (KVRT): Packed.Win32.Krap.ao
Why this verdict
The malicious score of 99/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged {MD5}bin.trojan.agent.7529.UNOFFICIAL (rule
{MD5}bin.trojan.agent.7529.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 7 finding(s), e.g. process hollowing in svchost.exe (pid 9008) (rule
windows.hollowprocesses.HollowProcesses) - memory signal, weight 0.70, confidence 0.85 - Microsoft Defender flagged TrojanDownloader:Win32/Cutwail.gen!C (rule
TrojanDownloader:Win32/Cutwail.gen!C) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Razy.676361 (rule
Gen:Variant.Razy.676361) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Packed.Win32.Krap.ao (rule
Packed.Win32.Krap.ao) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- none
Dropped files
- 4727bf625962d794b1786b48d607e41f33dde371318ed71995785a52d634238d -
4727bf625962d794b1786b48d607e41f33dde371318ed71995785a52d634238d
More Cutwail samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report