MALICIOUS — aa223638cd0363efd4195a0081ff36b953c45b36b2bc1dca0aba27ded47259bd.bin
MALICIOUS — aa223638cd0363efd4195a0081ff36b953c45b36b2bc1dca0aba27ded47259bd.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the Wacatac family. 7 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
aa223638cd0363efd4195a0081ff36b953c45b36b2bc1dca0aba27ded47259bd - SHA-1:
334250dac756bfa665aeea509b0660f8b7945733 - MD5:
2cfe98bab49dca2acdbef9ef5dfe6521 - imphash:
9be4f90f50c714bc00cc8beb2e137299 - ssdeep:
12288:KrZRD+8idy7j40JXwTWaA7V7Z3a13zdVlAptU+vR17F+ZoXfAHu7Cm5:K7D+Po4CwT/+Vlad/sVnFcnHuGm5 - TLSH:
T1064F120A89362E04CEF16D28DD424E5FD301976225BCDC64D763863AFCBF42B46A7462 - Submitted as: aa223638cd0363efd4195a0081ff36b953c45b36b2bc1dca0aba27ded47259bd.bin
- File type: pe · Size: 750928 bytes
- Verdict: malicious (91/100) · Family: Wacatac
Source: MalShare · first seen 2026-07-31T00:14:46.945Z · SHA-256 verified
Detections (7 of 53 engines)
- capa (capabilities): capability:collection/keylog
- MalwareAnalyser heuristics (entropy/packer): Windows Authenticode
- Detect It Easy (packer/type): DIE:Windows Authenticode
- LIEF (executable format parser): lief:invalid-authenticode
- Microsoft Defender: Trojan:Win32/Wacatac.B!ml
- Emsisoft (Emergency Kit): Trojan.GenericKD.80986569
- Kaspersky (KVRT): Trojan-Downloader.Win32.Minix.cyz
MITRE ATT&CK
Why this verdict
The malicious score of 91/100 is the fusion of 8 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Wacatac.B!ml (rule
Trojan:Win32/Wacatac.B!ml) - engine signal, weight 0.55, confidence 0.85 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 18 external host(s) at runtime (2 HTTP) - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:Windows Authenticode (rule
DIE:Windows Authenticode) - engine signal, weight 0.35, confidence 0.70 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://nsis.sf.net/NSIS_Error - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: Windows Authenticode - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
10661 behavior events · 1 ATT&CK techniques · 10 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- v10.events.data.microsoft.com
- login.live.com
- v20.events.data.microsoft.com
- desktop-hsgcbep
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- watson.events.data.microsoft.com
- ceuswatcab01.blob.core.windows.net
- g.live.com
- oneclient.sfx.ms
- self.events.data.microsoft.com
- http://www.msftconnecttest.com/connecttest.txt
Dropped files
- /opt/CAPEv2/storage/analyses/5533/files/47fb90afa9dcccdfc53368e9e170e9ee3ff626f36750a5bbb76d576a374eee9d -
47fb90afa9dcccdfc53368e9e170e9ee3ff626f36750a5bbb76d576a374eee9d - /opt/CAPEv2/storage/analyses/5533/files/356be165de128a2a2eb68a7b0522ff5ff330c0c244e0c73c676c037cf7ab4ceb -
356be165de128a2a2eb68a7b0522ff5ff330c0c244e0c73c676c037cf7ab4ceb - /opt/CAPEv2/storage/analyses/5533/files/f6d3bf51f916decc49f083d8eb3e7ae5c39255247dd2b162fdfdbd44953e946a -
f6d3bf51f916decc49f083d8eb3e7ae5c39255247dd2b162fdfdbd44953e946a - /opt/CAPEv2/storage/analyses/5533/files/cfec0c35cf34efa4a9c26b7e87020f19359c07b1a4290c7db39147016201cdbc -
cfec0c35cf34efa4a9c26b7e87020f19359c07b1a4290c7db39147016201cdbc - /opt/CAPEv2/storage/analyses/5533/files/f6fca0db373c500aef717fee5324e1a541ac557ef4eb861fce6a9a089445f7cd -
f6fca0db373c500aef717fee5324e1a541ac557ef4eb861fce6a9a089445f7cd - /opt/CAPEv2/storage/analyses/5533/files/735b6c229930767a14914143fb2a5e73ec331d8476964c9b91110ee568a72afb -
735b6c229930767a14914143fb2a5e73ec331d8476964c9b91110ee568a72afb - /opt/CAPEv2/storage/analyses/5533/files/f9e4d9ac675df8625d182b21cf9f9d714a278f171f26937948452c2a52fb7153 -
f9e4d9ac675df8625d182b21cf9f9d714a278f171f26937948452c2a52fb7153 - /opt/CAPEv2/storage/analyses/5533/files/33b570d86c4aac8c6785944f9b2992dc3eccc99e35c20ab79d81917bbef35622 -
33b570d86c4aac8c6785944f9b2992dc3eccc99e35c20ab79d81917bbef35622 - 384835c3156f69f91f94969ba84797300fa7c7056d9d43aa30896df434e6a41f -
384835c3156f69f91f94969ba84797300fa7c7056d9d43aa30896df434e6a41f - 3e3b135f323bd8a3f00b8aca5403143646bcb0db557e90505307ef9b14ea00a7 -
3e3b135f323bd8a3f00b8aca5403143646bcb0db557e90505307ef9b14ea00a7
Embedded URLs
- http://nsis.sf.net/NSIS_Error
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- f.ml
- nsis.sf.net
- inference.location.live.net
- oneclient.sfx.ms
Embedded IP addresses
- 23.40.52.209
- 52.168.117.174
- 20.184.175.5
- 52.123.252.245
- 52.230.59.222
- 4.230.171.124
- 23.33.238.116
- 135.233.45.221
- 51.104.15.253
- 150.171.109.25
- 57.150.192.97
- 23.46.179.24
- 23.40.52.69
- 52.110.12.22
- 52.110.12.40
- 40.126.14.164
- 184.84.165.136
- 23.198.40.44
More Wacatac samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report