MALICIOUS — 559_PotaoExpress.bin
MALICIOUS — 559_PotaoExpress.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the Potao family. 3 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
aa23a93d2fed81daacb93ea7ad633426e04fcd063ff2ea6c0af5649c6cfa0385 - SHA-1:
94bbf39fff09b3a62a583c7d45a00b2492102dd7 - MD5:
1927a80cd45f0d27b1ae034c11ddedb0 - imphash:
a9aba99e03845faab8cddded800bbfe9 - ssdeep:
3072:1x9Tn1i/ir8OlC9raZige0DGqiNJ07TIQ+:L9TngGDsiiLJ4y - TLSH:
T1FA3BAEAC430BA74FE2F3EB5028501F1E9416E59ED4FE7A0D5793E02D2BDA9678538101 - Submitted as: 559_PotaoExpress.bin
- File type: pe · Size: 104960 bytes
- Verdict: malicious (87/100) · Family: Potao
Detections (3 of 51 engines)
- Microsoft Defender: TrojanDropper:Win32/Potao.D!dha
- Emsisoft (Emergency Kit): Gen:Variant.Potao.12
- Trellix Stinger (McAfee): Generic Trojan.hg
MITRE ATT&CK
Why this verdict
The malicious score of 87/100 is the fusion of 5 weighted signals:
- Microsoft Defender flagged TrojanDropper:Win32/Potao.D!dha (rule
TrojanDropper:Win32/Potao.D!dha) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Potao.12 (rule
Gen:Variant.Potao.12) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Generic Trojan.hg (rule
Generic Trojan.hg) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (windows)
50 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- searchapp.bundleassets.example
- inference.location.live.net
- desktop-hsgcbep
- v10.events.data.microsoft.com
- config.edge.skype.com
- login.live.com
- settings-win.data.microsoft.com
- www.bing.com
- fd.api.iris.microsoft.com
- windows.msn.com
- officeclient.microsoft.com
- licensing.mp.microsoft.com
- msedge.api.cdp.microsoft.com
- sdx.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- nav.smartscreen.microsoft.com
- assets.msn.com
- dns.msftncsi.com
- watson.events.data.microsoft.com
Embedded domains
- inference.location.live.net
- aefd.nelreports.net
Embedded IP addresses
- 162.159.36.2
More Potao samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report