MALICIOUS — ad0529a80a1a00e7b7f65e3027a1d7199acb76986e60bcf435a6237bc70602da
MALICIOUS — ad0529a80a1a00e7b7f65e3027a1d7199acb76986e60bcf435a6237bc70602da is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the Gupboot family. 6 of 24 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ad0529a80a1a00e7b7f65e3027a1d7199acb76986e60bcf435a6237bc70602da - SHA-1:
4f03531c95d64543ce3cbaa1c200dd84c0519c68 - MD5:
8c856f7d8338453956e235da002060be - imphash:
e296f3e0d8a2821d5e0a3719d2e0e79d - ssdeep:
6144:oo3wBi+1Py3V0a2WkRNgi3caOHO5NjEwwiYWB5mV4Pzw9ygibGGMIG:rKf1PyKa2H3hOHOHz9JQ6zBnG - TLSH:
T1764ACF8D82F96784E7E3C7202E144F0E64F2ACDDE0BE5D450A83D02E27D291BD5D219A - Submitted as: ad0529a80a1a00e7b7f65e3027a1d7199acb76986e60bcf435a6237bc70602da
- File type: pe · Size: 453282 bytes
- Verdict: malicious (95/100) · Family: Gupboot
Detections (6 of 24 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- Microsoft Defender: Trojan:Win32/Urelas!pz
- Trellix Stinger (McAfee): Gupboot!8C856F7D8338
- Kaspersky (KVRT): Rootkit.Win32.Plite.pfl
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 95/100 is the fusion of 7 weighted signals:
- Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - Microsoft Defender flagged Trojan:Win32/Urelas!pz (rule
Trojan:Win32/Urelas!pz) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Gupboot!8C856F7D8338 (rule
Gupboot!8C856F7D8338) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 1.234.83.146, 133.242.129.155, 218.54.31.226 - static signal, weight 0.35, confidence 0.60
- inject code into another process (rule
inject code into another process) - capa signal, weight 0.12, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded IP addresses
- 1.234.83.146
- 133.242.129.155
- 218.54.31.226
- 218.54.31.165
File paths
- X:\:`:d:h:l:p:t:x:
More Gupboot samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report