MALICIOUS — 797_Win32.EternalRocks.bin
MALICIOUS — 797_Win32.EternalRocks.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the EternalRocks family. 2 of 36 detection engines flagged it.
Identification
- SHA-256:
aedd0c47daa35f291e670e3feadaed11d9b8fe12c05982f16c909a57bf39ca35 - SHA-1:
8726643ad103a28f8dd3d013fabe8a839f09e060 - MD5:
406ac1595991ea7ca97bc908a6538131 - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
1536:w0H0DNPlDiSJzQhLFUaDUV/HZHjV1mb8:w0HwVB+yasvZHjV1mb8 - TLSH:
T14F35EC7CCD71C2BEFF3F46E75C124ADE217A781C18547883505C6B10E20A29B2B756AA - Submitted as: 797_Win32.EternalRocks.bin
- File type: pe · Size: 59392 bytes
- Verdict: malicious (87/100) · Family: EternalRocks
Detections (2 of 36 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:SyGc`$
- ClamAV feed: SaneSecurity foxhole_generic: Sanesecurity.Rogue.0hr.20170518-1617.EternalRocks.UNOFFICIAL
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Sanesecurity.Rogue.0hr.20170518-1617.EternalRocks.UNOFFICIAL (rule
Sanesecurity.Rogue.0hr.20170518-1617.EternalRocks.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Packing/obfuscation: high-entropy-sections:SyGc`$ - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded domains
- system.io
- myapplication.app
Embedded IP addresses
- 1.0.0.0
- 4.0.0.0
- 14.0.0.0
More EternalRocks samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report