MALICIOUS — account-report.txt .pif
MALICIOUS — account-report.txt .pif is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Mytob family. 6 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b06840dad794177214c84540a83a32df9cdb76b2343e4533597cdba5cbfa892c - SHA-1:
e101329b664372951b248882b6154a217ddc99e2 - MD5:
0ab51a0826abca7ad25fb3e5797a8f09 - imphash:
7a7803027531302026dedc7b5f6025f2 - ssdeep:
768:w+4kWKXwZqZO1T9i9Bxs8jGnA2xbNwJeeN88G/mS9OkasoizzQcX:1/AEibXjFNww8gQXsffv - TLSH:
T1522FE12ADC6DA401E804F7447C0B4EDE57526F6389B3479BBE8065B76C3893B50C8B92 - Submitted as: account-report.txt .pif
- File type: pe · Size: 33280 bytes
- Verdict: malicious (99/100) · Family: Mytob
Detections (6 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Worm.Mytob-256
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Worm:Win32/Mytob.LT@mm
- Emsisoft (Emergency Kit): Trojan.GenericKD.75287192
- Kaspersky (KVRT): Net-Worm.Win32.Mytob.cz
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Worm.Mytob-256 (rule
Win.Worm.Mytob-256) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Worm:Win32/Mytob.LT@mm (rule
Worm:Win32/Mytob.LT@mm) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.GenericKD.75287192 (rule
Trojan.GenericKD.75287192) - engine signal, weight 0.55, confidence 0.85 - Memory forensics: 4 finding(s), e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.55, confidence 0.85 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1,UPX2, Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
17 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- none
More Mytob samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report