MALICIOUS — b0f66ce6ca1fa44ee7cc6e55dafe57f9bde8303bc4d69255ade8f2d0c61e8b35
MALICIOUS — b0f66ce6ca1fa44ee7cc6e55dafe57f9bde8303bc4d69255ade8f2d0c61e8b35 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100), attributed to the Sykipot family. 4 of 52 detection engines flagged it.
Identification
- SHA-256:
b0f66ce6ca1fa44ee7cc6e55dafe57f9bde8303bc4d69255ade8f2d0c61e8b35 - SHA-1:
500c27646382c08cfc467a0a83e0bb536f4898ef - MD5:
51b7614b0934ed7d51ff2509b9208560 - imphash:
0f1f50882245365b9ce5061a60975af4 - ssdeep:
24576:HUxVQLMmGdD/rz4nro5TZhFUOW44AFyxU5Mflp:HUxVQAmGVrz4E5TZhF1W4PSp - TLSH:
T1E2538E6A00173172D5BEDD44F426CDDDC033F858A535CB899607ED9E90A9EB7BAE00A0 - Submitted as: b0f66ce6ca1fa44ee7cc6e55dafe57f9bde8303bc4d69255ade8f2d0c61e8b35
- File type: pe · Size: 1063384 bytes
- Verdict: malicious (94/100) · Family: Sykipot
Detections (4 of 52 engines)
- ClamAV (daily): Win.Dropper.Sykipot-9968241-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- LIEF (executable format parser): lief:invalid-authenticode
Why this verdict
The malicious score of 94/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Dropper.Sykipot-9968241-0 (rule
Win.Dropper.Sykipot-9968241-0) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-cs-g1.crl05
- http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
Embedded domains
- openssl.org
- field.cc
- blink.net
- thread.cc
- cacerts.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
File paths
- c:\jenkins\workspace\8-2-build-windows-amd64-cygwin\jdk8u281\880\build\windows-amd64\jdk\objs\java-rmi_objs\java-rmi.pdb
More Sykipot samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report