MALICIOUS — 553_PotaoExpress.bin
MALICIOUS — 553_PotaoExpress.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the Potao family. 4 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b62589ee5ba94d15edcf8613e3d57255dd7a12fce6d2dbd660fd7281ce6234f4 - SHA-1:
12240271e928979ab2347c29b5599d6ac7cd6b8e - MD5:
11b4e7ea6bae19a29343ae3ff3fb00ca - imphash:
28160afac4b60d207256e4254513bee2 - ssdeep:
3072:c8sHkfrSowuAHI5tfbVOqN0LZIJs9E0ma:ctEfOYb0JLJ9EHa - TLSH:
T1253DAE4C08197707C3BBEA205E415F0CE022A4D9597EB5989C83C5EF76F382BDAB4856 - Submitted as: 553_PotaoExpress.bin
- File type: pe · Size: 134144 bytes
- Verdict: malicious (95/100) · Family: Potao
Detections (4 of 52 engines)
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: TrojanDropper:Win32/Potao.D!dha
- Emsisoft (Emergency Kit): Gen:Variant.Potao.18
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 6 weighted signals:
- Memory forensics: 3 finding(s), e.g. RWX/private injected region in sppsvc.exe (pid 9200) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged TrojanDropper:Win32/Potao.D!dha (rule
TrojanDropper:Win32/Potao.D!dha) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Potao.18 (rule
Gen:Variant.Potao.18) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win32.Generic (rule
HEUR:Trojan.Win32.Generic) - engine signal, weight 0.55, confidence 0.85 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
6111 behavior events · 1 ATT&CK techniques · 4 dropped files.
Runtime network
- none
Dropped files
- /opt/CAPEv2/storage/analyses/6078/files/a4f9f288df3f8c1eb414422650c5c1492c48ba8500e32293d27d126d04e68f12 -
a4f9f288df3f8c1eb414422650c5c1492c48ba8500e32293d27d126d04e68f12 - 27e7111794f169bb92956982d853ca84885cb94fb42b87150f6dd6697b17e161 -
27e7111794f169bb92956982d853ca84885cb94fb42b87150f6dd6697b17e161 - f1b07e13785ba57c8faeb2045b9b38acbf392ad7c8617abb4a85b71c982668e8 -
f1b07e13785ba57c8faeb2045b9b38acbf392ad7c8617abb4a85b71c982668e8 - 2c50c905c1019370a2f4b314ff878506cb9ce7173a952fa9887e7541d0fc8721 -
2c50c905c1019370a2f4b314ff878506cb9ce7173a952fa9887e7541d0fc8721
File paths
- T:\:d:l:t:
More Potao samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report