MALICIOUS — AudioSes.dll
MALICIOUS — AudioSes.dll is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the DangerousObject family. 6 of 52 detection engines flagged it.
Identification
- SHA-256:
b77ff307ea74a3ab41c92036aea4a049b3c2e69b12a857d26910e535544dfb05 - SHA-1:
9858d5cb2a6614be3c48e33911bf9f7978b441bf - MD5:
16bbc967a8b6a365871a05c74a4f345b - imphash:
3bd6975e0677b610f43ed93a5724d417 - ssdeep:
6144:S7qE85unM8ajZScS8a+ZhcZBaHTT2Q+dFwQG/:Sz8kM8ClMomdwn/ - TLSH:
T15746AE7F919C15C2C189237CFCB41C2DC880E5DA2C59A75A1B482E4EEF4447F29A19EE - Submitted as: AudioSes.dll
- File type: pe · Size: 294400 bytes
- Verdict: malicious (99/100) · Family: DangerousObject
Detections (6 of 52 engines)
- ClamAV (daily): Win.Trojan.CobaltStrike-7899871-1
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Trojan:Win64/Triskcam!dha
- Emsisoft (Emergency Kit): Trojan.Dropper.ZGM
- Trellix Stinger (McAfee): Trojan-FQIJ!16BBC967A8B6
- Kaspersky (KVRT): UDS:DangerousObject.Multi.Generic
Why this verdict
The malicious score of 99/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Trojan.CobaltStrike-7899871-1 (rule
Win.Trojan.CobaltStrike-7899871-1) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win64/Triskcam!dha (rule
Trojan:Win64/Triskcam!dha) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Dropper.ZGM (rule
Trojan.Dropper.ZGM) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Trojan-FQIJ!16BBC967A8B6 (rule
Trojan-FQIJ!16BBC967A8B6) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:DangerousObject.Multi.Generic (rule
UDS:DangerousObject.Multi.Generic) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More DangerousObject samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report