MALICIOUS — b83e92827a774505824298a442c6d9d7c7c6ec53d81ba35a782fe0121b4f41be
MALICIOUS — b83e92827a774505824298a442c6d9d7c7c6ec53d81ba35a782fe0121b4f41be is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (90/100), attributed to the Rozena family. 5 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b83e92827a774505824298a442c6d9d7c7c6ec53d81ba35a782fe0121b4f41be - SHA-1:
7255b2214a553047aa62eaf2e61eef5cd8b7369b - MD5:
f1f5d9cf90b71da21c6d3a0ae24a17e2 - imphash:
93a138801d9601e4c36e6274c8b9d111 - ssdeep:
12288:bYe1CsYe7dbCbYZryJP0sp+LY07RjKs6mv2zoPdpINpbP/9yLbSdkqyxGLoh8M5:zj5ebYE50H6o+8jIPELbSxs6oh75 - TLSH:
T1DE584BA4821B1411F0F59D50F42285DC9C4BB98AE33129CC9296ED7A11CEF7BE3A7097 - Submitted as: b83e92827a774505824298a442c6d9d7c7c6ec53d81ba35a782fe0121b4f41be
- File type: pe · Size: 1683968 bytes
- Verdict: malicious (90/100) · Family: Rozena
Detections (5 of 55 engines)
- ClamAV (daily): Win.Malware.Rozena-9975383-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Trojan:Win32/Wacatac.B!ml
- Emsisoft (Emergency Kit): Gen:Variant.Bulz.303426
- Kaspersky (KVRT): HEUR:Trojan.Win64.Goshell.gen
MITRE ATT&CK
Why this verdict
The malicious score of 90/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Malware.Rozena-9975383-0 (rule
Win.Malware.Rozena-9975383-0) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- reflect.name
- runtime.name
- atomic.store
- runtime.name.name
- reflectlite.name.name
- reflect.name.name
- go.xn--9tr.com
More Rozena samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report