MALICIOUS — 506_PotaoExpress.bin
MALICIOUS — 506_PotaoExpress.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Potao family. 6 of 52 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
b9c285f485421177e616a148410ddc5b02e43f0af375d3141b7e829f7d487bfd - SHA-1:
2cdd6aabb71fdb244baa313ebba13f06bcad2612 - MD5:
73e7ee83133a175b815059f1af79ab1b - imphash:
541f8571e1633593d73c9704f161a022 - ssdeep:
3072:8FKaPK5GuzEUvdvMqz83KYW5tVnrW6Ab:8FxK5XvqH6dvrW6Ab - TLSH:
T1833CD0A8052F7745E7F7DBD57C911E1E9023B4D9A4BF1A0C2A83D05E52E28B3D8B1089 - Submitted as: 506_PotaoExpress.bin
- File type: pe · Size: 114176 bytes
- Verdict: malicious (99/100) · Family: Potao
Detections (6 of 52 engines)
- capa (capabilities): capability:credential-access
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: TrojanDropper:Win32/Potao.E!dha
- Emsisoft (Emergency Kit): Trojan.Agent.BZWS
- Trellix Stinger (McAfee): Generic Trojan.hg
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- Microsoft Defender flagged TrojanDropper:Win32/Potao.E!dha (rule
TrojanDropper:Win32/Potao.E!dha) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Agent.BZWS (rule
Trojan.Agent.BZWS) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Generic Trojan.hg (rule
Generic Trojan.hg) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win32.Generic (rule
HEUR:Trojan.Win32.Generic) - engine signal, weight 0.55, confidence 0.85 - Dropped a suspicious payload: b9c285f485421177e616a148410ddc5b02e43f0af375d3141b7e829f7d487bfd - dynamic signal, weight 0.50, confidence 0.90
- access stored credentials (rule
access stored credentials) - capa signal, weight 0.50, confidence 0.80 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
15673 behavior events · 2 ATT&CK techniques · 6 dropped files.
Runtime network
- none
Dropped files
- /opt/CAPEv2/storage/analyses/6090/files/080a60482d3ab5b1b8b5abf5b2cf0c0a621cee1da7a6775cf6ba6e70cac409ef -
080a60482d3ab5b1b8b5abf5b2cf0c0a621cee1da7a6775cf6ba6e70cac409ef - /opt/CAPEv2/storage/analyses/6090/files/b9c285f485421177e616a148410ddc5b02e43f0af375d3141b7e829f7d487bfd -
b9c285f485421177e616a148410ddc5b02e43f0af375d3141b7e829f7d487bfd - /opt/CAPEv2/storage/analyses/6090/files/5f345202887517222270db35604adcb762278fb29a29bec16ca4a2b8dddf657f -
5f345202887517222270db35604adcb762278fb29a29bec16ca4a2b8dddf657f - 63de1e5c29b434b75ba21099c40996e10d456c97989803e75a8a2fb7025f4542 -
63de1e5c29b434b75ba21099c40996e10d456c97989803e75a8a2fb7025f4542 - 5ffe9095245d7801316749ee842e5dcd9be33d2caea93b8fd9407c0abbd786e9 -
5ffe9095245d7801316749ee842e5dcd9be33d2caea93b8fd9407c0abbd786e9 - c8d4960ff737d369095c132c21eaed2948ed03abd99350a938064dbe58aa73d6 -
c8d4960ff737d369095c132c21eaed2948ed03abd99350a938064dbe58aa73d6
More Potao samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report