MALICIOUS — unins000.exe
MALICIOUS — unins000.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (74/100), attributed to the Container family. 3 of 55 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
bd6f83e869c2554e9c69ad385420335b0b7041fdd53ba06e2b21ce943cd53ca9 - SHA-1:
98eb2c8511918ec8d47ac75a215656b5ba84cb35 - MD5:
004133e2fd10ea66c0eb7acd55a00878 - imphash:
4f3a70412c909e6e8f69020f0bee4f39 - ssdeep:
98304:kYU5hnuOajWwMPdCpepI3GrwrA+Jm333EmQx6DY:ExuHjWfZIzuDY - TLSH:
T145625ADF56173613E779C3044534EABF48F7F85B027B688C01A7892EEAF54132A6052A - Submitted as: unins000.exe
- File type: pe · Size: 4558246 bytes
- Verdict: malicious (74/100) · Family: Container
Detections (3 of 55 engines)
- capa (capabilities): capability:collection/keylog
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
MITRE ATT&CK
Why this verdict
The malicious score of 74/100 is the fusion of 6 weighted signals:
- capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: https://www.innosetup.com/, https://www.remobjects.com/ps, http://www.dk-soft.org/ - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- https://www.innosetup.com/
- https://www.remobjects.com/ps
- http://www.dk-soft.org/
Embedded domains
- schemas.microsoft.com
- vnd.ahead.space
- vnd.digital
- vnd.net
- vnd.sun.j2me.app
- www.innosetup.com
- www.remobjects.com
- www.dk-soft.org
File paths
- T:\:`:d:h:l:p:t:x:
- M:\:d:r:
- X:\:t:
- X:\:`:d:h:l:p:t:x:
- N:\:j:
- X:\:`:m:
- L:\:d:h:l:t:x:
- X:\:`:n:
- J:\:v:
- T:\:d:l:t:
- X:\:d:l:p:t:x:
- K:\:j:r:
- X:\:`:d:
- J:\:
- J:\:q:
- U:\:f:j:
- X:\:`:d:h:p:t:x:
- T:\:d:h:l:p:t:x:
- X:\:k:w:~:
- T:\:}:
- L:\:a:q:v:
- X:\:`:d:h:l:p:t:
- U:\:
- L:\:d:l:t:x:
- X:\:`:d:h:
More Container samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report