MALICIOUS — tsk_700918d48ebd48bd.exe
MALICIOUS — tsk_700918d48ebd48bd.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the Processhijack family. 7 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bf774633e810ca41ebbd47972e6c8c372cd45dd77647a914618cb86f0374de85 - SHA-1:
30c6fc6a6742544993879f30b4795b4d77e0ddb7 - MD5:
fad3009a8aea85402764399b992a4fd6 - imphash:
69cde517f1dded1a63d142cb349703e1 - ssdeep:
1536:/Zi59VSuW3Ip+4xxpB0TsY6DqjuKN/vVTD/ZMASQmPh:96xfuX6DqjTDxMjQmp - TLSH:
T11F397D62E39C0709EDF0A474D80D6FADC0576E4CB3742BDC265385089ADB8B7943989B - Submitted as: tsk_700918d48ebd48bd.exe
- File type: pe · Size: 86528 bytes
- Verdict: malicious (95/100) · Family: Processhijack
Detections (7 of 52 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- ClamAV (daily): Win.Trojan.Processhijack-10056424-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Trojan:Win32/ProcessHijack.GTM!MTB
- Emsisoft (Emergency Kit): Gen:Trojan.ProcessHijack.fKW@a0CCV2h
- Trellix Stinger (McAfee): Trojan-JBBC!FAD3009A8AEA
- Kaspersky (KVRT): HEUR:Trojan.Win32.Inject.gen
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 95/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Processhijack-10056424-0 (rule
Win.Trojan.Processhijack-10056424-0) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Processhijack samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report