MALICIOUS — c41b6e30a9d1d1232f59bd76902eac6037114da14dad47731b848e93aa9f2427
MALICIOUS — c41b6e30a9d1d1232f59bd76902eac6037114da14dad47731b848e93aa9f2427 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Pumoo family. 7 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
c41b6e30a9d1d1232f59bd76902eac6037114da14dad47731b848e93aa9f2427 - SHA-1:
9124e8582c376a9a308af377f5ba6093f43a8d84 - MD5:
8b29e1d0e490efc415b2d03757b0e17b - imphash:
a96d166ab17e011e8049d87211158ae5 - ssdeep:
96:KiNN2tdaQIBbmIWaYFXwD1coKdxE8raaQiv/FBgU:KiIdnedWFFX03KP9Qiv/F6U - TLSH:
T11A1F091276105BD5D343F092E497CE1DC7A70D4697AA2E8C591358AFE3DA1073C4198F - Submitted as: c41b6e30a9d1d1232f59bd76902eac6037114da14dad47731b848e93aa9f2427
- File type: pe · Size: 7680 bytes
- Verdict: malicious (97/100) · Family: Pumoo
Detections (7 of 52 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- ClamAV (daily): Win.Worm.Pumoo-1
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- Microsoft Defender: Worm:Win32/Plurp.A
- Emsisoft (Emergency Kit): Generic.Malware.SMe.762D8D78
- Kaspersky (KVRT): Email-Worm.Win32.Plemood.b
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 97/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Worm.Pumoo-1 (rule
Win.Worm.Pumoo-1) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - inject code into another process (rule
inject code into another process) - capa signal, weight 0.12, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- pact518.hit.edu.cn
File paths
- d:\test
- C:\Windows\system32\PurpleMood.scr
More Pumoo samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report