MALICIOUS — 542_PotaoExpress.bin
MALICIOUS — 542_PotaoExpress.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the Potao family. 3 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c821cb34c86ec259af37c389a8f6cd635d98753576c675882c9896025a1abc53 - SHA-1:
73a4a6864ef68c810c7c699ed51b759cf1c4adfb - MD5:
bdc9255df5385f534fea83b497c371c8 - imphash:
d1122623188e190d6a1690c523ea4c0f - ssdeep:
768:5Iq2pRHAjPP7xldWFhiIq8C7f5MYBFC2PV6JxJohF4TwFxmDOl2RtLbuuu:ydPHs8FHC7hMYnCAwJxiYcYDOl2RtL - TLSH:
T11834AFCE7236164FF8C71B1754A24D4E3032B1E991A24B08EEC7E79E8134C5758E6E62 - Submitted as: 542_PotaoExpress.bin
- File type: pe · Size: 52736 bytes
- Verdict: malicious (93/100) · Family: Potao
Detections (3 of 51 engines)
- Microsoft Defender: TrojanDropper:Win32/Potao.D!dha
- Emsisoft (Emergency Kit): Gen:Variant.Potao.8
- Trellix Stinger (McAfee): Trojan-FGWR!BDC9255DF538
MITRE ATT&CK
Why this verdict
The malicious score of 93/100 is the fusion of 6 weighted signals:
- Microsoft Defender flagged TrojanDropper:Win32/Potao.D!dha (rule
TrojanDropper:Win32/Potao.D!dha) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Potao.8 (rule
Gen:Variant.Potao.8) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Trojan-FGWR!BDC9255DF538 (rule
Trojan-FGWR!BDC9255DF538) - engine signal, weight 0.55, confidence 0.85 - Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (windows)
66 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- searchapp.bundleassets.example
- desktop-hsgcbep
- v10.events.data.microsoft.com
- login.live.com
- config.edge.skype.com
- fd.api.iris.microsoft.com
- www.bing.com
- licensing.mp.microsoft.com
- settings-win.data.microsoft.com
- windows.msn.com
- officeclient.microsoft.com
- dns.msftncsi.com
- fe3cr.delivery.mp.microsoft.com
- assets.msn.com
- g.live.com
- ecs.office.com
- watson.events.data.microsoft.com
- msedge.api.cdp.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/6068/files/9ce3c8ae2c0664868ceabdec3b16614e9147695eb061ff0a96119dfbeeca585d -
9ce3c8ae2c0664868ceabdec3b16614e9147695eb061ff0a96119dfbeeca585d - 2c4e2adb77ab2c3da8c8896338e67a0025fbfb6ebf9359fdaf4d6d33494f7f51 -
2c4e2adb77ab2c3da8c8896338e67a0025fbfb6ebf9359fdaf4d6d33494f7f51 - 711ff03d4f08c622189ae32911a30371b59d135fd2d0cf81d051827baac15e07 -
711ff03d4f08c622189ae32911a30371b59d135fd2d0cf81d051827baac15e07
Embedded domains
- inference.location.live.net
Embedded IP addresses
- 162.159.36.2
File paths
- E:\svn\sapotao\BIN\node69-dropper.pdb
- V:\:j:p:w:
More Potao samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report