MALICIOUS — cbba704df6150e737b7c4169ac8c1f3365a660b2c41a42719c00cbe22acbdd24
MALICIOUS — cbba704df6150e737b7c4169ac8c1f3365a660b2c41a42719c00cbe22acbdd24 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Emotet family. 10 of 52 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
cbba704df6150e737b7c4169ac8c1f3365a660b2c41a42719c00cbe22acbdd24 - SHA-1:
a0ca3cba11b69a88d6d638cdfe458a96a4454fd6 - MD5:
063712fb905f1f1ad8cef011ed554205 - imphash:
3e4757b6c44f364955a909104e3b2b4d - ssdeep:
49152:a8fIfw2mSdbDUAsHpD+bsxctZE+OM2EsT/HBJJdMmepI9g4pn0ekPy5JWkhPTH+V:aUUbYZfgs0QlxE - TLSH:
T109643ACD872B6222F2B6D814AC1DD9DC84A2F458507AE78D8B47882F40E313BEDF1556 - Submitted as: cbba704df6150e737b7c4169ac8c1f3365a660b2c41a42719c00cbe22acbdd24
- File type: pe · Size: 5476865 bytes
- Verdict: malicious (98/100) · Family: Emotet
Detections (10 of 52 engines)
- capa (capabilities): capability:credential-access
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Genpack-9875154-0
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Detect It Easy (packer/type): DIE:VMProtect
- Microsoft Defender: Trojan:Win32/Ausiv
- Emsisoft (Emergency Kit): GenPack:Trojan.Agent.EXMP
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Win.Malware.Genpack-9875154-0 (rule
Win.Malware.Genpack-9875154-0) - engine signal, weight 0.90, confidence 0.95 - access stored credentials (rule
access stored credentials) - capa signal, weight 0.50, confidence 0.80 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:VMProtect (rule
DIE:VMProtect) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://creativecommons.org/publicdomain/zero/1.0/, https://www.gnu.org/software/automake/manual/automake.html, http://fsmsh.com/2753 - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: high-entropy-sections:.lol 1, VMProtect - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- https://www.gnu.org/software/automake/manual/automake.html
- http://fsmsh.com/2753
- https://autotools.io/index.html
- http://miller.emu.id.au/pmiller/books/rmch/
- http://www.w3.org/Consortium/Legal/2002/copyright-software-20021231
- http://www.linuxnet.com
- http://relaxngcc.sf.net/
- http://www.mozilla.org/MPL/
- http://www.unicode.org/Public/
- http://www.unicode.org/reports/
- http://www.unicode.org/cldr/data/
- http://www.unicode.org/copyright.html
- http://wildsau.idv.uni-linz.ac.at/mfx/upx.html
- http://www.nexus.hu/upx
- http://upx.tsx.org
- http://upx.sourceforge.net/upx-license.html
- http://www.xfree86.org/
- http://www.sgi.com/software/opensource/glx/license.html
- http://www.sgi.com/software/opensource/cid/license.html
- http://www.apache.org/licenses/
- http://www.apache.org/licenses/LICENSE-2.0
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
Embedded domains
- creativecommons.org
- geocities.com
- www.gnu.org
- fsmsh.com
- autotools.io
- miller.emu.id.au
- www.w3.org
- w3.org
- users.sourceforge.net
- linuxnet.com
- free.fr
- www.linuxnet.com
- relaxngcc.sf.net
- www.mozilla.org
- megginson.com
- www.unicode.org
- upx.tsx.org
- upx.sourceforge.net
- www.xfree86.org
- attbi.com
- courtesan.com
- www.sgi.com
- urwpp.de
- bigelowandholmes.com
- gzip.org
Embedded IP addresses
- 10.8.3.0
File paths
- d:\dbs\el\oc\target\x64\ship\click2run\x-none\IntegratedOffice.pdb
More Emotet samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report