MALICIOUS — 124_EarthKrahang_20240404.bin
MALICIOUS — 124_EarthKrahang_20240404.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Doina family. 3 of 35 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
d176951b9ff3239b659ad57b729edb0845785e418852ecfeef1669f4c6fed61b - SHA-1:
707b56bdf9e0622f4c06b3f4c7225072ae2c14ab - MD5:
5022f69c4d88bc33457bb5248d97a045 - imphash:
4ae770c3d3f6130d918943dc30985e0c - ssdeep:
3072:qghXvOg9cOYqWDHjgT7byoftqsrQI6N/nDIRLI:qg8InYRgT7pftquuDI - TLSH:
T17B3C6B99861B3622F1B6E908BCA08DEDC823F09CA476924E9307DDAD50F2D33D4F6151 - Submitted as: 124_EarthKrahang_20240404.bin
- File type: pe · Size: 114176 bytes
- Verdict: malicious (97/100) · Family: Doina
Detections (3 of 35 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- capa (capabilities): inject code into another process
- ClamAV (daily): Win.Malware.Doina-10025202-0
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 97/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Malware.Doina-10025202-0 (rule
Win.Malware.Doina-10025202-0) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - inject code into another process (rule
inject code into another process) - capa signal, weight 0.50, confidence 0.80 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
Embedded domains
- schemas.microsoft.com
File paths
- Z:\newmm_v1\client\CallDll\x64\Release\GoogleUpdate.pdb
More Doina samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report