MALICIOUS — 081_EarthKrahang_20240404.bin
MALICIOUS — 081_EarthKrahang_20240404.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the DinodasRAT family. 3 of 51 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
d17fe5bc3042baf219e81cbbf991749dfcd8b6d73cf6506a8228e19910da3578 - SHA-1:
9a6e803a28d27462d2df47b52e34120fb2cf814b - MD5:
703bd29d65106d29651132d8c633a1c9 - imphash:
a5e3559270efc66aa896a251a888b8cd - ssdeep:
12288:B7gBFqivHbDz/xZyHhy7q6NQVS178Qg0/cRUdXd:ir/bRWSFMecRUdX - TLSH:
T11D4AA19413026A64DDF8AF0C5E550F0D30DEA7A9396ED888EE43E41E2657EB35D2306C - Submitted as: 081_EarthKrahang_20240404.bin
- File type: pe · Size: 465920 bytes
- Verdict: malicious (99/100) · Family: DinodasRAT
Detections (3 of 51 engines)
- ClamAV (daily): {MD5}bin.trojan.doina.7882.UNOFFICIAL
- Microsoft Defender: Trojan:Win32/Znyonm
- Emsisoft (Emergency Kit): Gen:Variant.DinodasRAT.3
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged {MD5}bin.trojan.doina.7882.UNOFFICIAL (rule
{MD5}bin.trojan.doina.7882.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 3 finding(s), e.g. RWX/private injected region in sppsvc.exe (pid 9176) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Win32/Znyonm (rule
Trojan:Win32/Znyonm) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.DinodasRAT.3 (rule
Gen:Variant.DinodasRAT.3) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: 8.8.8.8, 115.126.98.204 - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
84 behavior events · 1 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- searchapp.bundleassets.example
- inference.location.live.net
- desktop-hsgcbep
- v10.events.data.microsoft.com
- settings-win.data.microsoft.com
- config.edge.skype.com
- login.live.com
- fd.api.iris.microsoft.com
- www.bing.com
- msedge.api.cdp.microsoft.com
- windows.msn.com
- licensing.mp.microsoft.com
- officeclient.microsoft.com
- dns.msftncsi.com
- ecs.office.com
- g.live.com
- self.events.data.microsoft.com
- assets.msn.com
- watson.events.data.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/5922/files/1ee91676f9238424b54afd83c73dde7733d07a371756330e950ece4a97e98517 -
1ee91676f9238424b54afd83c73dde7733d07a371756330e950ece4a97e98517
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
Embedded domains
- schemas.microsoft.com
- inference.location.live.net
- aefd.nelreports.net
Embedded IP addresses
- 8.8.8.8
- 115.126.98.204
File paths
- H:\ShenTou\newmm\mm\Client\Release\Client.pdb
- X:\:
- X:\:`:d:h:l:p:t:x:
- D:\:p:
More DinodasRAT samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report