MALICIOUS — 910_WinX.OperationDianxun.bin
MALICIOUS — 910_WinX.OperationDianxun.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Cobaltstrike family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
d2642d3731508b52efa34adf57701f18e2f8b70addf31e33e445e75b9a909822 - SHA-1:
635860d4e6c9cc14e421f07f665aaaf6d25da13a - MD5:
4bb44c229b5ebd44bfabffdbb3635d8b - imphash:
829da329ce140d873b4a8bde2cbfaa7e - ssdeep:
6144:ZSWLTWJLT0C2jjfh4LVuGYiY3JAn71ffropmVj/A:1LTWtt4jfh4L7YiYunh7NY - TLSH:
T1F543DF99C33847ADEE80080EC876925C6A7A157320E1574CF4642CEBF5867A36E71BF1 - Submitted as: 910_WinX.OperationDianxun.bin
- File type: pe · Size: 224768 bytes
- Verdict: malicious (100/100) · Family: Cobaltstrike
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.tdqp
- ClamAV (daily): {MD5}bin.backdoor.cobaltstrike.2.UNOFFICIAL
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Backdoor:Win32/CobaltStrike!pz
- Emsisoft (Emergency Kit): Trojan.CobaltStrike.FM
- Kaspersky (KVRT): HEUR:Trojan.Win32.CobaltStrike.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged {MD5}bin.backdoor.cobaltstrike.2.UNOFFICIAL (rule
{MD5}bin.backdoor.cobaltstrike.2.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Backdoor:Win32/CobaltStrike!pz (rule
Backdoor:Win32/CobaltStrike!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.CobaltStrike.FM (rule
Trojan.CobaltStrike.FM) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win32.CobaltStrike.gen (rule
HEUR:Trojan.Win32.CobaltStrike.gen) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Extracted CobaltStrikeBeacon config (0 C2) - engine signal, weight 0.45, confidence 0.60
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.tdqp - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (windows)
433 behavior events · 2 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- searchapp.bundleassets.example
- inference.location.live.net
- update1.jscachecdn.com
- desktop-hsgcbep
- v10.events.data.microsoft.com
- config.edge.skype.com
- login.live.com
- settings-win.data.microsoft.com
- fd.api.iris.microsoft.com
- www.bing.com
- licensing.mp.microsoft.com
- windows.msn.com
- officeclient.microsoft.com
- sdx.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- nav.smartscreen.microsoft.com
- dns.msftncsi.com
- assets.msn.com
- oloobe.officeapps.live.com
Dropped files
- 369ed0d25b1033793caf47bbd2306472f89e013dc8171b361eec4b5ffbf639b8 -
369ed0d25b1033793caf47bbd2306472f89e013dc8171b361eec4b5ffbf639b8
Embedded domains
- inference.location.live.net
- update1.jscachecdn.com
- aefd.nelreports.net
Embedded IP addresses
- 162.159.36.2
More Cobaltstrike samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report