MALICIOUS — 552_PotaoExpress.bin
MALICIOUS — 552_PotaoExpress.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the Potao family. 4 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d2c11706736fda2b178ac388206472fd8d050e0f13568c84b37683423acd155d - SHA-1:
76da7b4abc9b711ab1ef87b97c61dd895e508232 - MD5:
27d74523b182ae630c4e5236897e11f3 - imphash:
555d1103c64944249123a7daaa9ceea9 - ssdeep:
3072:JWl0xCeqNLKV9frb/0+JXpt+ESquCwP24n6ela8tB:Ul0mNL4frDpJSXN6uD - TLSH:
T1823DBE9D502E3243D3ABEA605E518F4EE03270E809B9A50D5CC7C56F3693DA7EEB0815 - Submitted as: 552_PotaoExpress.bin
- File type: pe · Size: 130560 bytes
- Verdict: malicious (93/100) · Family: Potao
Detections (4 of 52 engines)
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Trojan:Win32/Zusy.AA!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Potao.12
- Kaspersky (KVRT): Trojan-Dropper.Win32.Injector.nlje
MITRE ATT&CK
Why this verdict
The malicious score of 93/100 is the fusion of 6 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Zusy.AA!MTB (rule
Trojan:Win32/Zusy.AA!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Potao.12 (rule
Gen:Variant.Potao.12) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-Dropper.Win32.Injector.nlje (rule
Trojan-Dropper.Win32.Injector.nlje) - engine signal, weight 0.55, confidence 0.85 - Contacted 40 external host(s) at runtime (14 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
6537 behavior events · 1 ATT&CK techniques · 5 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- cdnjs.cloudflare.com
- c.pki.goog
- v10.events.data.microsoft.com
- login.live.com
- settings-win.data.microsoft.com
- v20.events.data.microsoft.com
- desktop-hsgcbep
- fd.api.iris.microsoft.com
- config.edge.skype.com
- msedge.api.cdp.microsoft.com
- licensing.mp.microsoft.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- arc.msn.com
- odc.officeapps.live.com
- sdx.microsoft.com
- assets.msn.com
Dropped files
- /opt/CAPEv2/storage/analyses/6093/files/3b938a912c39034debb3587609e82ec7efbeb802b5aa92a3b2a1d57c7773b28f -
3b938a912c39034debb3587609e82ec7efbeb802b5aa92a3b2a1d57c7773b28f - 52c4d35c9d615fdfdb5dfaf9673a8188117bcdcb0206d102f2849173e191bde6 -
52c4d35c9d615fdfdb5dfaf9673a8188117bcdcb0206d102f2849173e191bde6 - a65c4514c36bc33b75705753d2a444a421205a73836bdb6b89bca4360480b45d -
a65c4514c36bc33b75705753d2a444a421205a73836bdb6b89bca4360480b45d - b08f21d6b1f3599806913bc8d9b01bf9f89299e58997e9d585733c7736def96b -
b08f21d6b1f3599806913bc8d9b01bf9f89299e58997e9d585733c7736def96b - 11f140e0e65b68ce730deebf7d0658eb17c31cf767aed45fa2b3b38ffa576877 -
11f140e0e65b68ce730deebf7d0658eb17c31cf767aed45fa2b3b38ffa576877
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://c.pki.goog/r/gsr1.crl
- http://c.pki.goog/r/r4.crl
- http://c.pki.goog/we1/_-4iFwfCacM.crl
Embedded domains
- inference.location.live.net
- content.lifecycle.office.net
Embedded IP addresses
- 23.40.52.209
- 20.184.175.3
- 85.210.193.152
- 20.184.175.0
- 150.171.22.17
- 52.230.59.222
- 74.178.232.29
- 4.230.171.124
- 57.154.63.210
- 72.147.149.16
- 74.179.77.164
- 135.233.95.144
- 4.150.223.110
- 74.178.240.61
- 20.184.175.23
- 172.178.240.162
- 4.195.116.8
- 20.190.122.23
- 204.79.197.203
- 23.33.238.114
- 150.171.109.24
- 40.126.14.160
- 48.211.4.16
- 135.149.173.69
- 125.56.205.42
File paths
- T:\:d:l:t:
More Potao samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report