MALICIOUS — 657_VolatileCedar.Explosion.bin
MALICIOUS — 657_VolatileCedar.Explosion.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Explosive family. 8 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
d30f306d4d866a07372b94f7657a7a2b0500137fe7ef51678d0ef4249895c2c5 - SHA-1:
1f98454d9ba6d540a0b65420fc49a5949dfff4aa - MD5:
6f11a67803e1299a22c77c8e24072b82 - imphash:
240012187e43b6ba80278a62911e8795 - ssdeep:
3072:tsHWUf1nAxsSkuF95mYZXa5r5H/16pOjJndqZtpMD/Tt6IB3l3o:tk/n4OrdqCdqZMDbz5 - TLSH:
T17E427C824557A341F7B38B608D99EC1D01F7A8BA72BF1A8C97C7D48F66DB44F6640028 - Submitted as: 657_VolatileCedar.Explosion.bin
- File type: pe · Size: 212992 bytes
- Verdict: malicious (100/100) · Family: Explosive
Detections (8 of 52 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Trojan.Explosive-6538486-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Cyble Vision: Cyble Vision: Malicious
- Microsoft Defender: Trojan:Win32/Hokobot.A!dha
- Emsisoft (Emergency Kit): Gen:Variant.Doina.11240
- Trellix Stinger (McAfee): Generic.dgg
- Kaspersky (KVRT): Trojan.Win32.Explosive.c
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Explosive-6538486-0 (rule
Win.Trojan.Explosive-6538486-0) - engine signal, weight 0.90, confidence 0.95 - Cyble Vision flagged Cyble Vision: Malicious (rule
Cyble Vision: Malicious) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Hokobot.A!dha (rule
Trojan:Win32/Hokobot.A!dha) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Doina.11240 (rule
Gen:Variant.Doina.11240) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Generic.dgg (rule
Generic.dgg) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Explosive.c (rule
Trojan.Win32.Explosive.c) - engine signal, weight 0.55, confidence 0.85 - Memory forensics: 3 finding(s), e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.55, confidence 0.85 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (windows)
61 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- searchapp.bundleassets.example
- desktop-hsgcbep
- v10.events.data.microsoft.com
- config.edge.skype.com
- login.live.com
- settings-win.data.microsoft.com
- fd.api.iris.microsoft.com
- windows.msn.com
- officeclient.microsoft.com
- licensing.mp.microsoft.com
- msedge.api.cdp.microsoft.com
- sdx.microsoft.com
- www.bing.com
- nav.smartscreen.microsoft.com
- dns.msftncsi.com
- fe3cr.delivery.mp.microsoft.com
- assets.msn.com
- 192.168.122.109
Embedded domains
- inference.location.live.net
Embedded IP addresses
- 162.159.36.2
More Explosive samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report