MALICIOUS — 096_EarthKrahang_20240404.bin
MALICIOUS — 096_EarthKrahang_20240404.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the Doina family. 3 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d31d135bc450eafa698e6b7fb5d11b4926948163af09122ca1c568284d8b33b3 - SHA-1:
2d11cc6827d69c09fc0ebddb485c391f776c4112 - MD5:
1de9b3824870d8cc2d36448b32d145d8 - imphash:
4031dc2e8268cb3797743afdc50b9cd4 - ssdeep:
6144:p4Fg7psgYlHp/ZcX1NzyLlIUiJJZsd2XCARwT283Uhc/Oibf/Lq9SQ:/VylMX19y5Iwd/jHLqt - TLSH:
T1C349496641172822F9B7B2749C008CEC8C93B46CB535425E2747DE2D80D3EB7A3F619A - Submitted as: 096_EarthKrahang_20240404.bin
- File type: pe · Size: 399360 bytes
- Verdict: malicious (96/100) · Family: Doina
Detections (3 of 51 engines)
- ClamAV (daily): {MD5}bin.trojan.doina.7875.UNOFFICIAL
- Microsoft Defender: Trojan:Win64/Doina.ALP!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Doina.63318
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged {MD5}bin.trojan.doina.7875.UNOFFICIAL (rule
{MD5}bin.trojan.doina.7875.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win64/Doina.ALP!MTB (rule
Trojan:Win64/Doina.ALP!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Doina.63318 (rule
Gen:Variant.Doina.63318) - engine signal, weight 0.55, confidence 0.85 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- none
Dropped files
- /opt/CAPEv2/storage/analyses/5924/files/49ac4416b7609195e1eacf20b69f1a05583da19cb1012c00c168c6ae480077e7 -
49ac4416b7609195e1eacf20b69f1a05583da19cb1012c00c168c6ae480077e7 - /opt/CAPEv2/storage/analyses/5924/files/1e4e4067f4666786586e9b8255b74f1e5d5fc78781f48f1a1f076a03351f886c -
1e4e4067f4666786586e9b8255b74f1e5d5fc78781f48f1a1f076a03351f886c
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
Embedded domains
- www.security-microsoft.net
- schemas.microsoft.com
More Doina samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report