MALICIOUS — 787_Win32.EternalRocks.bin
MALICIOUS — 787_Win32.EternalRocks.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the EternalRocks family. 2 of 36 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d43c10a2c983049d4a32487ab1e8fe7727646052228554e0112f6651f4833d2c - SHA-1:
ae461ac186c4e42f935ff9e49408bbae47899706 - MD5:
b61068f85f030ee23d5b33b5b0c03930 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
1536:fNDdNSkM8M6/q4iXYWcqtssGGFVFZvoxO3Fy:fNDdNSktLjiXYWcqtsvGFVvouFy - TLSH:
T16A3A3BCC42ADA724C5B2CE116D00D9DC295A3C86F87A7F8C2F4CA5776195E37A83502B - Submitted as: 787_Win32.EternalRocks.bin
- File type: pe · Size: 101888 bytes
- Verdict: malicious (92/100) · Family: EternalRocks
Detections (2 of 36 engines)
- capa (capabilities): execute via PowerShell
- ClamAV (daily): Win.Trojan.EternalRocks-6320066-0
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Trojan.EternalRocks-6320066-0 (rule
Win.Trojan.EternalRocks-6320066-0) - engine signal, weight 0.90, confidence 0.95 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Embedded network infrastructure: http://ubgdgno5eswkhmpy.onion - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://ubgdgno5eswkhmpy.onion
Embedded domains
- system.io
- system.net
- myapplication.app
- ubgdgno5eswkhmpy.onion
Embedded IP addresses
- 1.0.0.0
- 2.0.0.0
File paths
- C:\Program
- C:\Users\tmc\Documents\Visual
- c:\windows\system32\netstat.exe
- C:\WINDOWS\system32\framedyn.dll
- C:\WINDOWS\system32\dllcache\framedyn.dll
- c:\windows\system32\netsh.exe
More EternalRocks samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report