MALICIOUS — 501_PotaoExpress.bin
MALICIOUS — 501_PotaoExpress.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the ShellcodeRunner family. 5 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
dbc1b98b1df1d9c2dc8a5635682ed44a91df6359264ed63370724afa9f19c7ee - SHA-1:
4d5e0808a03a75bfe8202e3a6d2920eddbfc7774 - MD5:
5a24a7370f35dbdbb81adf52e769a442 - imphash:
e5f47c14608c9c00870027eee7d554bb - ssdeep:
1536:EkWr2wuehuST0cyuOCqcLuScjvCC89jH0mEizRjtCTw8DKEFXvxKqHs6:Py2CdJLLjA189j+YRjtCTlXeyT - TLSH:
T142387B92C252378ED65E317F07CD981C3A154EAFBB92B523074DA0D92734A2F4E49B84 - Submitted as: 501_PotaoExpress.bin
- File type: pe · Size: 77824 bytes
- Verdict: malicious (100/100) · Family: ShellcodeRunner
Detections (5 of 52 engines)
- ClamAV (daily): {MD5}bin.trojan.agent.7532.UNOFFICIAL
- Microsoft Defender: Trojan:Win32/ShellcodeRunner.PAHP!MTB
- Emsisoft (Emergency Kit): Gen:Trojan.Heur.euW@yjgGXfbif
- Trellix Stinger (McAfee): Dropper-FOI!5A24A7370F35
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged {MD5}bin.trojan.agent.7532.UNOFFICIAL (rule
{MD5}bin.trojan.agent.7532.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 3 finding(s), e.g. RWX/private injected region in svchost.exe (pid 984) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Win32/ShellcodeRunner.PAHP!MTB (rule
Trojan:Win32/ShellcodeRunner.PAHP!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Trojan.Heur.euW@yjgGXfbif (rule
Gen:Trojan.Heur.euW@yjgGXfbif) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Dropper-FOI!5A24A7370F35 (rule
Dropper-FOI!5A24A7370F35) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win32.Generic (rule
HEUR:Trojan.Win32.Generic) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
9104 behavior events · 2 ATT&CK techniques · 3 dropped files.
Runtime network
- none
Dropped files
- /opt/CAPEv2/storage/analyses/6072/files/66c8a0b834876d1c385c3f8acd91edef7b8c942b0b5a6965ab58bded9b0255e1 -
66c8a0b834876d1c385c3f8acd91edef7b8c942b0b5a6965ab58bded9b0255e1 - /opt/CAPEv2/storage/analyses/6072/files/b601716179f57651242e652afd4f7df58bc5940534f0d8fc71070544ae903a5c -
b601716179f57651242e652afd4f7df58bc5940534f0d8fc71070544ae903a5c - /opt/CAPEv2/storage/analyses/6072/files/27b5895c745ac81697bda4de756eb94d73bfdda9c30e0eac28e4911853c80137 -
27b5895c745ac81697bda4de756eb94d73bfdda9c30e0eac28e4911853c80137
More ShellcodeRunner samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report