MALICIOUS — 659_VolatileCedar.Explosion.bin
MALICIOUS — 659_VolatileCedar.Explosion.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the Explosive family. 5 of 39 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
dea53e331d3b9f21354147f60902f6e132f06183ed2f4a28e67816f9cb140a90 - SHA-1:
eb46d08f14119b33a92750e11e65445a216d1783 - MD5:
1dcac3178a1b85d5179ce75eace04d10 - imphash:
04ad2abcc93e6155ad98cbbf7d84da76 - ssdeep:
6144:nD/46x51zacOY8srInuxP28JLFZs/SBijGb8sZX4DLRuQaDqIZ3IZ:nM6D1AsrIuB2qZsHjU8s+D41DqIZq - TLSH:
T14949AD410F176649F2E38B908C14AD1D44B7A8BA31BF299C0BDBD45F6ADB89F610093D - Submitted as: 659_VolatileCedar.Explosion.bin
- File type: pe · Size: 402488 bytes
- Verdict: malicious (91/100) · Family: Explosive
Detections (5 of 39 engines)
- capa (capabilities): capture keystrokes
- ClamAV (daily): Win.Trojan.Explosive-6479674-0
- Microsoft Defender: Worm:Win32/Hokobot.A!dha
- Trellix Stinger (McAfee): Generic.dgg
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 91/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Explosive-6479674-0 (rule
Win.Trojan.Explosive-6479674-0) - engine signal, weight 0.90, confidence 0.95 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://www.microsoft.com/en-us/default.aspx
Embedded domains
- www.google.com
- www.microsoft.com
Registry keys
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
File paths
- c:\windows\wvhelp.exe
- c:\windows\
More Explosive samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report