MALICIOUS — 072_EarthKrahang_20240404.bin
MALICIOUS — 072_EarthKrahang_20240404.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the DinodasRAT family. 3 of 51 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
e0f109836a025d4531ea895cebecc9bdefb84a0cc747861986c4bc231e1d4213 - SHA-1:
33065850b30a7c797a9f1e5b219388c6991674db - MD5:
89ca5b5a6e4e320f80a6c9595f3f83e6 - imphash:
a5e3559270efc66aa896a251a888b8cd - ssdeep:
6144:1QwgBFqivHbDF9n/xZyHhAT7YL6Z3QVS17KpJprDig/s/uLRUKQCst:17gBFqivHbDz/xZyHhy7q6NQVS178Qg - TLSH:
T1C1468E98314A9F95E67197486C541E1E2073F8DE16BF28CCAB87E42F33A7EA75014078 - Submitted as: 072_EarthKrahang_20240404.bin
- File type: pe · Size: 300032 bytes
- Verdict: malicious (98/100) · Family: DinodasRAT
Detections (3 of 51 engines)
- ClamAV (daily): {MD5}bin.trojan.doina.7884.UNOFFICIAL
- Microsoft Defender: Backdoor:Win32/Dinodas!MSR
- Emsisoft (Emergency Kit): Gen:Variant.DinodasRAT.4
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged {MD5}bin.trojan.doina.7884.UNOFFICIAL (rule
{MD5}bin.trojan.doina.7884.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Backdoor:Win32/Dinodas!MSR (rule
Backdoor:Win32/Dinodas!MSR) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.DinodasRAT.4 (rule
Gen:Variant.DinodasRAT.4) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: 8.8.8.8, 115.126.98.204 - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
83 behavior events · 1 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- searchapp.bundleassets.example
- desktop-hsgcbep
- v10.events.data.microsoft.com
- settings-win.data.microsoft.com
- config.edge.skype.com
- login.live.com
- www.bing.com
- fd.api.iris.microsoft.com
- windows.msn.com
- licensing.mp.microsoft.com
- officeclient.microsoft.com
- watson.events.data.microsoft.com
- ecs.office.com
- g.live.com
- assets.msn.com
- dns.msftncsi.com
- self.events.data.microsoft.com
- msedge.api.cdp.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/5915/files/3e1ac48d6a4e28c00b304835ccbe5df88c426aeb2a006a2e4d89c454b8d3a15b -
3e1ac48d6a4e28c00b304835ccbe5df88c426aeb2a006a2e4d89c454b8d3a15b
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
Embedded domains
- schemas.microsoft.com
- inference.location.live.net
- aefd.nelreports.net
Embedded IP addresses
- 8.8.8.8
- 115.126.98.204
File paths
- H:\ShenTou\newmm\mm\Client\Release\Client.pdb
- X:\:
- X:\:`:d:h:l:p:t:x:
- D:\:p:
More DinodasRAT samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report