MALICIOUS — e8988d85be038100a3a59f7f2434e386dd6e2f0419cbaa91c7316221908ad831
MALICIOUS — e8988d85be038100a3a59f7f2434e386dd6e2f0419cbaa91c7316221908ad831 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Emotet family. 6 of 52 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
e8988d85be038100a3a59f7f2434e386dd6e2f0419cbaa91c7316221908ad831 - SHA-1:
78be85d82a601a918aab8696780a78fa80cf5b8b - MD5:
5d1e43470b13f0b6192230ce5ec8f1e0 - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
24576:btg5+t0pOdRkHQy5Sk2+fPi1dJU43I98U7nYYJ2tHhADSANLHgZpJEML:bBeODI92+/4MnYYJ2ZhqSGLHkJEM - TLSH:
T16756AE490220B381E6F29F209D50AD5E50AEB4EA21BD389F0EC7D12FB6F607F6521157 - Submitted as: e8988d85be038100a3a59f7f2434e386dd6e2f0419cbaa91c7316221908ad831
- File type: pe · Size: 1388188 bytes
- Verdict: malicious (98/100) · Family: Emotet
Detections (6 of 52 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- ClamAV (daily): Win.Trojan.Generic-9862772-0
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: flagged
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 98/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Generic-9862772-0 (rule
Win.Trojan.Generic-9862772-0) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://office.microsoft.com/0
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://www.digicert.com/ssl-cps-repository.htm0
- http://crl3.digicert.com/assured-cs-2011a.crl03
- http://crl4.digicert.com/assured-cs-2011a.crl0
- http://cacerts.digicert.com/DigiCertAssuredIDCodeSigningCA-1.crt0
- http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
- http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
- http://crl.thawte.com/ThawteTimestampingCA.crl0
- http://watson.microsoft.com/dw/dcp.asp
- http://watson.microsoft.com/dw/watsoninfo.asp
- http://www.microsoft.com/pki/certs/tspca.crt0
- http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl0O
- http://office.microsoft.com
Embedded domains
- crl.microsoft.com
- www.microsoft.com
- office.microsoft.com
- schemas.microsoft.com
- www.digicert.com
- cacerts.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- ts-aia.ws.symantec.com
- ts-crl.ws.symantec.com
- crl.thawte.com
- watson.microsoft.com
- microsoft.com
- msn.com
Registry keys
- HKCU\Software\Microsoft\Shared\OfficeUILanguage
- HKCU\Software
- HKLM\Software
- HKCU\Software\Microsoft\Internet
- HKLM\Software\Microsoft\Windows
- HKLM\Software\Microsoft\Office\11.0\Registration
- HKCU\Software\Policies
- HKLM\Software\Policies
File paths
- d:\_Bld\10657\7994\Sources\obj\Win32\Release\EvaluationContainer.csproj\Microsoft.Mashup.Container.pdb
- c:\builds\moz2_slave\rel-m-rel-w32_bld-000000000000\build\obj-firefox\ipc\app\plugin-container.pdb
- T:\:d:l:t:
- D:\:`:
- P:\Target\x86\ship\delivery\x-none\ose.pdb
- R:\Sg
- F:\Office\Target\x86\ship\postc2r\x-none\msosqm.pdb
More Emotet samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report