MALICIOUS — e8bdda20916b42f731ae31130a15f60a664f1947b519190a29a9db6a79645436
MALICIOUS — e8bdda20916b42f731ae31130a15f60a664f1947b519190a29a9db6a79645436 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the Uztuby family. 5 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e8bdda20916b42f731ae31130a15f60a664f1947b519190a29a9db6a79645436 - SHA-1:
3d8a2d501e06a0dcece645d8f608af20712f3a37 - MD5:
d4a8d50a74decb7b35a63ad2df498577 - imphash:
fcf1390e9ce472c7270447fc5c61a0c1 - ssdeep:
49152:SbA3tLuRshXwDTMk3e7BEBcEaYM6o40ewIWMpKVjXzCCjmc:SbuCRshXwPMkbBcELeKIV5mc - TLSH:
T1705ECF55C2AA5A32DBFCB25C5C33849E3AFAD896603D4C504A87B73F10591974B3223B - Submitted as: e8bdda20916b42f731ae31130a15f60a664f1947b519190a29a9db6a79645436
- File type: pe · Size: 3010280 bytes
- Verdict: malicious (93/100) · Family: Uztuby
Detections (5 of 55 engines)
- capa (capabilities): capability:execution/powershell
- ClamAV (daily): Win.Malware.Uztuby-9848412-0
- ESET: IIS_Group07_IISpy
- Microsoft Defender: Backdoor:MSIL/DCRat!rfn
- Kaspersky (KVRT): HEUR:Backdoor.MSIL.LightStone.gen
MITRE ATT&CK
Why this verdict
The malicious score of 93/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Malware.Uztuby-9848412-0 (rule
Win.Malware.Uztuby-9848412-0) - engine signal, weight 0.90, confidence 0.95 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - ESET flagged IIS_Group07_IISpy (rule
IIS_Group07_IISpy) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
Embedded domains
- to9.uk
- schemas.microsoft.com
- d.es
File paths
- D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb
- T:\:d:l:t:
- C:\ReviewSessionBrokerperfDhcp\ReviewSessionBrokerperfDhcpFontdhcp.exe
More Uztuby samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report