MALICIOUS — dropper.exe
MALICIOUS — dropper.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Sinowal family. 5 of 51 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
e8dc8fc7e3b763c2d70d8a714213d5d0fc79d04102881a80011cd073588df6e6 - SHA-1:
5f71cd9a8310ee36079163647b8d18ed1b6f14f9 - MD5:
c3366b6006acc1f8df875eaa114796f0 - imphash:
8116f49d45d2fd55c990c058161bad0c - ssdeep:
6144:8YyZ8hMKj5pIITSq1SdiQubLGDVDlaxO459MdR+GvhGw:8Yy7g5pIITSq1OiQubLGBl49ze8 - TLSH:
T1B4448DA666CF2217F0EC849CC4C01DEEC297103D6B948B2DAE17775D5BA40C34A698F6 - Submitted as: dropper.exe
- File type: pe · Size: 249344 bytes
- Verdict: malicious (99/100) · Family: Sinowal
Detections (5 of 51 engines)
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- ClamAV (daily): {MD5}bin.trojan.sinowal.9285.UNOFFICIAL
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: PWS:Win32/Sinowal.gen!AD
- Emsisoft (Emergency Kit): Gen:Variant.Mikey.184856
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged {MD5}bin.trojan.sinowal.9285.UNOFFICIAL (rule
{MD5}bin.trojan.sinowal.9285.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged PWS:Win32/Sinowal.gen!AD (rule
PWS:Win32/Sinowal.gen!AD) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Mikey.184856 (rule
Gen:Variant.Mikey.184856) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
3661 behavior events · 2 ATT&CK techniques · 9 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- staging.to-do.officeppe.com
- annotatinggramma.info
- teams.cloud.microsoft
- outlook.office.com
- www.bing.com
- desktop-hsgcbep
- config.edge.skype.com
- dns.msftncsi.com
- tas02.sls.update.microsoft.com
- to-do.microsoft.com
- settings-win.data.microsoft.com
- ctldl.windowsupdate.com
- staging.to-do.microsoft.com
- edge.microsoft.com
- aps.prod.windows.com
- watson.events.data.microsoft.com
- teams.microsoft.com
- ecs.office.com
Dropped files
- /opt/CAPEv2/storage/analyses/4439/files/139a31604e0c27657f99137eacecd2963586b69c073c95b9e4118310d0627bb9 -
139a31604e0c27657f99137eacecd2963586b69c073c95b9e4118310d0627bb9 - 068e6d3e4a07e78021fce2a286bc024bfc395840fd15e0dcbb1dc5b4b01b850f -
068e6d3e4a07e78021fce2a286bc024bfc395840fd15e0dcbb1dc5b4b01b850f - ab21ca6fb8f03bf3c8b2dd6a6cae0ec35d34127a58c5d241711613d8b5e7d249 -
ab21ca6fb8f03bf3c8b2dd6a6cae0ec35d34127a58c5d241711613d8b5e7d249 - 45ed97a59868606ce3441181f423a0418e3d2e1355e2f31310be381e47d1a3dc -
45ed97a59868606ce3441181f423a0418e3d2e1355e2f31310be381e47d1a3dc - 4af984d1a8d5e9a11d8d16620cf5c08705574cd0f9101fce47c8b78674176135 -
4af984d1a8d5e9a11d8d16620cf5c08705574cd0f9101fce47c8b78674176135 - 1762e383d15587dff8ec4894f435a32c022926c4ad32261dbdd7970fc5df33ea -
1762e383d15587dff8ec4894f435a32c022926c4ad32261dbdd7970fc5df33ea - 1b38c39e6643abec0556d731929a032ea5851e02473b95c27586bd44a72c7076 -
1b38c39e6643abec0556d731929a032ea5851e02473b95c27586bd44a72c7076 - 7655d3ee2026958bb17f40468c71586023fae49733ead7deb60b8857d60888e8 -
7655d3ee2026958bb17f40468c71586023fae49733ead7deb60b8857d60888e8 - 4cabe754a7283fba8bf29272e0aa001abb4274ee7a7499f86a293cb95e3806c1 -
4cabe754a7283fba8bf29272e0aa001abb4274ee7a7499f86a293cb95e3806c1
Embedded domains
- staging.to-do.officeppe.com
- annotatinggramma.info
File paths
- D:\distr\config.ini
More Sinowal samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report