MALICIOUS — 641_Trojan.Sinowal.bin
MALICIOUS — 641_Trojan.Sinowal.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Sinowal family. 4 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
ea8c6a377c474bcf7c34f642b8f6829591761da5b32d7a92ba1570ae498fb31b - SHA-1:
c41659957ae1ed5d1eea28b553af881c40ff24e6 - MD5:
4a3543e6771bc78d32ae46820aed1391 - imphash:
8116f49d45d2fd55c990c058161bad0c - ssdeep:
3072:7bDRqanQiZUwTSqFU1yklcv+umttE0s53ctzv53wIZ992nWrOjDrA3d+il2oU:7nXhZUwTSqFYoLmFUcXT4J/E+v - TLSH:
T19244AECDAACE2557F0E88A98D2040DAF91BB543D63591B1E8E1F4B4D6B440CB4E39CD2 - Submitted as: 641_Trojan.Sinowal.bin
- File type: pe · Size: 241152 bytes
- Verdict: malicious (100/100) · Family: Sinowal
Detections (4 of 52 engines)
- ClamAV (daily): {MD5}bin.trojan.sinowal.9280.UNOFFICIAL
- Microsoft Defender: PWS:Win32/Sinowal.gen!AD
- Emsisoft (Emergency Kit): Gen:Variant.Mikey.184856
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged {MD5}bin.trojan.sinowal.9280.UNOFFICIAL (rule
{MD5}bin.trojan.sinowal.9280.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 4 finding(s), e.g. process hollowing in tsk_8cce40771e (pid 7720) (rule
windows.hollowprocesses.HollowProcesses) - memory signal, weight 0.70, confidence 0.85 - Microsoft Defender flagged PWS:Win32/Sinowal.gen!AD (rule
PWS:Win32/Sinowal.gen!AD) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Mikey.184856 (rule
Gen:Variant.Mikey.184856) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Anti-analysis: T1497, T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 2 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (windows)
16641 behavior events · 2 ATT&CK techniques · 10 dropped files.
Runtime network
- www.msftconnecttest.com
- searchapp.bundleassets.example
- annotatinggramma.info
- inference.location.live.net
- desktop-hsgcbep
- ctldl.windowsupdate.com
- login.live.com
- v10.events.data.microsoft.com
- config.edge.skype.com
- www.bing.com
- windows.msn.com
- officeclient.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- dns.msftncsi.com
- watson.events.data.microsoft.com
- tsfe.trafficshaping.dsp.mp.microsoft.com
- fd.api.iris.microsoft.com
- msedge.api.cdp.microsoft.com
- sdx.microsoft.com
- edge.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/6345/files/a391316541811b6f955b53d4936e51948acbc4572517c76905e39250be1f64b4 -
a391316541811b6f955b53d4936e51948acbc4572517c76905e39250be1f64b4 - /opt/CAPEv2/storage/analyses/6345/files/9b9261283e0f962e29b528a79e4409465c96198c5f70d1ccad40b9101e4086a0 -
9b9261283e0f962e29b528a79e4409465c96198c5f70d1ccad40b9101e4086a0 - 87861f955128035a919f73d4bd7bea3a822f7daf93338dbcb94d3157c65fa44a -
87861f955128035a919f73d4bd7bea3a822f7daf93338dbcb94d3157c65fa44a - 068e6d3e4a07e78021fce2a286bc024bfc395840fd15e0dcbb1dc5b4b01b850f -
068e6d3e4a07e78021fce2a286bc024bfc395840fd15e0dcbb1dc5b4b01b850f - a71d39b885ee18d5ff7a82989397db9c57add2c5afdda8bcce5534006cfc210b -
a71d39b885ee18d5ff7a82989397db9c57add2c5afdda8bcce5534006cfc210b - 33d1d7b1baeaecbd32b1625673c8338c8fb3209e636e39f9638cbfe527540d06 -
33d1d7b1baeaecbd32b1625673c8338c8fb3209e636e39f9638cbfe527540d06 - e13ff643a29872dd8b35387eba4937f89344bef7e3204abca93bd3d8736ad842 -
e13ff643a29872dd8b35387eba4937f89344bef7e3204abca93bd3d8736ad842 - 28c716ba654f8af09b46996f2fa72c20762af782486a70714d54c3c8a7101bf3 -
28c716ba654f8af09b46996f2fa72c20762af782486a70714d54c3c8a7101bf3 - d5e1c81f037aad362cee1cd52a6a2be8dd1b1f123723a1bb67282470ada910f2 -
d5e1c81f037aad362cee1cd52a6a2be8dd1b1f123723a1bb67282470ada910f2 - a0d9d29ecd5f73c520a2b29a6e60c6f884611c4496cf4ccb8b85b8e48368f59b -
a0d9d29ecd5f73c520a2b29a6e60c6f884611c4496cf4ccb8b85b8e48368f59b
Embedded domains
- annotatinggramma.info
- inference.location.live.net
- aefd.nelreports.net
Embedded IP addresses
- 162.159.36.2
- 108.59.6.39
File paths
- D:\distr\config.ini
More Sinowal samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report