MALICIOUS — sample.exe
MALICIOUS — sample.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Nimda family. 8 of 51 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
ebc324308ee01698aeb02ab5de68cc7d8f9e13bd9f4d8edc7daeb438850612b9 - SHA-1:
2a72d49cfa0e5a497cd957b0365f7d472f626c26 - MD5:
130d2fe8174481170b3d78627c6b5e13 - imphash:
f7c5cb7d3be0b2cc0b9c48f91b1670b7 - ssdeep:
768:chGiIK52KgzvijWBzff2NuYXu/ljfyR/1rgqQajhtU1Hloc6BR+Mtcg10eZaXap:8I2jWBzf+knFI14a616BR+bgSEa - TLSH:
T1F0342821B112AB87EBC46241F0125C2DAFE1A9FA52B85C8751F241EE07FA067D85B437 - Submitted as: sample.exe
- File type: pe · Size: 57344 bytes
- Verdict: malicious (100/100) · Family: Nimda
Detections (8 of 51 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- ClamAV (daily): {HEX}bin.worm.n.134.UNOFFICIAL
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Virus:Win32/Nimda.E@mm
- Emsisoft (Emergency Kit): Trojan.Downloader.Small.ASU
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged {HEX}bin.worm.n.134.UNOFFICIAL (rule
{HEX}bin.worm.n.134.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - Microsoft Defender flagged Virus:Win32/Nimda.E@mm (rule
Virus:Win32/Nimda.E@mm) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Downloader.Small.ASU (rule
Trojan.Downloader.Small.ASU) - engine signal, weight 0.55, confidence 0.85 - Extracted Nimda config (0 C2) - engine signal, weight 0.45, confidence 0.60
- YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - inject code into another process (rule
inject code into another process) - capa signal, weight 0.12, confidence 0.60
Dynamic analysis (windows)
2350 behavior events · 1 ATT&CK techniques · 4 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- desktop-hsgcbep
- www.bing.com
- config.edge.skype.com
- aefd.nelreports.net
- dns.msftncsi.com
- watson.events.data.microsoft.com
- g.live.com
- self.events.data.microsoft.com
- edge.microsoft.com
- www.msftncsi.com
- time.windows.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- tsfe.trafficshaping.dsp.mp.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
- geover.prod.do.dsp.mp.microsoft.com
- cp801.prod.do.dsp.mp.microsoft.com
- _dosvc._tcp.local
Dropped files
- /opt/CAPEv2/storage/analyses/5053/files/22dfc1edf82a9878f42900099f7caa29a4fe91e6438c78e77b96169cf3f4b7aa -
22dfc1edf82a9878f42900099f7caa29a4fe91e6438c78e77b96169cf3f4b7aa - /opt/CAPEv2/storage/analyses/5053/files/481e1537f8e01c8853c72e452e367a58803b313219b1243e292736232ea66450 -
481e1537f8e01c8853c72e452e367a58803b313219b1243e292736232ea66450 - /opt/CAPEv2/storage/analyses/5053/files/61663cb71a574f352c4017b06d3516119ad7d51bdb690801082b39cde6cdff48 -
61663cb71a574f352c4017b06d3516119ad7d51bdb690801082b39cde6cdff48 - 82af8245f6d6f1eebb2241458c834a3017c322e487c75b39f4b9ea6782e09536 -
82af8245f6d6f1eebb2241458c834a3017c322e487c75b39f4b9ea6782e09536
Embedded domains
- aefd.nelreports.net
File paths
- c:\httpodbc.dll
- d:\httpodbc.dll
- e:\httpodbc.dll
More Nimda samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report