MALICIOUS — virussign.com_944eff05bf74cd2a9d882e289ab6a7a0.vir
MALICIOUS — virussign.com_944eff05bf74cd2a9d882e289ab6a7a0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the CobaltStrike family. 9 of 52 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
f344730e6ed7868ec597eb6a9ce33e64364f0d117c4bf13262872a022a4524e4 - SHA-1:
3a4cf3d78ef9746d5ff4af408b1517477591e920 - MD5:
944eff05bf74cd2a9d882e289ab6a7a0 - imphash:
96c44fa1eee2c4e9b9e77d7bf42d59e6 - ssdeep:
49152:r56uL3pgrCEdMKPFotsgEBr6GjvzW+UBA3Gd7po52xWKQY2v2V6liK1uOCeXvpna:r56utgpPFotBER/mQ32lUk - TLSH:
T171647CE24A61EB8BCFD7F0B09060677C68A3D45D71B60EEC1623DA24BDC59530AAF444 - Submitted as: virussign.com_944eff05bf74cd2a9d882e289ab6a7a0.vir
- File type: pe · Size: 5264689 bytes
- Verdict: malicious (100/100) · Family: CobaltStrike
Detections (9 of 52 engines)
- YARA: MalwareAnalyser built-in: Suspicious_PowerShell_Download_Exec
- capa (capabilities): capability:execution/powershell
- ClamAV (daily): Win.Trojan.CobaltStrike-8091534-0
- YARA: Google GCTI: GCTI_CobaltStrike_Beacon
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: MalwareAnalyser community pack: TL_Suspicious_PowerShell_Download
- Microsoft Defender: Trojan:Win32/CobaltStrike!pz
- Emsisoft (Emergency Kit): Trojan.GenericKD.45989870
- Kaspersky (KVRT): HEUR:Trojan.Win32.Cometer.gen
MITRE ATT&CK
YARA
- Suspicious_PowerShell_Download_Exec
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Trojan.CobaltStrike-8091534-0 (rule
Win.Trojan.CobaltStrike-8091534-0) - engine signal, weight 0.90, confidence 0.95 - Encoded/hidden PowerShell download-and-exec (rule
Suspicious_PowerShell_Download_Exec) - yara signal, weight 0.70, confidence 0.90 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - Microsoft Defender flagged Trojan:Win32/CobaltStrike!pz (rule
Trojan:Win32/CobaltStrike!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.GenericKD.45989870 (rule
Trojan.GenericKD.45989870) - engine signal, weight 0.55, confidence 0.85 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: Google GCTI flagged GCTI_CobaltStrike_Beacon (rule
GCTI_CobaltStrike_Beacon) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Suspicious_PowerShell_Download (rule
TL_Suspicious_PowerShell_Download) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - inject code into another process (rule
inject code into another process) - capa signal, weight 0.12, confidence 0.60
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded domains
- big.int
- idna.info
- pkix.name
- reflect.name
- runtime.name
- s3.us-east-2.amazonaws.com
- golang.org
- atomic.store
- runtime.name.name
- unicode.to
- reflect.name.name
- hash.net
- eq.net
- runtime.work
- go.itab.net
- go.itab.io
- unicode.cc
- unicode.cf
- unicode.co
- unicode.me
- unicode.nl
- unicode.no
- reflect.link
- reflect.fun
- http.fr
File paths
- C:\Users\SKOL-NOTE\Desktop\Loader
- V:\::;Q;k
More CobaltStrike samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report