MALICIOUS — 541_PotaoExpress.bin
MALICIOUS — 541_PotaoExpress.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Potao family. 4 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f845778c3f2e3272145621776a90f662ee9344e3ae550c76f65fd954e7277d19 - SHA-1:
9d584de2cce6b654e62573938c2c824d7cc7d0eb - MD5:
5199fcd031987834ed3121fb316f4970 - imphash:
d1122623188e190d6a1690c523ea4c0f - ssdeep:
6144:Ll3qf+cDNjRIry0Pf0/40p7g1/B48DbzdEofa5GbN:tqGyFRIrd70p7o1D9asp - TLSH:
T16C43F19BAA01FA89F5611702778E49CFF447A19F95B10B00B2B5CFFD9920E63865C702 - Submitted as: 541_PotaoExpress.bin
- File type: pe · Size: 232960 bytes
- Verdict: malicious (97/100) · Family: Potao
Detections (4 of 52 engines)
- Microsoft Defender: TrojanDropper:Win32/Potao.D!dha
- Emsisoft (Emergency Kit): Gen:Variant.Potao.8
- Trellix Stinger (McAfee): Trojan-FGWR!5199FCD03198
- Kaspersky (KVRT): Trojan.Win32.Agent.ifwr
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 7 weighted signals:
- Microsoft Defender flagged TrojanDropper:Win32/Potao.D!dha (rule
TrojanDropper:Win32/Potao.D!dha) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Potao.8 (rule
Gen:Variant.Potao.8) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Trojan-FGWR!5199FCD03198 (rule
Trojan-FGWR!5199FCD03198) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Agent.ifwr (rule
Trojan.Win32.Agent.ifwr) - engine signal, weight 0.55, confidence 0.85 - Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - Contacted 24 external host(s) at runtime (2 HTTP) - network signal, weight 0.40, confidence 0.80
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
68 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- v10.events.data.microsoft.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- fd.api.iris.microsoft.com
- settings-win.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- licensing.mp.microsoft.com
- tsfe.trafficshaping.dsp.mp.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- slscr.update.microsoft.com
- tas02.sls.update.microsoft.com
- watson.events.data.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/6070/files/4898f789d9587381786340f4950be5370cd15234b8059e8c82ef68e0baedd1af -
4898f789d9587381786340f4950be5370cd15234b8059e8c82ef68e0baedd1af - 0151612a0022ffd2fe01f4ab9613a385ad9cce3930dcec94fee097bf3829a51e -
0151612a0022ffd2fe01f4ab9613a385ad9cce3930dcec94fee097bf3829a51e - a116efc79e79ed43985bdf743b337e4796b5b418df6b00fd966d2e2c0c4115e1 -
a116efc79e79ed43985bdf743b337e4796b5b418df6b00fd966d2e2c0c4115e1
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- inference.location.live.net
Embedded IP addresses
- 23.40.52.85
- 20.89.1.11
- 4.150.223.111
- 4.247.188.224
- 52.123.252.244
- 40.126.14.163
- 4.230.171.124
- 57.155.104.224
- 52.230.60.54
- 72.147.149.16
- 4.150.223.101
- 74.178.240.51
- 135.232.92.137
- 20.184.175.21
- 150.171.22.17
- 135.233.45.222
- 20.247.184.197
- 20.165.94.46
- 23.33.238.102
- 172.179.80.7
- 125.56.205.17
- 52.110.12.53
- 23.198.40.44
- 125.56.205.26
File paths
- E:\svn\sapotao\BIN\node69-dropper.pdb
- V:\:j:p:w:
More Potao samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report