MALICIOUS — 530_PotaoExpress.bin
MALICIOUS — 530_PotaoExpress.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the Potao family. 5 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fcfdcbdd60f105af1362cfeb3decbbbbe09d5fc82bde6ee8dfd846b2b844f972 - SHA-1:
e400e1dd983fd94e29345aabc77fadeb3f43c219 - MD5:
14634d446471b9e2f55158d9ac09d0b2 - imphash:
64d8b4f0d310b5705f3240ac93242279 - ssdeep:
1536:XP9LtIYfn3N+IAtnZ1S+gCctnSksGOzMlryU5GmT:XPz/n3QtZ19gCcQxxo - TLSH:
T1E33702FB575A5368C33AF6363CE2B44E045B4C611D9D97AE16105B3B4F7930B8292122 - Submitted as: 530_PotaoExpress.bin
- File type: pe · Size: 74752 bytes
- Verdict: malicious (95/100) · Family: Potao
Detections (5 of 51 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): Gen:Variant.Potao.1
- Trellix Stinger (McAfee): Generic Trojan.hg
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 8 weighted signals:
- Microsoft Defender flagged flagged (rule
flagged) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Potao.1 (rule
Gen:Variant.Potao.1) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Generic Trojan.hg (rule
Generic Trojan.hg) - engine signal, weight 0.55, confidence 0.85 - Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (windows)
30 behavior events · 1 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- searchapp.bundleassets.example
- inference.location.live.net
- desktop-hsgcbep
- v10.events.data.microsoft.com
- login.live.com
- config.edge.skype.com
- settings-win.data.microsoft.com
- www.bing.com
- fd.api.iris.microsoft.com
- dns.msftncsi.com
- windows.msn.com
- officeclient.microsoft.com
- licensing.mp.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- watson.events.data.microsoft.com
- ecs.office.com
- g.live.com
- assets.msn.com
- tas02.sls.update.microsoft.com
Dropped files
- 6cc2a755959aa5b9d4f5ca9b66fb4df58b07ee4ccd9491db0fc7ad41d2029f30 -
6cc2a755959aa5b9d4f5ca9b66fb4df58b07ee4ccd9491db0fc7ad41d2029f30
Embedded domains
- inference.location.live.net
Embedded IP addresses
- 162.159.36.2
More Potao samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report