MALICIOUS — 02a1bef968a7d64ffd5ace45a9db0854704874349d4d9e5f291ad3a9eae7647d
MALICIOUS — 02a1bef968a7d64ffd5ace45a9db0854704874349d4d9e5f291ad3a9eae7647d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Bladabindi family. 6 of 56 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
02a1bef968a7d64ffd5ace45a9db0854704874349d4d9e5f291ad3a9eae7647d - SHA-1:
0335d7185fa109f86ca7f5f9bbc503e422b0cda4 - MD5:
0860b1a8eb460e2aac91bbb8dfd1193e - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
3072:18WZGrfC/JSwD0GupZV7oFlKK+hAX8fcGxRCpx8RIHIrelbAkL:18GG6gGCeKwXgNxRI83KlUk - TLSH:
T15240E04EC9CE8E17C86EAE9E605790FF26DC5FB7A8312809117E21777044867D732129 - Submitted as: 02a1bef968a7d64ffd5ace45a9db0854704874349d4d9e5f291ad3a9eae7647d
- File type: pe · Size: 180224 bytes
- Verdict: malicious (98/100) · Family: Bladabindi
Detections (6 of 56 engines)
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Backdoor:MSIL/Bladabindi.AJ
- Emsisoft (Emergency Kit): Gen:Heur.MSIL.Bladabindi.1
- Kaspersky (KVRT): HEUR:Trojan-PSW.MSIL.Agensla.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 11 weighted signals:
- Microsoft Defender flagged Backdoor:MSIL/Bladabindi.AJ (rule
Backdoor:MSIL/Bladabindi.AJ) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Heur.MSIL.Bladabindi.1 (rule
Gen:Heur.MSIL.Bladabindi.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan-PSW.MSIL.Agensla.gen (rule
HEUR:Trojan-PSW.MSIL.Agensla.gen) - engine signal, weight 0.55, confidence 0.85 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Contacted 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Extracted Njrat config (0 C2) - engine signal, weight 0.45, confidence 0.60
- Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-sections:.text (rule
high-entropy-sections:.text) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.text, Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Memory forensics: 4 finding(s) elsewhere in the guest, not attributed to this sample, e.g. RWX/private injected region in SppExtComObj.E (pid 5800) (rule
windows.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
1121 behavior events · 0 ATT&CK techniques · 8 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- www.bing.com
- assets.msn.com
- th.bing.com
- fe3cr.delivery.mp.microsoft.com
- settings-win.data.microsoft.com
- slscr.update.microsoft.com
Dropped files
- 691fb82c3f78a49086c6f61747195cde07448d2c03cc91b1889b407c50183c98 -
691fb82c3f78a49086c6f61747195cde07448d2c03cc91b1889b407c50183c98 - 0b54d8226641ab4fbbcc8f93d8e7112cbecd1bd0b4bff7400d5a9f8535ca1c3d -
0b54d8226641ab4fbbcc8f93d8e7112cbecd1bd0b4bff7400d5a9f8535ca1c3d - d73582d96028fb4cbccec6b3a8b74a7642e4a71c71ae5cf3c646041501055639 -
d73582d96028fb4cbccec6b3a8b74a7642e4a71c71ae5cf3c646041501055639 - 200e4d824b2345bb3791dfbf562c2e5f50f8e67fa62ff10b124fffd5a3582ec9 -
200e4d824b2345bb3791dfbf562c2e5f50f8e67fa62ff10b124fffd5a3582ec9 - 5120a1a340c5adc1cedc3ef8ce7ed3678aae450fe3ef7a0d68d66c615110c931 -
5120a1a340c5adc1cedc3ef8ce7ed3678aae450fe3ef7a0d68d66c615110c931 - 122d63bd508327db00224f82fa1e9f7a31df500a763335d8b342ab8cb9184dd1 -
122d63bd508327db00224f82fa1e9f7a31df500a763335d8b342ab8cb9184dd1 - 4a493bb68cdc37c2d1af454e2b6d310dd64cadfccdea27d5b437584c14de427f -
4a493bb68cdc37c2d1af454e2b6d310dd64cadfccdea27d5b437584c14de427f - 5e9f09e06e5e7cf07b905a04dff6caad2c25b8b23f61a8f11754edfe3b43fcde -
5e9f09e06e5e7cf07b905a04dff6caad2c25b8b23f61a8f11754edfe3b43fcde
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 4.207.44.77
- 20.3.1.41
- 4.155.94.229
- 4.230.171.124
- 172.64.154.167
- 135.233.95.135
- 57.155.104.224
- 74.178.240.61
- 40.79.141.152
- 52.110.12.45
- 52.110.12.51
More Bladabindi samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report