MALICIOUS — 0b40c8b390504546f10ecc9ceaa0830e35706bad79f03718d22c96ef988811c2
MALICIOUS — 0b40c8b390504546f10ecc9ceaa0830e35706bad79f03718d22c96ef988811c2 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the RedLine family. 4 of 56 detection engines flagged it.
Identification
- SHA-256:
0b40c8b390504546f10ecc9ceaa0830e35706bad79f03718d22c96ef988811c2 - SHA-1:
b7f60449f83c9942308ac0fac7491d41e2acde59 - MD5:
e7b58d9e169fead322afc4e23b667c00 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
6144:2kqoDfvM9jf+wfJtlFxohA1ze1e4xHiY7CBLRgWD1R:f7U9L+Ut3/GqLRX - TLSH:
T12F470E4B839C6D35C4DC401E027E0EDB8BDF74297A73321E122849369A996739E325B7 - Submitted as: 0b40c8b390504546f10ecc9ceaa0830e35706bad79f03718d22c96ef988811c2
- File type: pe · Size: 341400 bytes
- Verdict: malicious (99/100) · Family: RedLine
Detections (4 of 56 engines)
- LIEF (executable format parser): lief:invalid-authenticode
- Emsisoft (Emergency Kit): Trojan.Agent
- Trellix Stinger (McAfee): AgentTesla-FDDZ!E7B58D9E169F
- Kaspersky (KVRT): UDS:Trojan-Spy.MSIL.Stealer.gen
Why this verdict
The malicious score of 99/100 is the fusion of 8 weighted signals:
- Extracted RedLine config (1 C2) - engine signal, weight 0.80, confidence 0.90
- Memory forensics: 2 finding(s) attributed to the sample across 2 technique(s), e.g. process hollowing in tsk_3fa09855d6 (pid 2620) (rule
windows.hollowprocesses.HollowProcesses) - memory signal, weight 0.75, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Agent (rule
Trojan.Agent) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged AgentTesla-FDDZ!E7B58D9E169F (rule
AgentTesla-FDDZ!E7B58D9E169F) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:Trojan-Spy.MSIL.Stealer.gen (rule
UDS:Trojan-Spy.MSIL.Stealer.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 1 external host(s) and 17 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
1404 behavior events · 0 ATT&CK techniques · 10 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- windows.msn.com
- www.msn.com
- config.edge.skype.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
Dropped files
- 1383b0456c32b7e2bb8d5f00e68cef180c90579a63ee577c5321077af1fc9ac2 -
1383b0456c32b7e2bb8d5f00e68cef180c90579a63ee577c5321077af1fc9ac2 - 3f2c9874112986014b891bf5bc746eb91f54f12a0bf16dd8c8c9a35ac9411c86 -
3f2c9874112986014b891bf5bc746eb91f54f12a0bf16dd8c8c9a35ac9411c86 - 8460121ccb5e439580c31931532c097030bff7b5dc9b277e235f6a4d8218afc2 -
8460121ccb5e439580c31931532c097030bff7b5dc9b277e235f6a4d8218afc2 - 16ee9fd7b32b79efba4154c77ea856dff744a8421c817ee0ffb41e4afe9cb2d7 -
16ee9fd7b32b79efba4154c77ea856dff744a8421c817ee0ffb41e4afe9cb2d7 - 60203938ac6c3c84a3e46bc5a3ec55a48b2a7cbd4a524d4a655e10a3984a050f -
60203938ac6c3c84a3e46bc5a3ec55a48b2a7cbd4a524d4a655e10a3984a050f - aa01728444e2caef95b4dc9dcaa4e519070e0a166ba099600606002aa2374be5 -
aa01728444e2caef95b4dc9dcaa4e519070e0a166ba099600606002aa2374be5 - 28309fd6ca7986df38e51606bef86f92483e3fe3f98f09c7a7d9925dafa670d4 -
28309fd6ca7986df38e51606bef86f92483e3fe3f98f09c7a7d9925dafa670d4 - 7cfba7cbaea634f404cdd4eb471bfb4de619b75b98d3ccf280852505a867bfd2 -
7cfba7cbaea634f404cdd4eb471bfb4de619b75b98d3ccf280852505a867bfd2 - c2ac8d5e92275d7416e5f6274a22f89cd98221c679ead7cb9381fa828717f33f -
c2ac8d5e92275d7416e5f6274a22f89cd98221c679ead7cb9381fa828717f33f - c2a47f955a1677fb15b6a34c1777ee525c760b644898be9bf16e9878b8faec34 -
c2a47f955a1677fb15b6a34c1777ee525c760b644898be9bf16e9878b8faec34
Embedded URLs
- http://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
- https://www.digicert.com/CPS0
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- www.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- cacerts.digicert.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 20.42.65.90
- 20.247.185.124
- 4.230.171.124
- 185.215.113.109
- 4.247.188.233
- 85.210.193.152
- 72.153.5.136
- 52.148.114.188
- 52.110.12.52
- 52.110.12.54
More RedLine samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report