MALICIOUS — 0bc3ce0eb0a32c8929a9bc8c124eb05c65d03c5f12ea2613c7d35e0eefda240f
MALICIOUS — 0bc3ce0eb0a32c8929a9bc8c124eb05c65d03c5f12ea2613c7d35e0eefda240f is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Bgmo family. 3 of 56 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
0bc3ce0eb0a32c8929a9bc8c124eb05c65d03c5f12ea2613c7d35e0eefda240f - SHA-1:
a78490237e97acdb7186b1d18aeb0b9c904e3c2d - MD5:
ea1a723598a8baf1e57caf444381402f - imphash:
a9192bab5c7c795c7488b69a1853f9c2 - ssdeep:
192:G49HsxwSUFx+UEqzerwdIpJNY8uMkp4fvL:GBXUFh1yvN/uMa4b - TLSH:
T1452DE95612141714ECF99DA0D8989E2C21C7A9E5A2BB1FDCF11FAC0771EE8A310390F9 - Submitted as: 0bc3ce0eb0a32c8929a9bc8c124eb05c65d03c5f12ea2613c7d35e0eefda240f
- File type: pe · Size: 29077 bytes
- Verdict: malicious (99/100) · Family: Bgmo
Detections (3 of 56 engines)
- ClamAV (daily): Win.Dropper.Bgmo-9890812-0
- Microsoft Defender: Trojan:Win32/CryptInject!pz
- Kaspersky (KVRT): Virus.Win32.Lamer.ks
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Win.Dropper.Bgmo-9890812-0 (rule
Win.Dropper.Bgmo-9890812-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/CryptInject!pz (rule
Trojan:Win32/CryptInject!pz) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.Lamer.ks (rule
Virus.Win32.Lamer.ks) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 2 external host(s) and 6 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1622, T1497.001, T1082 - dynamic signal, weight 0.40, confidence 0.75
- persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://www.pinkworld.com, http://www.youporn.com, http://www.redtube.com - static signal, weight 0.35, confidence 0.60
- Dropped 22 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
40684 behavior events · 2 ATT&CK techniques · 36 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- odc.officeapps.live.com
- www.msn.com
- settings-win.data.microsoft.com
- assets.msn.com
- www.bing.com
- tas02.sls.update.microsoft.com
- licensing.mp.microsoft.com
- fe3cr.delivery.mp.microsoft.com
Dropped files
- C:\Windows\System32\NOISE.DAT -
878e54f22f8a00c8fe79bbf28685843e118353c7dacdb7fae79bea116c2f8efd - C:\Windows\setuperr.log -
14f6a3878f91d098fc30a56f99752697d57d0750ec639f215b823256d2bdb8c9 - C:\Windows\System32\msvcp140_1.dll -
0d91504f32f0a72f4d48c943fccec04386bfe85e499e95cd850fbe4898495f7e - C:\Windows\pyshellext.amd64.dll -
4604134130d05364c272cc8f84272f7468d4a5f74603afa7fa2ca3f2424b5bd4 - C:\Windows\System32\vcruntime140_threads.dll -
596e04f210242c2a9ca6593d4444c693e7646857d8ddf59ec27a9057eabaf67d - C:\Windows\setupact.log -
13512936e4820f886e53075ed392455c2dd340d6ac485b7e5a31d5521e035bc0 - C:\Windows\System32\mfcm140u.dll -
439285a441a3779e93ffa5e5b71521226f8ee0faa93f3882b84902279300ed70 - C:\Windows\win.ini -
7103b8c7a506c442058154234ad47f05b290d361781cfddbf697723fe611dd8d - C:\Windows\WindowsUpdate.log -
8c408507c55bee41e32dafdee7191175d4e63bc3df500979b575556c0addeb3b - C:\Windows\System32\msvcp140.dll -
1575c10ad5f06b5331740c6383b33eee25d3a6c9415ab850e727f347bd669d9d - C:\Windows\lsasetup.log -
2a605a338ff215b989fe1bb33483b1cdcd6d9bc1b75a1b9bbabdb1734548e0fe - C:\Windows\System32\license.rtf -
fe851562097763933ca5e67fe44373d49604c93c81bd35ca741031685b86a5b5 - C:\Windows\PFRO.log -
ed2bdfe0ee7624a5ee930258bee90d0adb9b330f24e2ad29ceb1265afe76f330 - C:\Windows\System32\dssec.dat -
a9b7087919d093856528a99241cb5dbc45f6309971cae5d9e94890be35ad82ff - C:\Windows\Professional.xml -
e0dad788c85a9930d8dd2b97baeb6ec9b8b361ccb5a30304c2b39731aac0dd6d
Embedded URLs
- http://www.pinkworld.com
- http://www.youporn.com
- http://www.redtube.com
- http://www.assparade.com/
- http://www.freeav.com/
- http://www.antispyware.com/
- http://www.antivirus.com/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- www.pinkworld.com
- www.youporn.com
- www.redtube.com
- www.assparade.com
- www.freeav.com
- www.antispyware.com
- www.antivirus.com
Embedded IP addresses
- 51.116.246.105
- 52.123.252.242
- 4.230.171.124
- 20.42.179.192
- 135.232.92.137
- 20.247.184.197
- 74.178.240.51
- 4.150.223.96
- 52.110.12.52
- 52.110.12.2
- 20.184.175.2
- 20.42.73.25
- 135.233.45.221
- 72.145.35.110
- 52.148.114.188
- 52.110.12.46
- 52.110.12.33
More Bgmo samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report