MALICIOUS — 0cff6694d5a665accb26248d4d14d8c7fa1343694ad37a7796bad10ed7622b86
MALICIOUS — 0cff6694d5a665accb26248d4d14d8c7fa1343694ad37a7796bad10ed7622b86 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Cryptinject family. 4 of 56 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
0cff6694d5a665accb26248d4d14d8c7fa1343694ad37a7796bad10ed7622b86 - SHA-1:
5d6a120f05aa922c3e9fcf23ce765f10adcdf34d - MD5:
c2cd00f041b7b6d2a530050dc5ce0d89 - imphash:
a9192bab5c7c795c7488b69a1853f9c2 - ssdeep:
3072:MEsmNnEO58ppAsPqEsmNnEKEsmNnEO58ppAsPqEsmNnEKEsmNnEKEsmNnEO58ppr:MZsvwAHZstZsvwAHZstZstZsvwA0 - TLSH:
T17B4B82D972542715EDF0F858AD04AD2C71A299B1223A2BD86407C03F75EEBF7067C829 - Submitted as: 0cff6694d5a665accb26248d4d14d8c7fa1343694ad37a7796bad10ed7622b86
- File type: pe · Size: 473484 bytes
- Verdict: malicious (100/100) · Family: Cryptinject
Detections (4 of 56 engines)
- ClamAV (daily): Win.Malware.Cryptinject-9890994-0
- Microsoft Defender: Trojan:Win32/CryptInject!pz
- Trellix Stinger (McAfee): Trojan-FUFL!C2CD00F041B7
- Kaspersky (KVRT): Virus.Win32.Lamer.ks
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Malware.Cryptinject-9890994-0 (rule
Win.Malware.Cryptinject-9890994-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/CryptInject!pz (rule
Trojan:Win32/CryptInject!pz) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Trojan-FUFL!C2CD00F041B7 (rule
Trojan-FUFL!C2CD00F041B7) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.Lamer.ks (rule
Virus.Win32.Lamer.ks) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 1 external host(s) and 18 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497, T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://www.pinkworld.com, http://www.youporn.com, http://www.redtube.com - static signal, weight 0.35, confidence 0.60
- Dropped 23 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
92055 behavior events · 2 ATT&CK techniques · 38 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
Dropped files
- C:\Windows\System32\vcruntime140_threads.dll -
9cb608f0ee7559f7983655c6510e26e78c93fd2cb123610f6afe6d23072c1708 - C:\Windows\DtcInstall.log -
6bf07835087fd1df090c661267f8f4803575bb49db865fea1b0e941a1087bbea - C:\Windows\System32\msvcp140.dll -
5c0c9658884db9a9c74b41fa0805f96d4ae95af5962b83b543ebb2b6b65f1672 - C:\Windows\System32\NOISE.DAT -
c2a94b70347c16367a2f9791135eee50c0e61bb90717223c3523a07d5a664be6 - C:\Windows\System32\concrt140.dll -
f05f2d3c7c73d8701dbab94ae8e677d48be37e73a191787f5cea55519ce05b4d - C:\Windows\System32\msclmd.dll -
f8c585e9a36f256f5b01ddf5a16122580f2877aecb9745a70e9ed36cdbf6938f - C:\Windows\Professional.xml -
4f3690d3cc07f282aa75454667ef8147749b3cb2b80ba21f7fe5a5bac69ee7e0 - C:\Windows\System32\mfc140.dll -
ebab06d07c0382aa4904c446bb75bfb883a77a68e4fa63b814de920d53e95d2f - C:\Windows\pyshellext.amd64.dll -
68a89911317aa9932287f78d908dcbc3f11c8f3af6674dc51d4ffe8fb0f2011e - C:\Windows\System32\msvcp140_1.dll -
8e626187edbaa589885f19107eb1eaaf0daf0841f1b9093b29adeeb512f67ede - C:\Windows\setupact.log -
5649ecc5646e2f2083addf07b4f744f3916c8a114ef6a47329e17c61aa9f79bd - C:\Windows\System32\mfcm140.dll -
6e1e3a83df08e6491f2d183e757526c6c9a816478e9abc4e57dbbc322598d4a2 - C:\Windows\System32\PrintConfig.dll -
6d2596cddc8db12da77320f852d8008010fe889af72b48972483a3ad5a9ea1b2 - C:\Windows\System32\msvcp140_atomic_wait.dll -
2d7aed45324bc3c0a062aaeaabbaa09101a416b90bf99d307e4ba53e69f96e9c - C:\Windows\system.ini -
634e6ab7f86dd8d2fde2612c614355fc8e0fb54746be9a104bb0f35c528a2e46
Embedded URLs
- http://www.pinkworld.com
- http://www.youporn.com
- http://www.redtube.com
- http://www.assparade.com/
- http://www.freeav.com/
- http://www.antispyware.com/
- http://www.antivirus.com/
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://office.microsoft.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- http://203.26.79.13/filestreamingservice//files/6c2dbffa-872a-4f74-b39c-0ab782eea5bf/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/6c2dbffa-872a-4f74-b39c-0ab782eea5bf?P1=1787354299&P2=404&P3=2&P4=ElLaAGSqvHE%2fud1oOy9cHTUmePvNSsovOeUG0kb6%2bBU6%2b%2bMYS0cpPMllI2X7kLzG0p4YKwEcdFNAK2Q5UFj2GA%3d%3d&cacheHostOrigin=tlu.dl.delivery.mp.microsoft.com
Embedded domains
- www.pinkworld.com
- www.youporn.com
- www.redtube.com
- www.assparade.com
- www.freeav.com
- www.antispyware.com
- www.antivirus.com
- crl.microsoft.com
- www.microsoft.com
- office.microsoft.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 20.42.65.85
- 4.230.171.124
- 57.155.101.212
- 4.144.132.114
- 74.178.76.128
- 135.232.92.97
- 40.74.98.197
- 74.178.240.61
- 104.18.33.89
- 20.42.73.30
- 20.42.179.192
- 20.184.175.17
- 4.207.44.65
- 162.159.142.9
- 92.223.78.30
- 135.233.45.221
- 48.199.12.1
- 13.89.179.12
- 203.26.79.13
- 4.150.223.99
- 52.148.114.188
- 52.110.12.14
- 52.110.12.45
- 72.145.35.104
File paths
- C:\!
More Cryptinject samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report