MALICIOUS — 0dacd6ff329842e9b970ee23ea1b0243b5926bc523fdb4a6835a02136300c118
MALICIOUS — 0dacd6ff329842e9b970ee23ea1b0243b5926bc523fdb4a6835a02136300c118 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Bertel family. 4 of 56 detection engines flagged it.
Identification
- SHA-256:
0dacd6ff329842e9b970ee23ea1b0243b5926bc523fdb4a6835a02136300c118 - SHA-1:
ebe72c271057aa20c8aae5fde7cfe4b8f851765c - MD5:
1513f5dfe2f6205ef884d2062584b5e0 - imphash:
d8830768e26d5542e5a19dad95d6bbc7 - ssdeep:
384:SQ6rb88pnllolDiz+FHOYNkqiMlZlZloDlmlZllcl7l1hllEXvnblMlZlEY:ShdlEDwWRFXXKEXMprzEfJKXEY - TLSH:
T151291AC6F3291C72E56A5BF708DAD28C26295C7D6714B204A1012C1BA4F5DDB3D87C4E - Submitted as: 0dacd6ff329842e9b970ee23ea1b0243b5926bc523fdb4a6835a02136300c118
- File type: pe · Size: 18963 bytes
- Verdict: malicious (99/100) · Family: Bertel
Detections (4 of 56 engines)
- ClamAV (daily): Win.Worm.Bertel-1
- Microsoft Defender: Worm:Win32/Bartly.A
- Emsisoft (Emergency Kit): Win32.Bertlea.A
- Kaspersky (KVRT): Virus.Win32.HLLP.Bertle.4608
Why this verdict
The malicious score of 99/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Win.Worm.Bertel-1 (rule
Win.Worm.Bertel-1) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Worm:Win32/Bartly.A (rule
Worm:Win32/Bartly.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Bertlea.A (rule
Win32.Bertlea.A) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.HLLP.Bertle.4608 (rule
Virus.Win32.HLLP.Bertle.4608) - engine signal, weight 0.55, confidence 0.85 - Contacted 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
Dynamic analysis (windows)
515 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- desktop-hsgcbep
- login.live.com
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
- www.bing.com
- licensing.mp.microsoft.com
- tas02.sls.update.microsoft.com
- fe3cr.delivery.mp.microsoft.com
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 20.42.65.94
- 52.123.252.224
- 4.230.171.124
- 40.84.97.4
- 52.230.59.222
- 74.178.76.128
- 74.179.77.164
- 52.168.117.169
- 20.165.94.63
- 135.233.45.221
- 52.110.12.53
- 92.223.78.30
- 52.110.12.10
More Bertel samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report