MALICIOUS — 191ec88a8ef8636c3623ce75f2a65760b0a66c4d69e28e4108026d3ce26ba812
MALICIOUS — 191ec88a8ef8636c3623ce75f2a65760b0a66c4d69e28e4108026d3ce26ba812 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the LightStone family. 5 of 56 detection engines flagged it, exhibiting 6 ATT&CK techniques.
Identification
- SHA-256:
191ec88a8ef8636c3623ce75f2a65760b0a66c4d69e28e4108026d3ce26ba812 - SHA-1:
9db31f2d16f646af4c3eff2d281e945773eb1a06 - MD5:
803072eaec25c3927fefe200ed685601 - imphash:
fcf1390e9ce472c7270447fc5c61a0c1 - ssdeep:
49152:UbA30N5mZY/eIfERZcHfUHnRrprmUtzEEH85Z9Q3JDndRlHaFAf:Ubp5m6fuc/UHRVrmWgw8Z9CJbdD6FAf - TLSH:
T18E5BD06BC67A6E67CDFC76285C33D59F2AE6A807203D21404B87F43A21161A74B3117B - Submitted as: 191ec88a8ef8636c3623ce75f2a65760b0a66c4d69e28e4108026d3ce26ba812
- File type: pe · Size: 2360545 bytes
- Verdict: malicious (100/100) · Family: LightStone
Detections (5 of 56 engines)
- capa (capabilities): capability:execution/powershell
- ClamAV (daily): Win.Malware.Uztuby-9848412-0
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- Microsoft Defender: flagged
- Kaspersky (KVRT): HEUR:Backdoor.MSIL.LightStone.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 14 weighted signals:
- ClamAV (daily) flagged Win.Malware.Uztuby-9848412-0 (rule
Win.Malware.Uztuby-9848412-0) - engine signal, weight 0.90, confidence 0.95 - 2 behavioral detection(s) across 2 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.63, confidence 0.90 - Microsoft Defender flagged flagged (rule
flagged) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Backdoor.MSIL.LightStone.gen (rule
HEUR:Backdoor.MSIL.LightStone.gen) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.50, confidence 0.70 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Contacted 2 external host(s) and 6 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497, T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - Dropped 3 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
21581 behavior events · 3 ATT&CK techniques · 12 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
- licensing.mp.microsoft.com
- www.bing.com
- th.bing.com
- fe3cr.delivery.mp.microsoft.com
Dropped files
- C:\Recovery\reviewwinsessionhostbrokerCrtmonitor.exe -
5911358b42e2e4a186d9b2e71efcfe8c08e0b6ebdd486c1439ef81a5d3c05659 - C:\Users\analyst\AppData\Local\Temp\spWno9lfKm -
0012bf65a62188866436c24bb4d97e29d06c2459818940f33f1b1fe0b71bf1ec - C:\reviewwinsessionhost\PkFU6uy1kbvW5.bat -
7b027a0d1953835599f6cf5700192c0c25ef014f98811ec0ec89ab123860700c - C:\reviewwinsessionhost\aRERDNiWMwhRxh6I82hZaoEN5OLv.vbe -
28335214fd8d6b963a59fe365ba3bd63371ebc4cd91a061c22e1faad32a4b5a8 - C:\Recovery\cb4be4d22deb3de7467a48224c0f9aa58961360f -
c8cea68d3f7711deb807b4f1e458a0a2dc3624a9e8a8dc3df8a01f18ce4647bc - C:\Users\analyst\AppData\Local\Temp\Yhbk3iUtGP.bat -
ebcb7d625de6ec44fdb80fee70f9d439482447d6e0017e8299a81444f95b84ff - C:\Recovery\ebf1f9fa8afd6d1932bd65bc4cc3af89a4c8e228 -
512a29a60b12bb08c6ec538075f93a8e794f2f76898e64c2f269b1f6e6513712 - 8a598da4b5f09a55415cd9b200d90edfc65150006e431080e46aa3549aa1608f -
8a598da4b5f09a55415cd9b200d90edfc65150006e431080e46aa3549aa1608f - C:\ThreatLens\2a08264799fbe84f2cb3417a4144790b358759d2 -
b2b2cf4d5163243b097a51fe7f415ba20b0c643b0daa3c419871f7272eabd2d1 - C:\ThreatLens\eddb19405b7ce1152b3e19997f2b467f0b72b3d3 -
959d045a75eda428d87157515f81c7ff4f1b1b3383a465ebf644334f1bd80fb9 - db158725807a4dfbe815bc27550f319dc005cb90ff23bdb1d27cdc4a794652f1 -
db158725807a4dfbe815bc27550f319dc005cb90ff23bdb1d27cdc4a794652f1 - 53c7bcd374f1a67f1d199890ce855934777d62c82ae6257dca584da2bb90d065 -
53c7bcd374f1a67f1d199890ce855934777d62c82ae6257dca584da2bb90d065
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- to9.uk
- schemas.microsoft.com
- d.es
Embedded IP addresses
- 20.184.175.6
- 4.230.171.124
- 48.211.4.16
- 52.253.84.76
- 20.165.94.54
- 135.233.95.144
- 20.184.175.21
- 104.18.33.89
- 4.207.44.76
- 52.110.12.20
- 52.110.12.21
- 172.178.240.161
- 72.145.35.99
- 52.148.114.188
- 52.110.12.47
- 52.110.12.4
File paths
- D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb
- T:\:d:l:t:
- C:\reviewwinsessionhost\reviewwinsessionhostbrokerCrtmonitor.exe
More LightStone samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report