MALICIOUS — ThreatLens .exe
MALICIOUS — ThreatLens .exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Krap family. 5 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
1bdfc3014f303b7fc7e72944f7efb97b2bab2059e4f6f7c9233f90244be3e77e - SHA-1:
815fa4caf1a2eec6b79cc70ae822c903624c1503 - MD5:
272dde96354683d70c8e8e31ddde42c8 - imphash:
3a2003ea545fe942681da9e7683ebb58 - ssdeep:
12288:CxIK9V14ImyHYbLyquUv6bz1Jbu2xgSSHPZWAmU1SzGPVbWBxZw6pM6+nz5pFsPy:CJEyY1SjSAxdMVp - TLSH:
T14F49BF5827B4804BEF96416FD5CB027E139A07E20144668C5CDBA82FD4EE12F9DCCA5E - Submitted as: ThreatLens .exe
- File type: pe · Size: 420286 bytes
- Verdict: malicious (99/100) · Family: Krap
Detections (5 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Packed.Mira-7330891-0
- Detect It Easy (packer/type): DIE:MinGW
- Microsoft Defender: Trojan:Win32/Krap!pz
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Packed.Mira-7330891-0 (rule
Win.Packed.Mira-7330891-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Mira): $WinREAgent .exe - dynamic signal, weight 0.62, confidence 0.90
- 1 behavioral detection(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 23 external host(s) at runtime (22 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:MinGW (rule
DIE:MinGW) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.lol 1, MinGW - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
5937 behavior events · 1 ATT&CK techniques · 34 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- settings-win.data.microsoft.com
Dropped files
- C:\$WinREAgent .exe -
1176ee53458406895c89dc52bc357b3eec4dfdb810ad41ae377ccd59b818f5ec - C:\Program Files (x86) .exe -
641dddc54996bb9200bcbf556a995c92e098a391a4aefffab2fd7b2285153806 - C:\PerfLogs .exe -
df56f95a8bc0d3bfdfad3346801e3c1cba67dee9bfc872d16f5c761a917d59d0 - C:\DumpStack.log.tmp .exe -
72676e0e98cf196e13de1e446d10cb5bdf53b58bc6b425c7f0102001eef33f50 - C:\Recovery .exe -
014ab3394651933a0862ed99b4f6f9bf4f43cc5b926fc7f394c026f37b4845fe - C:\800.ini -
7c39f1f7574756b1480251b6f09b399a3aaad1e41cb7c4003e69f9ad0a626881 - C:\$Recycle.Bin .exe -
5e1fd9740842f6d75bd7e1bc0c6bdadd4164e217ada4b61466fcb40b1c27ad64 - C:\System Volume Information .exe -
0cfaf528273f2c383cf5c40027961dbf89e8acf2b41804743c6e431f337288de - C:\800.ini .exe -
5d42f4e96f6c9d32afa57e34e431a689e7566c1d34f4aee0c6eb3dc2270ea408 - C:\uac-done.txt -
ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a - C:\Config.Msi .exe -
1390201a71dc3ad1167859812f7541c6b232c742d7d2d0b6933151250601fd09 - C:\scoobe-fix.cmd .exe -
4d8395cd0fa2a382dd1ee71719023ec898db88d82bebedc9884f9ed2968e515a - C:\ThreatLens .exe -
d36ce2485311a544b58c6acdb5a881cdd8bd85739918829c3f65d56b912c5f6a - C:\inetpub .exe -
2ef904b631c8cbb7b60e3c9f1454f08c3d1b04590d050bb92c8da620db2f4d69 - C:\swapfile.sys .exe -
03f609896a74d8a1ed5cce6a68f900e6706983629c1eb2ec42a574949c9d17d3
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787665569&P2=404&P3=2&P4=HkehVAZFiiIqkDuLDUj6K4DWdZg4eJhOY2JGiJvDocGkG1RFuENUesCgF4M2%2fgktDXlZM8R8l%2f8hEkhkT0W2JA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787665607&P2=404&P3=2&P4=PShwk43d8BFbFgo838XOgi%2bK8uYWm9k9yfhmBu%2fdya8lpyG4emApmPB2IUSx5eLYRvfZ%2fKfITIdkGV0fpadOeg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 104.46.162.231
- 52.110.12.51
- 4.230.171.124
- 85.210.193.152
- 20.247.185.124
- 52.110.12.16
- 74.179.77.204
- 20.42.73.26
- 74.178.240.51
- 4.150.223.109
- 135.233.45.221
- 20.236.44.162
- 52.123.128.14
- 52.123.252.239
- 203.26.79.13
- 52.123.252.241
- 52.148.114.188
- 74.178.76.44
- 20.42.179.192
- 4.150.223.102
- 72.154.7.106
- 52.110.12.33
- 52.110.12.50
More Krap samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report