MALICIOUS — 1cd3402ec910e27b023ead10f91ccfa3e2fcff9da6d31f7e9711ef78a6b517d7
MALICIOUS — 1cd3402ec910e27b023ead10f91ccfa3e2fcff9da6d31f7e9711ef78a6b517d7 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Gandcrab family. 5 of 56 detection engines flagged it.
Identification
- SHA-256:
1cd3402ec910e27b023ead10f91ccfa3e2fcff9da6d31f7e9711ef78a6b517d7 - SHA-1:
d7c2d007c4709d71966f981ac6d78283de163606 - MD5:
deddae380ef564f140c4b09436fa40dd - imphash:
89b936c2fdecda00580c9be31a57dc50 - ssdeep:
3072:CBsAwANar4mnAD/IDz31t0a31gA6n5ZeBeYHBbJKFc9du8UtDZJIfb/Arw6yW+:CSAW4mnIG1XGXYHBbJKFc9IZ4fb/+wn - TLSH:
T14443E1DD023E26C2D8B6EA9938860C4F656BA0E0D7B7195D4AC20E1DF5DB853EC9140F - Submitted as: 1cd3402ec910e27b023ead10f91ccfa3e2fcff9da6d31f7e9711ef78a6b517d7
- File type: pe · Size: 230920 bytes
- Verdict: malicious (99/100) · Family: Gandcrab
Detections (5 of 56 engines)
- ClamAV (daily): Win.Packed.Gandcrab-6552923-4
- Microsoft Defender: Ransom:Win32/GandCrab.AO
- Emsisoft (Emergency Kit): Trojan.Ransom.GandCrab.Gen.2
- Trellix Stinger (McAfee): Packed-FBN!DEDDAE380EF5
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
Why this verdict
The malicious score of 99/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Packed.Gandcrab-6552923-4 (rule
Win.Packed.Gandcrab-6552923-4) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Ransom:Win32/GandCrab.AO (rule
Ransom:Win32/GandCrab.AO) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Ransom.GandCrab.Gen.2 (rule
Trojan.Ransom.GandCrab.Gen.2) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Packed-FBN!DEDDAE380EF5 (rule
Packed-FBN!DEDDAE380EF5) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win32.Generic (rule
HEUR:Trojan.Win32.Generic) - engine signal, weight 0.55, confidence 0.85 - Contacted 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Memory forensics: 4 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
37466 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- licensing.mp.microsoft.com
- desktop-hsgcbep
- login.live.com
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- th.bing.com
- v10.events.data.microsoft.com
- settings-win.data.microsoft.com
- edge.microsoft.com
Dropped files
- C:\Windows\xacoziyecakefasomoja xuruyilizajamo fuvonocudolaribapekafixetado kocawepeyemibejere juhoyafayaxatugeluvosabefela -
09dab62af8d1355c4785e69e356e4956cedb44719d79ac89e92595fade15f186 - 769dd68b3cf225d360e5b3c2dd2003464c77b92123663901f65fe13505e4211d -
769dd68b3cf225d360e5b3c2dd2003464c77b92123663901f65fe13505e4211d
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 4.144.132.223
- 20.184.175.19
- 4.230.171.124
- 172.64.154.167
- 172.66.2.5
- 51.132.193.104
- 4.247.188.233
- 172.178.240.162
- 52.110.12.14
- 52.110.12.55
More Gandcrab samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report