MALICIOUS — 1ce80b56b7acc37e7919f891f2d0e90414bb7b0de521267daed9923b2d7d6cb4
MALICIOUS — 1ce80b56b7acc37e7919f891f2d0e90414bb7b0de521267daed9923b2d7d6cb4 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Gamarue family. 6 of 56 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
1ce80b56b7acc37e7919f891f2d0e90414bb7b0de521267daed9923b2d7d6cb4 - SHA-1:
d174a69e69c7cd9f7534fc6c716ebe763fbb64b7 - MD5:
5523e5721000ede181f415c6fcdd9cc4 - imphash:
fdd04a035b60535fe13c28e8c52a1a78 - ssdeep:
3072:rSQ0EWVwZhKxC5Rt+k60Zh+qw6PYSsszfHZTZJ2lC:rPA6wxmuJspr2l - TLSH:
T1D8453E7A640B3A36D26215C6A3F9E64E3CEEF4A51E5A140103335FB9327EDDF1046A24 - Submitted as: 1ce80b56b7acc37e7919f891f2d0e90414bb7b0de521267daed9923b2d7d6cb4
- File type: pe · Size: 290816 bytes
- Verdict: malicious (100/100) · Family: Gamarue
Detections (6 of 56 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- ClamAV (daily): Win.Malware.Gamarue-6729983-0
- Microsoft Defender: Worm:Win32/Gamarue.F
- Emsisoft (Emergency Kit): Trojan.VB.12
- Trellix Stinger (McAfee): Trojan-FQAL!5523E5721000
- Kaspersky (KVRT): Trojan.Win32.Lilu.c
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 100/100 is the fusion of 17 weighted signals:
- ClamAV (daily) flagged Win.Malware.Gamarue-6729983-0 (rule
Win.Malware.Gamarue-6729983-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 1 finding(s) attributed to the sample across 1 technique(s), e.g. process hollowing in skyrpe.exe (pid 3204) (rule
windows.hollowprocesses.HollowProcesses) - memory signal, weight 0.70, confidence 0.85 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - 1 behavioral detection(s) across 1 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged Worm:Win32/Gamarue.F (rule
Worm:Win32/Gamarue.F) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.VB.12 (rule
Trojan.VB.12) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Trojan-FQAL!5523E5721000 (rule
Trojan-FQAL!5523E5721000) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Lilu.c (rule
Trojan.Win32.Lilu.c) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 1 external host(s) and 7 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1497, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Extracted Andromeda config (0 C2) - engine signal, weight 0.45, confidence 0.60
- YARA: MalwareAnalyser built-in flagged Windows_Injection_Api_Combo (rule
Windows_Injection_Api_Combo) - engine signal, weight 0.35, confidence 0.70 - Dropped 2 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
35223 behavior events · 3 ATT&CK techniques · 9 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- sonic4me.com
- imageshells.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- edge.microsoft.com
- www.update.microsoft.com
Dropped files
- C:\ProgramData\Local Settings\Temp\mswonkev.scr -
54fdbf276fa382c552baee6d08bcd48b16977b0741e42a841ee82a1a3c1e2a4f - C:\Users\analyst\AppData\Local\Temp\BYMYK.bat -
951c53b3bb0e4558c961bd7915656d6f526332088ff5085fd72882cf08ad8890 - 381f4b8cdcd2e2b17fe28f3a879e7b389871c71c11e9dd2bfe8f75e7a81f7ed2 -
381f4b8cdcd2e2b17fe28f3a879e7b389871c71c11e9dd2bfe8f75e7a81f7ed2 - 066eeca0a06265ae9af0b0fab239bc1dedbf993a3627afcb2acce8ad5c8eb185 -
066eeca0a06265ae9af0b0fab239bc1dedbf993a3627afcb2acce8ad5c8eb185 - 867ab031c3242f54cf72e8db797f3aa487f5f73e9dcdd5b5f4abfa6a68cf7349 -
867ab031c3242f54cf72e8db797f3aa487f5f73e9dcdd5b5f4abfa6a68cf7349 - 3e1d56d6abf0d0553dbf4cea2f6fb0b11a8c65cdacd724be7704428322614e9f -
3e1d56d6abf0d0553dbf4cea2f6fb0b11a8c65cdacd724be7704428322614e9f - e238caa6065101a8e8287804c4029e27a889aeb866e62cb9c93b3b8b52a4fa19 -
e238caa6065101a8e8287804c4029e27a889aeb866e62cb9c93b3b8b52a4fa19 - df5f9be2ccc4267ef4acdc8b914d28481c4954c844b2ffa27813b8c564ff4543 -
df5f9be2ccc4267ef4acdc8b914d28481c4954c844b2ffa27813b8c564ff4543 - fd03ae8cfe671f37f8b96270d5f897cd043ad0d65dda357975cc2dfda6466058 -
fd03ae8cfe671f37f8b96270d5f897cd043ad0d65dda357975cc2dfda6466058
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://sonic4me.com/login/image.php
- http://imageshells.com/login/image.php
Embedded domains
- sonic4me.com
- imageshells.com
Embedded IP addresses
- 4.150.223.99
- 52.230.60.54
- 4.230.171.124
- 172.66.2.5
- 128.85.102.70
- 184.105.192.2
- 172.178.240.162
- 4.247.188.233
- 72.154.7.102
- 52.148.114.188
- 52.110.12.4
- 52.110.12.50
File paths
- C:\Program
- C:\Windows\SysWOW64\msvbvm60.dll\3
More Gamarue samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report