MALICIOUS — 1d3360a2c60c1596c32b8377e21bd7d42c2723fd2e19e710db06b11e473eebbc
MALICIOUS — 1d3360a2c60c1596c32b8377e21bd7d42c2723fd2e19e710db06b11e473eebbc is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Vindor family. 6 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1d3360a2c60c1596c32b8377e21bd7d42c2723fd2e19e710db06b11e473eebbc - SHA-1:
5b25b112ee5a89053bfbd2202e9a5a9a7b0d38bb - MD5:
cc57af24ae0408b7b41144de6e3a44a7 - imphash:
1bc18422ce3ff8b1f4b00d97efa67a6b - ssdeep:
24576:cg0ynSHEoJdXN0BN2qnw4a+edxoBrLdggwCqnstLyUktHIiLy:lRoJdXN0BMOwLloBrughqnstLet3Ly - TLSH:
T1635CC5C81150DB01EAF45FAD7D37265D2161B0B437BF5828AA82603949E7E7FF8A085C - Submitted as: 1d3360a2c60c1596c32b8377e21bd7d42c2723fd2e19e710db06b11e473eebbc
- File type: pe · Size: 2393823 bytes
- Verdict: malicious (98/100) · Family: Vindor
Detections (6 of 55 engines)
- ClamAV (daily): Win.Worm.Vindor-9886047-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Microsoft Defender: Trojan:Win32/Vindor!pz
- Kaspersky (KVRT): Worm.Win32.AutoRun.vx
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Win.Worm.Vindor-9886047-0 (rule
Win.Worm.Vindor-9886047-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - Contacted 20 external host(s) at runtime (16 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://stackoverflow.com/a/15281070/18475, http://stanislavs.org/stopping-command-line-applications-programatically-with-ctrl-c-events-from-net/, https://services.acrobat.com - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Extracted generic config (2 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- settings-win.data.microsoft.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
Embedded URLs
- http://msdn.microsoft.com/en-us/library/windows/desktop/ms681388
- http://msdn.microsoft.com/en-us/library/windows/desktop/ms681383
- https://gist.github.com/jvshahid/6fb2f91fa7fb1db23599
- http://stackoverflow.com/a/15281070/18475
- http://stanislavs.org/stopping-command-line-applications-programatically-with-ctrl-c-events-from-net/
- http://www.w3.org/2001/XMLSchema-instance
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-cs-g1.crl05
- http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
- http://www.digicert.com/ssl-cps-repository.htm0
- https://services.acrobat.com
- https://services.acrobat.com/account/wsapi/
- https://v2.services.acrobat.com
- https://tob.acrobat.com/TOB/
- https://api.share.acrobat.com
- https://api.share.acrobat.com/webservices/api/v1/
- https://createpdf.acrobat.com
- https://api2.acrobat.com/webservices
- https://v2.services.acrobat.com/
- https://api2.acrobat.com
- http://ns.adobe.com/Acrobat/RSS/Inbox/feedUI
- http://ns.adobe.com/Acrobat/RSS/Inbox/icon
- http://ns.adobe.com/Acrobat/RSS/Reviews/deadline
- http://ns.adobe.com/synchronizer/ttl
- http://ns.adobe.com/synchronizer/dependency
Embedded domains
- msdn.microsoft.com
- gist.github.com
- stackoverflow.com
- stanislavs.org
- www.w3.org
- shim.app
- shimgenerator.app
- cacerts.digicert.com
- crl4.digicert.com
- crl3.digicert.com
- www.digicert.com
- u.jp
- services.acrobat.com
- v2.services.acrobat.com
- tob.acrobat.com
- api.share.acrobat.com
- createpdf.acrobat.com
- api2.acrobat.com
- ns.adobe.com
- purl.org
- crl.thawte.com
- ts-aia.ws.symantec.com
- ts-crl.ws.symantec.com
- crl.verisign.com
- www.verisign.com
Embedded IP addresses
- 0.8.2.0
- 20.42.179.192
- 20.42.65.88
- 4.144.132.114
- 135.232.92.137
- 4.230.171.124
- 4.150.223.113
- 135.232.92.97
- 40.84.85.40
- 20.112.250.133
- 52.123.129.14
- 52.123.128.14
- 203.26.79.13
- 74.178.76.44
- 52.110.12.50
- 52.110.12.49
- 135.233.45.221
- 52.148.114.188
- 52.110.12.26
- 52.110.12.42
- 72.154.7.109
File paths
- c:\borrar\EmptyDll\Release\EmptyDll.pdb
- X:\:x:
- X:\:`:d:h:l:p:t:
- X:\:`:d:h:l:p:t:x:
- X:\:l:p:
- H:\:d:l:
- T:\:d:l:t:
- T:\:h:
- d:\dbs\el\oc\target\x86\ship\postc2r\x-none\olicenseheartbeat.pdb
- P:\:`:l:p:
- H:\:d:h:p:
More Vindor samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report