MALICIOUS — 1d4fd2fb71eae1f76e973fb20456894d5aa87f0a7674a886e85f24126c21ca02
MALICIOUS — 1d4fd2fb71eae1f76e973fb20456894d5aa87f0a7674a886e85f24126c21ca02 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the CryptInject family. 2 of 25 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
1d4fd2fb71eae1f76e973fb20456894d5aa87f0a7674a886e85f24126c21ca02 - SHA-1:
79b2c0d30290e66868e0ea33eb160a4059164817 - MD5:
676668a7ec1843a30da60f335629a3eb - imphash:
a9192bab5c7c795c7488b69a1853f9c2 - ssdeep:
192:G49HsxwSUFx+UEqzerwdIpJNY8uMp7QPJVNMxUPAUBlxPVGcm:GBXUFh1yvN/uMmxDMm - TLSH:
T1132D83C963592720DCF0F854ED046D2C31D39AA462763BDC6406D43FB4EAAF305798A9 - Submitted as: 1d4fd2fb71eae1f76e973fb20456894d5aa87f0a7674a886e85f24126c21ca02
- File type: pe · Size: 28672 bytes
- Verdict: malicious (97/100) · Family: CryptInject
Detections (2 of 25 engines)
- Microsoft Defender: Trojan:Win32/CryptInject!pz
- Kaspersky (KVRT): Virus.Win32.Lamer.ks
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 9 weighted signals:
- Memory forensics: 5 finding(s), e.g. RWX/private injected region in svchost.exe (pid 932) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Win32/CryptInject!pz (rule
Trojan:Win32/CryptInject!pz) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 84 external host(s) at runtime (21 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497, T1497.001, T1622, T1082 - dynamic signal, weight 0.40, confidence 0.75
- persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://www.pinkworld.com, http://www.youporn.com, http://www.redtube.com - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
41589 behavior events · 2 ATT&CK techniques · 27 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- www.freeav.com
- www.avira.com
- script.crazyegg.com
- www.webassetscdn.com
- nexus.ensighten.com
- assets.adobedtm.com
- t.nc0.co
- doh.cq0.co
- s.go-mpulse.net
- widget.trustpilot.com
- data.privacy.ensighten.com
- dpm.demdex.net
- www.nortonlifelock.com
- symantec.demdex.net
- symantec.tt.omtrdc.net
- rmbyy5ra.avira.com
- mhubc.avira.com
- oms.avira.com
Dropped files
- /opt/CAPEv2/storage/analyses/8768/files/a843860d23f9805c96ec304672996b5ac78544fa67da72fc58a3963a6bb42740 -
a843860d23f9805c96ec304672996b5ac78544fa67da72fc58a3963a6bb42740 - /opt/CAPEv2/storage/analyses/8768/files/bd23a22e984eb61a54d6feac6525edb8f7ec551abd04236babcb7557cc158011 -
bd23a22e984eb61a54d6feac6525edb8f7ec551abd04236babcb7557cc158011 - /opt/CAPEv2/storage/analyses/8768/files/023a5926ed5a51e186f68118a97e9f47fc2e14e9e5d2227e45c84cce52535fc8 -
023a5926ed5a51e186f68118a97e9f47fc2e14e9e5d2227e45c84cce52535fc8 - /opt/CAPEv2/storage/analyses/8768/files/720d34fd99d3c12d8fce3689eecd384549d92e9a9e79531494c4a874fdbae098 -
720d34fd99d3c12d8fce3689eecd384549d92e9a9e79531494c4a874fdbae098 - /opt/CAPEv2/storage/analyses/8768/files/a214100a212bd60f5500f8f4c746c32cd9972e290836c1437f73089fa35cf814 -
a214100a212bd60f5500f8f4c746c32cd9972e290836c1437f73089fa35cf814 - /opt/CAPEv2/storage/analyses/8768/files/82cf191d43e893cf4bb42e6a721e8e6dc338c4d8ad9bf426548b9ac9f4ecd182 -
82cf191d43e893cf4bb42e6a721e8e6dc338c4d8ad9bf426548b9ac9f4ecd182 - /opt/CAPEv2/storage/analyses/8768/files/8a81c3a2bcc062622547ffe917301bb7f8712ef36ac07576987baaa974b393ad -
8a81c3a2bcc062622547ffe917301bb7f8712ef36ac07576987baaa974b393ad - /opt/CAPEv2/storage/analyses/8768/files/b94e6b5b7b7e884705d66ac836c833eefc4c6c5d47e51d843a1b26c199727489 -
b94e6b5b7b7e884705d66ac836c833eefc4c6c5d47e51d843a1b26c199727489 - /opt/CAPEv2/storage/analyses/8768/files/8edf5f6e8842c9e35b2ad855c6c13328f2c51b4f107137e1dab7a615cb3ae96b -
8edf5f6e8842c9e35b2ad855c6c13328f2c51b4f107137e1dab7a615cb3ae96b - /opt/CAPEv2/storage/analyses/8768/files/b2378e7c05c098e3ee682e87f10ff3a1444728ea1a979f434d3437a063a2bb9e -
b2378e7c05c098e3ee682e87f10ff3a1444728ea1a979f434d3437a063a2bb9e - /opt/CAPEv2/storage/analyses/8768/files/3cdfa1a4bbb62611381e394a62af61f5ea806d5e5f091392b12f135cdcbdc965 -
3cdfa1a4bbb62611381e394a62af61f5ea806d5e5f091392b12f135cdcbdc965 - /opt/CAPEv2/storage/analyses/8768/files/b90b617577ff0545b4e2fe2faaed7ec62c640fcb1b0cf57df8a917009a3df7a4 -
b90b617577ff0545b4e2fe2faaed7ec62c640fcb1b0cf57df8a917009a3df7a4 - /opt/CAPEv2/storage/analyses/8768/files/f30ef286e5ae37caef14c7a9cfdf48698cd2b39532957a827ab4c0545b214c94 -
f30ef286e5ae37caef14c7a9cfdf48698cd2b39532957a827ab4c0545b214c94 - /opt/CAPEv2/storage/analyses/8768/files/c4575110abacdbc69bb07e9d4cbdf2d3b61d6b77e322a4e524aad7727dba82ea -
c4575110abacdbc69bb07e9d4cbdf2d3b61d6b77e322a4e524aad7727dba82ea - /opt/CAPEv2/storage/analyses/8768/files/b6fdada23d137544266af8d170cccf7e8ffee10e704d9b08892cc79de10237c8 -
b6fdada23d137544266af8d170cccf7e8ffee10e704d9b08892cc79de10237c8
Embedded URLs
- http://www.pinkworld.com
- http://www.youporn.com
- http://www.redtube.com
- http://www.assparade.com/
- http://www.freeav.com/
- http://www.antispyware.com/
- http://www.antivirus.com/
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786359798&P2=404&P3=2&P4=ATcL29TAp7ogL9OFr7%2b1Dqq7qxjmq%2fT0OkPeyN91qEB%2fuiOeyemKQTLqhRtphgxOzD75CVLVACTKXpRJWqK27Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786359869&P2=404&P3=2&P4=Qy1MXpYP9Ad8BJ39cGzn9idHXq7GDkh5vPtlwWHBnSet4Npct6NwpAuJE634hT4bOi4Y%2brZkLjXaKf7bgG3qlQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- www.pinkworld.com
- www.youporn.com
- www.redtube.com
- www.assparade.com
- www.freeav.com
- www.antispyware.com
- www.antivirus.com
- www.avira.com
- script.crazyegg.com
- nexus.ensighten.com
- assets.adobedtm.com
- www.webassetscdn.com
- t.nc0.co
- doh.cq0.co
- s.go-mpulse.net
- widget.trustpilot.com
- data.privacy.ensighten.com
- dpm.demdex.net
- symantec.demdex.net
- symantec.tt.omtrdc.net
- www.nortonlifelock.com
- rmbyy5ra.avira.com
- mhubc.avira.com
- oms.avira.com
- getrockerbox.com
Embedded IP addresses
- 4.150.223.98
- 4.144.132.223
- 85.210.193.152
- 4.230.171.124
- 135.232.92.137
- 57.155.104.224
- 4.150.223.115
- 74.178.76.54
- 135.233.95.144
- 4.150.223.99
- 135.233.45.223
- 4.150.223.100
- 20.42.73.26
- 135.233.95.80
- 203.26.79.13
- 52.123.252.245
- 52.58.28.12
- 20.11.121.11
- 20.190.122.23
- 135.234.160.246
- 142.250.195.232
- 54.253.247.127
- 108.158.32.110
- 13.55.4.2
- 3.175.115.19
File paths
- C:\!
More CryptInject samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report