MALICIOUS — 1d6839c5cc1c611f778fbadea1dea6a2b1733b5e8d2dbc8f550a7a0d6c609334
MALICIOUS — 1d6839c5cc1c611f778fbadea1dea6a2b1733b5e8d2dbc8f550a7a0d6c609334 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the Genie8DN family. 3 of 56 detection engines flagged it.
Identification
- SHA-256:
1d6839c5cc1c611f778fbadea1dea6a2b1733b5e8d2dbc8f550a7a0d6c609334 - SHA-1:
ec508e31913dc80cfb9998252953fac23671b1c6 - MD5:
d49b4a369ea96e884c15c12ac686d2d7 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
192:zkM3nZSWSPmVrnlYJLLLTTWFnP/Czf+uD:zkM1SPm2PLT1j+y - TLSH:
T17E1FC7CE083D6A46E775FE275441D96E9492F8D62CB6050E025080B30EBA727E53B3CB - Submitted as: 1d6839c5cc1c611f778fbadea1dea6a2b1733b5e8d2dbc8f550a7a0d6c609334
- File type: pe · Size: 7680 bytes
- Verdict: malicious (93/100) · Family: Genie8DN
Detections (3 of 56 engines)
- Microsoft Defender: Trojan:MSIL/Strictor.AMCZ!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Genie8DN.142
- Kaspersky (KVRT): HEUR:Trojan.Win32.Agent.gen
Why this verdict
The malicious score of 93/100 is the fusion of 6 weighted signals:
- Microsoft Defender flagged Trojan:MSIL/Strictor.AMCZ!MTB (rule
Trojan:MSIL/Strictor.AMCZ!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Genie8DN.142 (rule
Gen:Variant.Genie8DN.142) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win32.Agent.gen (rule
HEUR:Trojan.Win32.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. RWX/private injected region in SppExtComObj.E (pid 5932) (rule
windows.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
2079 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- settings-win.data.microsoft.com
- aefd.nelreports.net
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Dropped files
- c7e36f8081fc50d6e86d665b2fc27a6498766827908bf7629ce4b6281c2f9623 -
c7e36f8081fc50d6e86d665b2fc27a6498766827908bf7629ce4b6281c2f9623
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- aefd.nelreports.net
Embedded IP addresses
- 4.150.223.108
- 4.144.132.114
- 52.123.252.247
- 4.230.171.124
- 4.247.188.224
- 52.110.12.32
- 52.110.12.31
More Genie8DN samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report