MALICIOUS — 2245329eb19c9c600f14588aae186ecc886945eb1ad09ca8e79c825dc2a54afa
MALICIOUS — 2245329eb19c9c600f14588aae186ecc886945eb1ad09ca8e79c825dc2a54afa is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (82/100), attributed to the DangerousObject family. 5 of 55 detection engines flagged it.
Identification
- SHA-256:
2245329eb19c9c600f14588aae186ecc886945eb1ad09ca8e79c825dc2a54afa - SHA-1:
0dc80ca4bb241aed06b1f59352e9a6714234f60f - MD5:
02e2c17c72b2d6ce318b9f1520604b3b - imphash:
bd87fa86379dfe3191af6f4deaf9d10e - ssdeep:
196608:pr2EV30u5GF5eY5PXZWRDqHI/I1qwn3AW9z:cbJFZXZBHf1Vn3Pz - TLSH:
T18F6933823AEE86FAD6EBE1A98CCA310D551563FDDCDE9016D91BD2D208CD41780C7827 - Submitted as: 2245329eb19c9c600f14588aae186ecc886945eb1ad09ca8e79c825dc2a54afa
- File type: pe · Size: 8195194 bytes
- Verdict: malicious (82/100) · Family: DangerousObject
Detections (5 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): Themida/VMProtect
- Detect It Easy (packer/type): DIE:Turbo Linker
- Microsoft Defender: Spyware:Win32/Casbaneiro!mclg
- Emsisoft (Emergency Kit): Gen:Variant.Bulz.819677
- Kaspersky (KVRT): UDS:DangerousObject.Multi.Generic
Why this verdict
The malicious score of 82/100 is the fusion of 5 weighted signals:
- Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - Contacted 22 external host(s) at runtime (16 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082, T1497 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Themida/VMProtect, high-entropy-sections: , , , , , , , ,.boot, Turbo Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
244 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- settings-win.data.microsoft.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787867511&P2=404&P3=2&P4=hHtnh%2bDMXEoGaHLj6ct1u%2bBHBsC9Qq9e0cxh2Ctxrn1TBMw00NZoxInHF%2b6Kll%2bHlHVr9zGmmsraWtO7XGzisA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- 8.jp
- qj.pl
- f.au
Embedded IP addresses
- 57.154.63.210
- 20.184.175.9
- 4.230.171.124
- 4.144.132.223
- 20.42.179.192
- 74.178.76.128
- 74.179.77.164
- 52.182.141.63
- 20.76.201.171
- 52.123.129.14
- 20.52.64.200
- 52.123.252.215
- 52.110.12.30
- 52.110.12.54
- 203.26.79.13
- 135.234.160.244
- 74.179.71.159
- 52.148.114.188
- 92.223.78.30
- 52.110.12.52
- 52.110.12.26
- 72.153.5.138
File paths
- Z:\Qz-
- X:\M+
- x:\;dt
More DangerousObject samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report