SUSPICIOUS — 25245350be0d0b3277bfa71ea274a0a0dee3e884ee6c1a9b6e477465b49edbc0
SUSPICIOUS — 25245350be0d0b3277bfa71ea274a0a0dee3e884ee6c1a9b6e477465b49edbc0 is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 4 of 55 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
25245350be0d0b3277bfa71ea274a0a0dee3e884ee6c1a9b6e477465b49edbc0 - SHA-1:
0a83b5c2fa55f9f40d5543c85f2b23bdb7cff94f - MD5:
ea3fe66f38d75dec82b3c3686e67b2cb - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
3072:COegU9ecFsPq2RKJKYwzmPFoNyXDeUZxMfDMpup:CT3D2oJK7mP2y62xML - TLSH:
T1ED3A02C2C6BCB31BF1F0E4B401648A5D3C4E81A896FA95ABDA5421393EBD5336C70275 - Submitted as: 25245350be0d0b3277bfa71ea274a0a0dee3e884ee6c1a9b6e477465b49edbc0
- File type: pe · Size: 98816 bytes
- Verdict: suspicious (54/100)
Detections (4 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- Microsoft Defender: Trojan:MSIL/Bladabindi.DB!MTB
- Emsisoft (Emergency Kit): Gen:Heur.Mint.Packer.8
- Kaspersky (KVRT): HEUR:Backdoor.MSIL.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 54/100 is the fusion of 8 weighted signals:
- 4 behavioral detection(s) across 4 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.69, confidence 0.90 - 2 IDS alert(s): ThreatLens no-ip dynamic DNS C2 - network signal, weight 0.50, confidence 0.80
- Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 29 external host(s) and 21 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082 - dynamic signal, weight 0.40, confidence 0.75
- Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
15064 behavior events · 3 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- abodxo.no-ip.org
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- msedge.api.cdp.microsoft.com
Dropped files
- 68c87e4fad5afe52c9150ff031803d3d893bfe88f9165f26a524deed3c68db6f -
68c87e4fad5afe52c9150ff031803d3d893bfe88f9165f26a524deed3c68db6f - 45ae84e98c33577794d10439844fabc78fed454cc6f0b9d17dfe0705532e8524 -
45ae84e98c33577794d10439844fabc78fed454cc6f0b9d17dfe0705532e8524 - b5f7c59d2a17128a6c150ae7d5a28a541858aeb497a0a4cbb87314cd4b0cbc35 -
b5f7c59d2a17128a6c150ae7d5a28a541858aeb497a0a4cbb87314cd4b0cbc35
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9?P1=1787949348&P2=404&P3=2&P4=H7Ff16yMYr61zfWRfzgyRv%2bCSfPllvmX2NLOvOHMMwLd8T44LkDmq0sj46GoZZ66e2jnO2gC9QbpyXdYeldyRw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787949362&P2=404&P3=2&P4=OuMlKYSckZvVZgowSdbCBOtkikOYc2eswxvkXMU6v9LGGVA246%2bGHprwI8Fdh1WxdyqqI7aQVJW2zsJh8bHCgg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- abodxo.no-ip.org
Embedded IP addresses
- 52.168.112.67
- 52.123.252.236
- 52.123.252.197
- 4.247.188.224
- 4.230.171.124
- 52.230.60.54
- 74.178.240.61
- 52.123.252.248
- 135.232.92.34
- 20.50.201.204
- 74.178.240.51
- 74.179.77.204
- 20.236.44.162
- 52.123.129.14
- 52.123.128.14
- 52.123.252.232
- 203.26.79.13
- 172.178.240.162
- 4.150.223.109
- 20.42.73.26
- 204.95.99.26
- 52.148.114.188
- 52.110.12.21
- 52.110.12.10
- 72.154.7.97
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report