MALICIOUS — 25e1577ccee5bc33d5273e5d4aec9442e31d7158e496cc11189b4790e25ded5c.py
MALICIOUS — 25e1577ccee5bc33d5273e5d4aec9442e31d7158e496cc11189b4790e25ded5c.py is a shell sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (76/100), attributed to the 6945C0D8 family. 5 of 53 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
25e1577ccee5bc33d5273e5d4aec9442e31d7158e496cc11189b4790e25ded5c - SHA-1:
502ab4ca49761addf087a248d57866fd301468d4 - MD5:
1b2b917354879a60a52056f9994a142f - ssdeep:
384:t9Zfz/V77fOxi7t06OjleSnE+SpaIMTzkYh7eMye2p3cyboYdCPJEM+nj6axHODr:tXz/VeeTZaH7eMyXwJEMaZl7o - TLSH:
T1B834B70F554D28FF1791085CAC580FBD1626C9CAE19838E26FC977842872E91F43A5BE - Submitted as: 25e1577ccee5bc33d5273e5d4aec9442e31d7158e496cc11189b4790e25ded5c.py
- File type: shell · Size: 52834 bytes
- Verdict: malicious (76/100) · Family: 6945C0D8
Detections (5 of 53 engines)
- capa (capabilities): capability:credential-access
- YARA: MalwareAnalyser community pack: TL_Ransomware_Note_Markers
- YARA: Yara-Rules community: YR_AntiVM_Sandbox
- Emsisoft (Emergency Kit): Generic.PY.STEALER.B.6945C0D8
- Kaspersky (KVRT): HEUR:Trojan-PSW.Multi.Disco.gen
MITRE ATT&CK
Why this verdict
The malicious score of 76/100 is the fusion of 5 weighted signals:
- access stored credentials (rule
access stored credentials) - capa signal, weight 0.50, confidence 0.80 - YARA: MalwareAnalyser community pack flagged TL_Ransomware_Note_Markers (rule
TL_Ransomware_Note_Markers) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiVM_Sandbox (rule
YR_AntiVM_Sandbox) - engine signal, weight 0.35, confidence 0.70 - query domain / anti-analysis (rule
query domain / anti-analysis) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: https://t.me/CirqueiraDev, https://ipwhois.app/json/, https://discord.com/api/v9/users/@me - static signal, weight 0.35, confidence 0.60
Dynamic analysis (linux)
865 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- ntp.ubuntu.com
- _dosvc._tcp.local
- desktop-hsgcbep
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- 10.240.0.1
- ff02::1:3
- 224.0.0.252
- ff02::fb
- 224.0.0.251
- 10.240.0.255
- 239.255.255.250
- 20.42.179.204 US · Moses Lake · AS8075 Microsoft Corporation
- 255.255.255.255
- 40.84.97.4 US · Boydton · AS8075 Microsoft Corporation
- 185.125.190.56
- ff02::16
- 57.155.104.224 SG · Singapore · AS8075 Microsoft Limited UK
- ff02::1:ff12:3456
- 185.125.190.58
Embedded URLs
- https://t.me/CirqueiraDev
- https://www.google.com
- https://ipwhois.app/json/
- https://discord.com/api/v9/users/@me
- https://discord.com/api/v8/users/@me
- https://www.roblox.com/mobileapi/userinfo
- https://api.minecraftservices.com/minecraft/profile
- https://discord.com/api/webhooks/1508443663879901194/MA8K81_jhkzTnMnheyGJr0WFgNxb_r12IcLBwpQQNlcHu6hK8wmg9zeSl11sGhamqaLr
- https://github.com/CirqueiraDev
- https://upload.gofile.io/uploadFile
Embedded domains
- t.me
- proc.info
- www.google.com
- ipwhois.app
- discord.com
- roblox.com
- profile.name
- www.roblox.com
- item.name
- path.name
- api.minecraftservices.com
- ssfn.name
- github.com
- upload.gofile.io
Embedded IP addresses
- 20.42.179.204
- 40.84.97.4
- 57.155.104.224
- 74.179.77.204
- 74.178.232.29
- 48.211.4.16
- 72.153.5.138
More 6945C0D8 samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report