MALICIOUS — 575_Ransomware.Petya.bin
MALICIOUS — 575_Ransomware.Petya.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Filecoder family. 7 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
26b4699a7b9eeb16e76305d843d4ab05e94d43f3201436927e13b3ebafa90739 - SHA-1:
39b6d40906c7f7f080e6befa93324dddadcbd9fa - MD5:
af2379cc4d607a45ac44d62135fb7015 - imphash:
1a63922d5931d1bb8ca5188313f78eaa - ssdeep:
6144:DCyjXhd1mialK+qoNr8PxtZE6x5v+k6f:rjXhd8ZlKOrMZE6x5b6f - TLSH:
T154439CCDCD196706FAB087104F10ADBD50B6B4E5A2FD781E0983816E7ED644FBCA8099 - Submitted as: 575_Ransomware.Petya.bin
- File type: pe · Size: 230912 bytes
- Verdict: malicious (100/100) · Family: Filecoder
Detections (7 of 52 engines)
- ClamAV (daily): {MD5}bin.trojan.petya.9225.UNOFFICIAL
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Cyble Vision: Cyble Vision: Malicious
- Microsoft Defender: Ransom:Win32/Filecoder.DLK!MTB
- Emsisoft (Emergency Kit): Trojan.Ransomware.BM
- Trellix Stinger (McAfee): Generic trojan.jy
- Kaspersky (KVRT): Trojan-Ransom.Win32.Petr.a
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged {MD5}bin.trojan.petya.9225.UNOFFICIAL (rule
{MD5}bin.trojan.petya.9225.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Cyble Vision flagged Cyble Vision: Malicious (rule
Cyble Vision: Malicious) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Ransom:Win32/Filecoder.DLK!MTB (rule
Ransom:Win32/Filecoder.DLK!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Ransomware.BM (rule
Trojan.Ransomware.BM) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Generic trojan.jy (rule
Generic trojan.jy) - engine signal, weight 0.55, confidence 0.85 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
448 behavior events · 1 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- desktop-hsgcbep
- v10.events.data.microsoft.com
- config.edge.skype.com
- login.live.com
- settings-win.data.microsoft.com
- fd.api.iris.microsoft.com
- windows.msn.com
- licensing.mp.microsoft.com
- officeclient.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- sdx.microsoft.com
- nav.smartscreen.microsoft.com
- dns.msftncsi.com
- www.bing.com
- msedge.api.cdp.microsoft.com
- 192.168.122.106
- 224.0.0.252
- 192.168.122.255
Dropped files
- c17cac07059f6dc07e05bed49ef46988dc0f622aca17378897a00ec883405931 -
c17cac07059f6dc07e05bed49ef46988dc0f622aca17378897a00ec883405931 - 55ef76ce7e5309b665a62316d2ec2a15643c805e93a3b7865a3c08d2416ddee4 -
55ef76ce7e5309b665a62316d2ec2a15643c805e93a3b7865a3c08d2416ddee4
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
Embedded domains
- logging.cc
- schemas.microsoft.com
- inference.location.live.net
Registry keys
- HKLM\Software\Google\UpdateDev\
- HKCU\Software\Google\Update\ClientState\
- HKCU\Software\Google\Update\
- HKLM\Software\Google\Update\ClientState\
- HKLM\Software\Google\Update\
- HKLM\Software\Policies\Google\Update\
- HKLM\Software\Microsoft\Windows
- HKLM\Software\Google\Update\ClientStateMedium\
File paths
- T:\:d:l:t:
- X:\:`:d:h:
- X:\:d:x:
- P:\:`:d:h:l:p:t:x:
More Filecoder samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report