MALICIOUS — 27ea404fa6494664b3544f1cf28e94d8a8895556265946736da56575f9b844f0
MALICIOUS — 27ea404fa6494664b3544f1cf28e94d8a8895556265946736da56575f9b844f0 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the 43DF2D29 family. 5 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
27ea404fa6494664b3544f1cf28e94d8a8895556265946736da56575f9b844f0 - SHA-1:
e6f235b97dba4891fc2fe3f70f2f375e31d107af - MD5:
0e1ccf2ff0996ffac0bbadfcf33a5356 - imphash:
a64e048b98d051ae6e6b6334f77c95d3 - ssdeep:
3072:rrCAEJgaw+0y4uBw0TLwJLtQg6T2TTpppuBiCMyjSnbwx:rJil10yLBwLKT2TTpppHCMyj8bw - TLSH:
T1FB3F4BD21A959FE1C862F97D70F9989E8261F2659EDFC900673D61CA408BB4B7C0012F - Submitted as: 27ea404fa6494664b3544f1cf28e94d8a8895556265946736da56575f9b844f0
- File type: pe · Size: 156672 bytes
- Verdict: malicious (99/100) · Family: 43DF2D29
Detections (5 of 56 engines)
- ClamAV (daily): Win.Trojan.Crypted-31
- Microsoft Defender: Backdoor:Win32/Berbew!pz
- Emsisoft (Emergency Kit): Generic.Dacic.1.Backdoor.Hangup.A.43DF2D29
- Trellix Stinger (McAfee): Trojan-FRJE!EE5D5FEA5990
- Kaspersky (KVRT): Trojan-Proxy.Win32.Qukart.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypted-31 (rule
Win.Trojan.Crypted-31) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Backdoor:Win32/Berbew!pz (rule
Backdoor:Win32/Berbew!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Generic.Dacic.1.Backdoor.Hangup.A.43DF2D29 (rule
Generic.Dacic.1.Backdoor.Hangup.A.43DF2D29) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Trojan-FRJE!EE5D5FEA5990 (rule
Trojan-FRJE!EE5D5FEA5990) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-Proxy.Win32.Qukart.gen (rule
Trojan-Proxy.Win32.Qukart.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 2 external host(s) and 17 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Dropped 118 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
3783 behavior events · 1 ATT&CK techniques · 118 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- www.bing.com
- assets.msn.com
Dropped files
- C:\Windows\System32\Phckpp32.exe -
44908d2ed93c4fba3a80dd0955dfbc8ff7b73de97437a91075b3b1699002058f - C:\Windows\System32\Gehhijai.dll -
366b5f19bdfb273c746432d2c4b39a7f14581f2dccb62c40ea78800894766bd5 - C:\Windows\System32\Gfdabpbl.dll -
81d97098892c80800a5b914d049d0aa507fef34dbbd35298757828b3dd5a1019 - C:\Windows\System32\Ggnopfgo.dll -
3f908953003b8c8a7ddbb574d491121a8cc9e73f4ee8bdff325663bc780bc830 - C:\Windows\System32\Clnieeec.exe -
df9da0950dd8169c0c4ece4e524c1ff420ee40a74e809d26b43aaca7639df030 - C:\Windows\System32\Lhfjffce.exe -
e8cff9c0af95d4fd349d0d8b5199b11adaaa75a149dfb82cee2f8146ba68afa8 - C:\Windows\System32\Lijacg32.dll -
d8f0aa91adfa366eea1a532b3459df3139539b288911adf5927787b9b2d632f1 - C:\Windows\System32\Dfcfhgan.exe -
73f6b51335149a0286b68b5554343ebc67a18bc69361569e4fd5cd12e771e74a - C:\Windows\System32\Ecknibpg.exe -
ff85f72280769712932fca01ab9eac6ace9bc4c02605cdf94075d58308d97f7f - C:\Windows\System32\Eljgqejf.dll -
9697745bad3489413e577cfbdbbfe23e68c15c075da5b3c5e5c06c77ab0fc588 - C:\Windows\System32\Ipodco32.dll -
84493279371875b7c3839666ebf7cedf66054c55dcdbfedee0388e584e4e21d9 - C:\Windows\System32\Cahjnd32.dll -
c77ffb7a699a1853d5b124555ccc700e57d8a1ed6322fb046034aab733f8d88b - C:\Windows\System32\Kapkcg32.exe -
9ef2ee46912e6e61269dbc31c10d05bdae071a24e33f198202216ee4f3e574cf - C:\Windows\System32\Gjmnkpgd.dll -
cf5b9a66004ffe43964b06c687b659623b40856a6f17f3016ab85cc778b4d237 - C:\Windows\System32\Bciakdpc.exe -
0d9738471be6d4b75e1d7cca0f05b25b505b68af53aa44fa36b01bcb5045ee73
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 4.150.223.112
- 20.247.184.197
- 4.230.171.124
- 172.64.154.167
- 52.110.12.15
- 52.110.12.46
- 20.42.179.204
- 52.168.117.175
- 4.150.223.109
- 172.178.240.161
- 52.148.114.188
- 52.110.12.54
- 72.145.35.100
- 52.110.12.38
More 43DF2D29 samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report