MALICIOUS — 296fa7d869009b88b0638c32a8255ac5bf0c12b6f3863ece179f2c1a0a074787
MALICIOUS — 296fa7d869009b88b0638c32a8255ac5bf0c12b6f3863ece179f2c1a0a074787 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Barys family. 6 of 56 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
296fa7d869009b88b0638c32a8255ac5bf0c12b6f3863ece179f2c1a0a074787 - SHA-1:
36c890aa2529d56ee6620137ed311e384f95176c - MD5:
1916262810e385582c3bc92a0e3ef762 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
3072:GQ0bwSP9c7Vsl1SLZWF0V32AJ82QVOd2tWaPu6:YbP18Vsl1SLt2k82TIE - TLSH:
T10C3FAE87D7ECAE33C4BEBD1E153A402F32CE5A5F5875191C223E707294222A7977112A - Submitted as: 296fa7d869009b88b0638c32a8255ac5bf0c12b6f3863ece179f2c1a0a074787
- File type: pe · Size: 162816 bytes
- Verdict: malicious (100/100) · Family: Barys
Detections (6 of 56 engines)
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Emsisoft (Emergency Kit): Gen:Variant.Barys.55525
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 17 weighted signals:
- 3 behavioral detection(s) across 3 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.66, confidence 0.90 - Memory forensics: 1 finding(s) attributed to the sample across 1 technique(s), e.g. RWX/private injected region in chroom.exe (pid 5912) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Barys.55525 (rule
Gen:Variant.Barys.55525) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win32.Generic (rule
HEUR:Trojan.Win32.Generic) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Contacted 17 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082 - dynamic signal, weight 0.40, confidence 0.75
- Extracted Njrat config (0 C2) - engine signal, weight 0.45, confidence 0.60
- Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged Microsoft Linker (rule
Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
28084 behavior events · 3 ATT&CK techniques · 16 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- hugydttuyiu.ddns.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
Dropped files
- c:\windows\microsoft.net\framework64\v2.0.50727\config\enterprisesec.config.cch -
8ec1a47436dca98fc8c94079c32f893c7cf5cb72abc188fd6bf3757fc8d5ac79 - 13e52fa0925953e2e68e319791ba1a64483953ecbac5bbd5cab6b40189e0c007 -
13e52fa0925953e2e68e319791ba1a64483953ecbac5bbd5cab6b40189e0c007 - 6277f56e90d8548254f389a6e71f2287749b8dfb95d7962e3766f7e942885326 -
6277f56e90d8548254f389a6e71f2287749b8dfb95d7962e3766f7e942885326 - 293b0f62e7567e44593c0d8280db269e712383366f190d6bd4a14459f9a8e469 -
293b0f62e7567e44593c0d8280db269e712383366f190d6bd4a14459f9a8e469 - decf245c8967d1d071b470388d48ea0b1053ebf0cfb621921d83e00cf28ab1e0 -
decf245c8967d1d071b470388d48ea0b1053ebf0cfb621921d83e00cf28ab1e0 - 92ada9b1fc916a6a3b00b28c282472d7b3894bfea0d543d241a4e146565d236b -
92ada9b1fc916a6a3b00b28c282472d7b3894bfea0d543d241a4e146565d236b - 73be6682423c64177463c781372d17819c74082ad4a06143ff6520dfe84ce286 -
73be6682423c64177463c781372d17819c74082ad4a06143ff6520dfe84ce286 - b7bbbd9c34daf533dfd7aa9488a615547ec8fa80189c970bacb50a43af3c5511 -
b7bbbd9c34daf533dfd7aa9488a615547ec8fa80189c970bacb50a43af3c5511 - b9c92b16ffccc7ad96f8e8dd4f8f0392c1400d3f744f0a7d77738323c86a1d19 -
b9c92b16ffccc7ad96f8e8dd4f8f0392c1400d3f744f0a7d77738323c86a1d19 - fe297afe6b87ecede64d5352a2316c49e987be5c8f54106c4339d3b032f7229e -
fe297afe6b87ecede64d5352a2316c49e987be5c8f54106c4339d3b032f7229e - e8ef22658df2347701502665e96f3c9dbb97f6cdeb7fd44b080d03db1be10f1f -
e8ef22658df2347701502665e96f3c9dbb97f6cdeb7fd44b080d03db1be10f1f - ad8406d863c7803e9fe92ea3427b3d936f3858371c8c1d83f6157990fabe2ac9 -
ad8406d863c7803e9fe92ea3427b3d936f3858371c8c1d83f6157990fabe2ac9 - e57aff0f489bebd154dac3f4dcca53021ded061638290c7b80ff5eed46712575 -
e57aff0f489bebd154dac3f4dcca53021ded061638290c7b80ff5eed46712575 - af1836675a0f0fc2cc51b391c5b97dff2b077656bd74d3bcdff6a7bf45fd899a -
af1836675a0f0fc2cc51b391c5b97dff2b077656bd74d3bcdff6a7bf45fd899a - 78a53f4f5d1d0e47b924eb0ea734a2039927929a93cfd922092e7e7a5557664f -
78a53f4f5d1d0e47b924eb0ea734a2039927929a93cfd922092e7e7a5557664f
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- hugydttuyiu.ddns.net
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 4.150.223.96
- 52.230.59.222
- 52.123.252.226
- 4.230.171.124
- 74.178.240.51
- 57.155.104.224
- 52.182.141.63
- 135.233.95.144
- 40.79.141.154
- 4.144.132.223
- 92.223.78.30
- 20.42.179.192
- 52.178.17.233
- 72.145.35.100
- 52.148.114.188
- 52.110.12.45
More Barys samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report