MALICIOUS — 2c3cc8e204d79fbb3ffc1b7fbe784c7cfb6453d07fb59478e784776f9d9187f9
MALICIOUS — 2c3cc8e204d79fbb3ffc1b7fbe784c7cfb6453d07fb59478e784776f9d9187f9 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Clipper family. 4 of 56 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2c3cc8e204d79fbb3ffc1b7fbe784c7cfb6453d07fb59478e784776f9d9187f9 - SHA-1:
9c1f75704e0bb5a9ce49aba2e510767385c221db - MD5:
44cea21bb9a8fc37325ff3405ca0aa9f - imphash:
0001abda4ac864e0bb45e4f20fa8db25 - ssdeep:
96:6AovbmfqD0CtlOvCRUCSs8vsOPHY62QybLRw:6NWqD0CtZRU31X4kiRw - TLSH:
T1321C5D69CE333790E68950A1B4C8F0FC13F324151EDA8FD5D172647A228D22B1597A1F - Submitted as: 2c3cc8e204d79fbb3ffc1b7fbe784c7cfb6453d07fb59478e784776f9d9187f9
- File type: pe · Size: 5632 bytes
- Verdict: malicious (92/100) · Family: Clipper
Detections (4 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:Win32/Tiggre!rfn
- Kaspersky (KVRT): HEUR:Trojan-Spy.Win32.Clipper.gen
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 8 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Tiggre!rfn (rule
Trojan:Win32/Tiggre!rfn) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan-Spy.Win32.Clipper.gen (rule
HEUR:Trojan-Spy.Win32.Clipper.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 24 external host(s) and 11 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1, Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
24762 behavior events · 1 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- 251.0.0.224.in-addr.arpa.
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 252.0.0.224.in-addr.arpa.
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- nexusrules.officeapps.live.com
- 150.109.171.150.in-addr.arpa.
- v20.events.data.microsoft.com
- 8.175.184.20.in-addr.arpa.
- v10.events.data.microsoft.com
- 2.175.184.20.in-addr.arpa.
- c.pki.goog
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- 195.25.217.172.in-addr.arpa.
Dropped files
- 3a6aa72b89223541d3678f4c351333392bfe6a27739e1fe2bb435acbebe81f19 -
3a6aa72b89223541d3678f4c351333392bfe6a27739e1fe2bb435acbebe81f19
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ..localmachine
Embedded IP addresses
- 40.84.97.4
- 4.150.223.113
- 4.207.44.65
- 52.123.128.14
- 20.184.175.23
- 20.184.175.2
- 20.184.175.8
- 52.148.114.188
- 57.154.63.210
- 92.223.78.30
- 57.155.104.224
- 72.154.7.16
- 72.145.35.97
- 48.211.4.16
- 52.123.129.14
- 172.172.255.217
- 20.42.179.192
- 172.215.188.225
- 57.155.101.212
- 172.215.188.232
- 172.172.255.218
- 52.123.252.202
- 20.89.1.13
- 20.42.73.25
- 40.84.85.40
More Clipper samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report