MALICIOUS — 2d845e89a0b2bcd7e8abc39ff4f33a905d50e108e50c3aee222b81a71026389d
MALICIOUS — 2d845e89a0b2bcd7e8abc39ff4f33a905d50e108e50c3aee222b81a71026389d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Crypted family. 5 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
2d845e89a0b2bcd7e8abc39ff4f33a905d50e108e50c3aee222b81a71026389d - SHA-1:
b80bebc2c8f89475b283e0d776c9d7ecc68d0cea - MD5:
e40fc7f5798d4be357f8a7ad665f088e - imphash:
c2a87fabf96470db507b2e6b43bd92eb - ssdeep:
6144:LW4CvwghZK/P6G+bSLVwHZLj/xHUQkvbITEv/5nqSLVwHZLj/xHUQ:LdCvbhZK/P6GZLV6ZLFsjTLV6ZLF - TLSH:
T1AE434AC68755D7C2FEBDC2C57094F99DB6A1048824FE512A109AE490CBDFCBBB412398 - Submitted as: 2d845e89a0b2bcd7e8abc39ff4f33a905d50e108e50c3aee222b81a71026389d
- File type: pe · Size: 229376 bytes
- Verdict: malicious (92/100) · Family: Crypted
Detections (5 of 55 engines)
- ClamAV (daily): Win.Trojan.Crypted-29
- Microsoft Defender: Backdoor:Win32/Berbew!pz
- Emsisoft (Emergency Kit): GenPack:Generic.Dacic.1.Backdoor.Hangup.A.8D3133A2
- Trellix Stinger (McAfee): Trojan-FUGH!E40FC7F5798D
- Kaspersky (KVRT): Trojan-Proxy.Win32.Qukart.vjh
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypted-29 (rule
Win.Trojan.Crypted-29) - engine signal, weight 0.90, confidence 0.95 - Contacted 24 external host(s) at runtime (23 HTTP) - network signal, weight 0.40, confidence 0.80
- Dropped 96 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
3079 behavior events · 1 ATT&CK techniques · 96 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Dropped files
- C:\Windows\System32\Bpibkgjc.dll -
f0f36f19f6be00e526a1f8049a7f4e5428b28aee3ce2895b46a24baf9d4bc6ab - C:\Windows\System32\Addmebnd.dll -
4444e29559d3206df10e3666e2dbdd24bf5d7bdfc3e1b4b53ffcc013c5ecf9f1 - C:\Windows\System32\Ldmdaqen.exe -
af2613d5a08e42ac5d4894478c35a222c532f01700913cb9c64686b814f94ff8 - C:\Windows\System32\Nancqmhf.dll -
08cd1ca9bc5ff45ebac5799775e4dca64997c7c1d46c193baf0035ff79bd428b - C:\Windows\System32\Lpafbm32.exe -
f5e5a506464a054abea6c9bf9ab3b189f67fc63a90cb0f686206b2104883f2bf - C:\Windows\System32\Eeclklhm.exe -
4859ca5e0f7ba0619ef5df5598d7047fe001ac69e6096c14ad7316bc6b8132ab - C:\Windows\System32\Maipfmha.exe -
fbf99324c276fad25652d7b4b2f82ed586af94a977e5947a7e037d2e3afe1045 - C:\Windows\System32\Aclhbm32.dll -
4af303e65b0d826b9beeb77e08bed1caaa73c74edbefdf91bdb84bab8066e745 - C:\Windows\System32\Egieemnf.dll -
0152585e4c0981a7dac5e86e7a25ecb9bcf5881aec1846f533a570532ac4b265 - C:\Windows\System32\Pjpgad32.dll -
1af04c8c1a394532fd18cd9937f257e0f50a903a0fdb171ee0ed04321214b030 - C:\Windows\System32\Ehbchd32.dll -
cf396cd8aa038780e72dc4483943a4696d288c6e23a0083203ea0bf036c6b519 - C:\Windows\System32\Ijchfqej.dll -
e579f840085a70136711e12efd2e53d2120bb3c3127209c03b4b01befdfcd48b - C:\Windows\System32\Nqcknl32.exe -
bebff59077c47600399e50f130aebc21c50eeacab0c0bca54914ab45acfca3d4 - C:\Windows\System32\Edpenm32.dll -
38bdb80a46037e3b5d3af2c11bc04553d74746a19d76a99cf87e15a59a27249a - C:\Windows\System32\Mbginplf.exe -
47cb89b97e22225762c52da6f1bb9e864644fbb3d96d35d52a01b400662e6c35
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787937267&P2=404&P3=2&P4=IxHNUhNk%2fTo1wuY9yQzuSasb%2bfeYwpnZBFQ7KBfytPCxwuJ01AJ9pnuJOZnJEnthdTI9GR1jR4DHDnNm6Ue4Iw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787937326&P2=404&P3=2&P4=X6Frcoh6AvcRLyr9F5yjK3Dr8veLRE%2fuxX84yc9jMliRith4ufj28tIUG%2feTFOH8Rl88TL0EElf6NYaPFXVk%2fQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 51.116.253.170
- 57.155.101.212
- 4.230.171.124
- 172.215.188.232
- 20.247.185.124
- 74.178.240.61
- 20.42.73.30
- 74.178.240.51
- 74.178.76.128
- 52.123.128.14
- 20.112.250.133
- 135.233.45.221
- 203.26.79.13
- 135.232.92.34
- 52.148.114.188
- 20.52.64.201
- 4.207.44.68
- 20.42.179.192
- 72.153.5.61
- 92.223.78.30
- 52.110.12.19
- 52.110.12.47
- 52.110.12.56
- 52.110.12.48
More Crypted samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report