MALICIOUS — 2e8f526aac5b5b183eb78aa2b7b1638b21e2ebfa55410a204a76c1b24c69201f
MALICIOUS — 2e8f526aac5b5b183eb78aa2b7b1638b21e2ebfa55410a204a76c1b24c69201f is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Viking family. 8 of 25 detection engines flagged it, exhibiting 9 ATT&CK techniques.
Identification
- SHA-256:
2e8f526aac5b5b183eb78aa2b7b1638b21e2ebfa55410a204a76c1b24c69201f - SHA-1:
1860ae055bf1e835ee1d38af5bffaba04a2cb06e - MD5:
9869dd2fccb0244c7434b76aba168c99 - imphash:
31d1c48ee7d8e07a5706e963146db875 - ssdeep:
24576:B5hVZUdyzGtxQd1QSZ7yjraAXYBkJb+QW4pEui1JcaKBHBm7NQjlciUCqP:HWdyzGtxQXvyjGlBkJHqcaKxBmUUCqP - TLSH:
T149585C9C5A0FB731F2B1C5B45E584F5E402BF09421BE655C1B52C07E2AE3937E8A206B - Submitted as: 2e8f526aac5b5b183eb78aa2b7b1638b21e2ebfa55410a204a76c1b24c69201f
- File type: pe · Size: 1631680 bytes
- Verdict: malicious (100/100) · Family: Viking
Detections (8 of 25 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- capa (capabilities): capability:credential-access
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Virus:Win32/Viking.MS
- Emsisoft (Emergency Kit): Trojan.Agent.FPMF
- Kaspersky (KVRT): Virus.Win32.Lamer.xe
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 100/100 is the fusion of 15 weighted signals:
- Dropped a malicious payload: 0e30c51ac086b6b5dae2ae7039af88c090316805aa0927ab4e2f007895f3841f - dynamic signal, weight 0.80, confidence 0.90
- Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - Microsoft Defender flagged Virus:Win32/Viking.MS (rule
Virus:Win32/Viking.MS) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Agent.FPMF (rule
Trojan.Agent.FPMF) - engine signal, weight 0.55, confidence 0.85 - access stored credentials (rule
access stored credentials) - capa signal, weight 0.50, confidence 0.80 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Anti-analysis: T1497, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
60484 behavior events · 2 ATT&CK techniques · 66 dropped files.
Runtime network
- www.msftconnecttest.com
- searchapp.bundleassets.example
- desktop-hsgcbep
- ctldl.windowsupdate.com
- config.edge.skype.com
- www.bing.com
- dns.msftncsi.com
- watson.events.data.microsoft.com
- msedge.api.cdp.microsoft.com
- edge.microsoft.com
- aefd.nelreports.net
- www.msftncsi.com
- time.windows.com
- geo.prod.do.dsp.mp.microsoft.com
- geover.prod.do.dsp.mp.microsoft.com
- 192.168.122.112
- 224.0.0.252
- 192.168.122.1
- 192.168.122.255
- 192.168.122.107
Dropped files
- /opt/CAPEv2/storage/analyses/9210/files/ed357b8d2c4536d4457710e0efa72238c0a83078a9a1cd74c4d3ba68e6cbfa49 -
ed357b8d2c4536d4457710e0efa72238c0a83078a9a1cd74c4d3ba68e6cbfa49 - /opt/CAPEv2/storage/analyses/9210/files/5b7c6a0f3af7e6f8c3a002a27b0dbc229f0ff22f0a88d950096c5d7f859397b3 -
5b7c6a0f3af7e6f8c3a002a27b0dbc229f0ff22f0a88d950096c5d7f859397b3 - /opt/CAPEv2/storage/analyses/9210/files/1ca20872bd7bad2f44f5c8845ede32368aff842a04374052f4ef0dccd712b16b -
1ca20872bd7bad2f44f5c8845ede32368aff842a04374052f4ef0dccd712b16b - /opt/CAPEv2/storage/analyses/9210/files/2f4c353a958881b1ec617f50dad2deee5309c181b5c1399a3c955811d761f665 -
2f4c353a958881b1ec617f50dad2deee5309c181b5c1399a3c955811d761f665 - /opt/CAPEv2/storage/analyses/9210/files/0e30c51ac086b6b5dae2ae7039af88c090316805aa0927ab4e2f007895f3841f -
0e30c51ac086b6b5dae2ae7039af88c090316805aa0927ab4e2f007895f3841f - /opt/CAPEv2/storage/analyses/9210/files/22bbaaf2b6738efdf687309c219b8d0ceb26a32ab6298aa1db4d26de08ebad4f -
22bbaaf2b6738efdf687309c219b8d0ceb26a32ab6298aa1db4d26de08ebad4f - /opt/CAPEv2/storage/analyses/9210/files/5c9876e405fcc0c420fbc02cd71c0d63a0d19ebe9e1b9bad530b6ccda9a043f1 -
5c9876e405fcc0c420fbc02cd71c0d63a0d19ebe9e1b9bad530b6ccda9a043f1 - /opt/CAPEv2/storage/analyses/9210/files/bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 -
bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 - /opt/CAPEv2/storage/analyses/9210/files/09b424f26896db6f2bc3c53595ec7607ef3d812219be576d4104e224f5417b6f -
09b424f26896db6f2bc3c53595ec7607ef3d812219be576d4104e224f5417b6f - /opt/CAPEv2/storage/analyses/9210/files/1d0fbfd581f1034913f1b72074ea5f03ee08019c5888397fa730d8ddefd523c8 -
1d0fbfd581f1034913f1b72074ea5f03ee08019c5888397fa730d8ddefd523c8 - /opt/CAPEv2/storage/analyses/9210/files/0466978952a3886112efd1cce34efa86f5f69c1702e55c5ecbf2ea51c8169e4e -
0466978952a3886112efd1cce34efa86f5f69c1702e55c5ecbf2ea51c8169e4e - /opt/CAPEv2/storage/analyses/9210/files/29ced22ab5d90976c570c7284b50332cd6dcee84d6ca9e4e585a302260eb1f63 -
29ced22ab5d90976c570c7284b50332cd6dcee84d6ca9e4e585a302260eb1f63 - /opt/CAPEv2/storage/analyses/9210/files/f4fac4593b8be5a373e4dd3e709c5882e2fcd7315a909b64a6a8e770942e0b43 -
f4fac4593b8be5a373e4dd3e709c5882e2fcd7315a909b64a6a8e770942e0b43 - /opt/CAPEv2/storage/analyses/9210/files/f0a1e75b067b9e72b2c6a5ee350f664919b80e7891d1e9bbce212dd8a80bd143 -
f0a1e75b067b9e72b2c6a5ee350f664919b80e7891d1e9bbce212dd8a80bd143 - /opt/CAPEv2/storage/analyses/9210/files/5a905c5e7806b13c7ac2e2cf07800866823706b13b82a2a20cf16b1529c6be0b -
5a905c5e7806b13c7ac2e2cf07800866823706b13b82a2a20cf16b1529c6be0b
Embedded URLs
- https://ecs.office.com/config/v1/
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://schemas.microsoft.com/SMI/2016/WindowsSettings
- http://schemas.microsoft.com/SMI/2020/WindowsSettings
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- https://login.windows.net
- https://login.microsoft.com
- https://graph.microsoft.com
- https://go.microsoft.com/fwlink/?LinkID=518969
- https://go.microsoft.com/fwlink/?LinkId=246444
- https://go.microsoft.com/fwlink/?LinkID=518968
- https://go.microsoft.com/fwlink/?LinkId=246445
- https://definitionupdates.microsoft.com/
Embedded domains
- ecs.office.com
- endpoint.security.microsoft.com
- schemas.microsoft.com
- www.microsoft.com
- crl.microsoft.com
- login.windows.net
- login.microsoft.com
- graph.microsoft.com
- go.microsoft.com
- 474a-87ad-2f9a87615fa3-dc1-tip.cloudapp.net
- definitionupdates.microsoft.com
- aefd.nelreports.net
Embedded IP addresses
- 192.168.0.30
- 192.168.8.1
Registry keys
- HKEY_LOCAL_MACHINE\%ws
File paths
- S:\:m:~:
- G:\:u:
- U:\:
- G:\:g:{:
- T:\:d:l:t:
- X:\:`:d:h:l:p:t:x:
- L:\:`:p:t:x:
- X:\:`:t:x:
- T:\:h:
- C:\Users\Public\Downloads
More Viking samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report