MALICIOUS — virussign.com_9ae49ead7877e73d1ed9856c4673f450.vir
MALICIOUS — virussign.com_9ae49ead7877e73d1ed9856c4673f450.vir is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Cryxos family. 1 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2e95c6a1842b99a4045e973126f1b16261cb8f0b89ee9e7c618a6e4d0746d7fd - SHA-1:
c9283e758a645a973a6e1e7656cddc6620c2a41d - MD5:
9ae49ead7877e73d1ed9856c4673f450 - ssdeep:
192:fVktQCcjBdvQTPKGEqKwlpvLTUytOM6DVhKQzZiZ:9wcjBiTPcqKwPLTUMqhKQtg - TLSH:
T1691E6D3BF2584F7541CEE114C75CBDB09B93396B33A2C6472E05AB02C9E7B19D06A0A1 - Submitted as: virussign.com_9ae49ead7877e73d1ed9856c4673f450.vir
- File type: html · Size: 6659 bytes
- Verdict: malicious (92/100) · Family: Cryxos
Detections (1 of 51 engines)
- Emsisoft (Emergency Kit): JS:Trojan.Cryxos.16391
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 7 weighted signals:
- Emsisoft (Emergency Kit) flagged JS:Trojan.Cryxos.16391 (rule
JS:Trojan.Cryxos.16391) - engine signal, weight 0.55, confidence 0.85 - Memory forensics: 3 finding(s), e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 20 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://indiazinhalindoya.com.br/vmc/ - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
277 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- login.live.com
- v20.events.data.microsoft.com
- desktop-hsgcbep
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- licensing.mp.microsoft.com
- assets.msn.com
- www.bing.com
- watson.events.data.microsoft.com
- v10.events.data.microsoft.com
- edge.microsoft.com
- ctldl.windowsupdate.com
- time.windows.com
- geo.prod.do.dsp.mp.microsoft.com
- kv801.prod.do.dsp.mp.microsoft.com
Embedded URLs
- https://indiazinhalindoya.com.br/vmc/
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- indiazinhalindoya.com.br
- inference.location.live.net
Embedded IP addresses
- 23.40.52.209
- 4.150.223.97
- 52.123.252.243
- 52.230.60.54
- 4.230.171.124
- 135.233.45.223
- 52.168.117.175
- 52.138.229.67
- 23.33.238.115
- 20.190.142.164
- 23.198.40.44
- 23.33.238.207
- 23.33.238.135
- 23.221.133.185
- 52.148.114.188
- 23.40.52.174
- 52.110.12.1
- 52.110.12.18
- 72.153.5.128
- 150.171.28.11
More Cryxos samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report