MALICIOUS — 2ea55889733089718430e7a5da15ef44200525047ad564dbbab9f0911b896b92
MALICIOUS — 2ea55889733089718430e7a5da15ef44200525047ad564dbbab9f0911b896b92 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Crypted family. 4 of 56 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2ea55889733089718430e7a5da15ef44200525047ad564dbbab9f0911b896b92 - SHA-1:
2bc1e68ee171b843f0c7d9b151be83bb1b8da54e - MD5:
4b627dd4cd617ecb1c9e48f33edabbc6 - imphash:
95e6f8741083e0c7d9a63d45e2472360 - ssdeep:
768:G94SL/wJCmeHzS82IMs36dQhWKFD7otqkrjnqbp/1H5Nq:44SEyR4tqkrDWju - TLSH:
T1BB326B0F30706E2DEA465FFE706AE06D76922D15C8A211C257B5803BCF8B74FA097186 - Submitted as: 2ea55889733089718430e7a5da15ef44200525047ad564dbbab9f0911b896b92
- File type: pe · Size: 46592 bytes
- Verdict: malicious (98/100) · Family: Crypted
Detections (4 of 56 engines)
- ClamAV (daily): Win.Trojan.Crypted-29
- Microsoft Defender: TrojanDownloader:Win32/Berbew!pz
- Emsisoft (Emergency Kit): Backdoor.Hangup.B
- Kaspersky (KVRT): Trojan-Spy.Win32.Qukart.af
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypted-29 (rule
Win.Trojan.Crypted-29) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged TrojanDownloader:Win32/Berbew!pz (rule
TrojanDownloader:Win32/Berbew!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Backdoor.Hangup.B (rule
Backdoor.Hangup.B) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-Spy.Win32.Qukart.af (rule
Trojan-Spy.Win32.Qukart.af) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
15635 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 1.0.240.10.in-addr.arpa.
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 252.0.0.224.in-addr.arpa.
- watson.events.data.microsoft.com
- 162.240.178.172.in-addr.arpa.
- nexusrules.officeapps.live.com
- 145.109.171.150.in-addr.arpa.
- ff02:0:0:0:0:0:1:3
- 224.0.0.252
- 10.240.0.1
- 224.0.0.251
- ff02:0:0:0:0:0:0:fb
- ff02:0:0:0:0:0:1:2
- 172.178.240.162 US · San Jose · AS8075 Microsoft Limited
- 150.171.109.145
Embedded IP addresses
- 172.178.240.162
More Crypted samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report