MALICIOUS — 2f1db040507f182758de861826ffcaf684c5582cbdd4e7a3487d5e7fddf770c7
MALICIOUS — 2f1db040507f182758de861826ffcaf684c5582cbdd4e7a3487d5e7fddf770c7 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100). 6 of 56 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
2f1db040507f182758de861826ffcaf684c5582cbdd4e7a3487d5e7fddf770c7 - SHA-1:
7269e6c768d1eb0cbd7b61b3fcba8a67c5dc7313 - MD5:
67474eea7d59f9895f80c0d19ff4d609 - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
3072:bjhNJvOSfNTZdylRJAIMkGi4M1vU2pTvTnQ1P9z3Z/ZV/S65MINy5aELjAiFMNV:PhrFfclP6M1vU2O9V/ZVfqXFMNGc8i/ - TLSH:
T1D7461A23081364F5B08D168F92AB596D0D01764EE339914B2F45F63A39E2F976CD8E32 - Submitted as: 2f1db040507f182758de861826ffcaf684c5582cbdd4e7a3487d5e7fddf770c7
- File type: pe · Size: 302592 bytes
- Verdict: malicious (100/100)
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): BC.Win.Virus.Ransom-9157.A
- Microsoft Defender: Virus:Win32/Nabucur.A
- Emsisoft (Emergency Kit): Win32.Virlock.Gen.4
- Trellix Stinger (McAfee): W32/VirRansom
- Kaspersky (KVRT): Virus.Win32.PolyRansom.a
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 14 weighted signals:
- ClamAV (daily) flagged BC.Win.Virus.Ransom-9157.A (rule
BC.Win.Virus.Ransom-9157.A) - engine signal, weight 0.90, confidence 0.95 - 2 behavioral detection(s) across 2 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.63, confidence 0.90 - Microsoft Defender flagged Virus:Win32/Nabucur.A (rule
Virus:Win32/Nabucur.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Virlock.Gen.4 (rule
Win32.Virlock.Gen.4) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged W32/VirRansom (rule
W32/VirRansom) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.PolyRansom.a (rule
Virus.Win32.PolyRansom.a) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 5 external host(s) and 7 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-sections:.text (rule
high-entropy-sections:.text) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
- Dropped 17 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
44920 behavior events · 3 ATT&CK techniques · 34 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- google.com
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- officeclient.microsoft.com
- www.msn.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- www.bing.com
- assets.msn.com
- th.bing.com
- licensing.mp.microsoft.com
Dropped files
- C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.exe -
ede7deb0f57c504cb58bd9d1109558df63514e6380fd8e5b0c76af068625372a - bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 -
bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 - C:\ProgramData\xiocAsMc\yKgEskQE.exe -
6130e234fb03f2a2813940f041058ada9ebcfe75c6efb501f96cfc5164509e5e - C:\Users\analyst\AppData\Local\Temp\swwO.exe -
71b29a27d64816e3c344784d8e95a9542681d4c9c23e19247969127f8de98a4e - C:\ProgramData\Microsoft\User Account Pictures\guest.bmp.exe -
6240af70465a5879b5f87562491ccc38cf9428f534bcf0e84c9b743fc7a1d1d3 - C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.exe -
866b6077fa72c97821c71e891843ca519872847c4ea20893927c7e4121e46071 - C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png.exe -
d7c1285e4dedbce173496d07a86285f46610c029fca93ce3d630e0b4b81ba58f - C:\Users\analyst\AppData\Local\Temp\qIgi.exe -
abd5336a874035978b4fc12c11bb54b30e9c7ebce784376e494b374b32e2b710 - C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png.exe -
de8972a51d2010ae27f5d6ce79e1ab67bb38e2905f740855b984cc0b8eda54c4 - C:\Users\analyst\AppData\Local\Temp\OQcc.exe -
4dd0dec71c8dad37c30c9a1dc4567088872b3c6854562afb63d83b68023371c1 - C:\Users\analyst\AppData\Local\Temp\DAoYkQQc.bat -
716a2713795ebb4d9e180328e7162687b1d3ac4afe1aee1d520f2544f7129519 - C:\ProgramData\Microsoft\User Account Pictures\guest.bmp -
dffedb4bd7421e0d8b56380f0641136f61f2316d9943e4cdfe0962643abe355d - C:\Users\analyst\AppData\Local\Temp\qwAO.ico -
bcb253ea3735a0cf0a8c6ee06c14c884937c64ddeacedb17240e40d403577620 - C:\ProgramData\xiocAsMc\yKgEskQE.inf -
98d30a5b12fb229e184444448506e3253557425986804597754e7691ec2066ef - C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png -
d3e8d47e8c1622ec10adef672ca7a8992748c4f0a4e75f877462e7e661069698
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://google.com/
Embedded IP addresses
- 40.79.141.155
- 4.230.171.124
- 172.215.188.232
- 40.84.97.4
- 20.247.184.142
- 135.232.92.97
- 20.42.73.30
- 74.178.240.61
- 20.165.94.63
- 104.18.33.89
- 52.168.117.170
- 200.87.164.69
- 48.211.4.16
- 200.119.204.12
- 190.186.45.170
- 52.110.12.21
- 52.110.12.1
- 72.154.7.96
- 52.148.114.188
- 52.110.12.54
- 52.110.12.32
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report