MALICIOUS — 2f4c6f9277fa26233329e8cc0a10c54dc1ca052340c1332fcf15a224d71e5906
MALICIOUS — 2f4c6f9277fa26233329e8cc0a10c54dc1ca052340c1332fcf15a224d71e5906 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100), attributed to the Fareit family. 4 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2f4c6f9277fa26233329e8cc0a10c54dc1ca052340c1332fcf15a224d71e5906 - SHA-1:
4f771c447ae54661218eac7d8f33570176f324cc - MD5:
b7f150ddfaebd506e87cffe648c3279f - imphash:
87a2cde6b27d67fdc47722aff8d57145 - ssdeep:
49152:69MABnFTknAGlV5rbxfOFDcr+03TnAK68l7PslxnjDgJBXo36JHbAGfmK:69MABan1lROc+0jnRf6lZgJNJ7h - TLSH:
T1BB6012BE03633A83D676C7254841BF6E44B2F8A9107A7CCD51B3D03EA7E5C636A90245 - Submitted as: 2f4c6f9277fa26233329e8cc0a10c54dc1ca052340c1332fcf15a224d71e5906
- File type: pe · Size: 3643676 bytes
- Verdict: malicious (94/100) · Family: Fareit
Detections (4 of 52 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Malware.Fareit-10007968-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Trojan:Win32/Fareit.RNDM!MTB
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Malware.Fareit-10007968-0 (rule
Win.Malware.Fareit-10007968-0) - engine signal, weight 0.90, confidence 0.95 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://www.runonpc.com/teach-you-how-to-manually-install-or-upgrade-drivers-for-devices-in-windows-without-installing-drivers-automatically/, https://www.runonpc.com/teach-you-how-to-find-drivers-for-unknown-devices-in-windows-with-the-accuracy-rate-up-to-90/, https://www.runonpc.com - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://www.runonpc.com/teach-you-how-to-manually-install-or-upgrade-drivers-for-devices-in-windows-without-installing-drivers-automatically/
- https://www.runonpc.com/teach-you-how-to-find-drivers-for-unknown-devices-in-windows-with-the-accuracy-rate-up-to-90/
- https://www.runonpc.com
- http://www.w3.org/2001/XMLSchema
- http://www.w3.org/2000/xmlns/
- http://www.w3.org/2001/XMLSchema-instance
Embedded domains
- www.runonpc.com
- runonpc.com
- 03.mx
- www.w3.org
File paths
- X:\:`:d:h:l:p:t:x:
- T:\:d:l:t:
- X:\:`:d:x:
- X:\:`:d:h:l:p:
- X:\:`:d:h:
- J:\:l:
- T:\:`:d:h:l:p:t:x:
- M:\:
- T:\:`:h:l:p:t:x:
- C:\DriverFiles\
- E:\Zz
- e:\JaY
More Fareit samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report