MALICIOUS — 32519b85c0b422e4656de6e6c41878e95fd95026267daab4215ee59c107d6c77.exe
MALICIOUS — 32519b85c0b422e4656de6e6c41878e95fd95026267daab4215ee59c107d6c77.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Sunburst family. 7 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
32519b85c0b422e4656de6e6c41878e95fd95026267daab4215ee59c107d6c77 - SHA-1:
76640508b1e7759e548771a5359eaed353bf1eec - MD5:
b91ce2fa41029f6955bff20079468448 - imphash:
dae02f32a21e03ce65412f6e56942daa - ssdeep:
24576:6aEBTvRBi6uL6dIvDtjpH9+0A8vca9oD:6awk5vDVpH9+0A8vcay - TLSH:
T15E534AED552FA301D338C5362A40EAEE4C59B89439BDB7AC0F4986721051977FC3A0AD - Submitted as: 32519b85c0b422e4656de6e6c41878e95fd95026267daab4215ee59c107d6c77.exe
- File type: pe · Size: 1011032 bytes
- Verdict: malicious (100/100) · Family: Sunburst
Detections (7 of 52 engines)
- capa (capabilities): capability:execution/powershell
- ClamAV (daily): Win.Countermeasure.Sunburst-9809152-0
- Cyble Vision: Cyble Vision: Cobalt Strike
- Microsoft Defender: Trojan:MSIL/Solorigate!atmn
- Emsisoft (Emergency Kit): Trojan.Win32.Sunburst
- Trellix Stinger (McAfee): Trojan-sunburst
- Kaspersky (KVRT): HEUR:Backdoor.MSIL.SunBurst.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Win.Countermeasure.Sunburst-9809152-0 (rule
Win.Countermeasure.Sunburst-9809152-0) - engine signal, weight 0.90, confidence 0.95 - Cyble Vision flagged Cyble Vision: Cobalt Strike (rule
Cyble Vision: Cobalt Strike) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:MSIL/Solorigate!atmn (rule
Trojan:MSIL/Solorigate!atmn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Win32.Sunburst (rule
Trojan.Win32.Sunburst) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Trojan-sunburst (rule
Trojan-sunburst) - engine signal, weight 0.55, confidence 0.85 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Embedded network infrastructure: http://sv.symcb.com/sv.crl0a, https://d.symcb.com/rpa0, http://sv.symcb.com/sv.crt0 - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (windows)
48 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- searchapp.bundleassets.example
- inference.location.live.net
- desktop-hsgcbep
- ctldl.windowsupdate.com
- v10.events.data.microsoft.com
- login.live.com
- config.edge.skype.com
- www.bing.com
- windows.msn.com
- officeclient.microsoft.com
- msedge.api.cdp.microsoft.com
- dns.msftncsi.com
- fe3cr.delivery.mp.microsoft.com
- watson.events.data.microsoft.com
- edge.microsoft.com
- g.live.com
- ecs.office.com
- self.events.data.microsoft.com
- aefd.nelreports.net
Embedded URLs
- http://sv.symcb.com/sv.crl0a
- https://d.symcb.com/rpa0
- http://sv.symcb.com/sv.crt0
- http://www.symauth.com/cps0
- http://www.symauth.com/rpa00
- http://s1.symcb.com/pca3-g5.crl0
- http://s.symcb.com/universal-root.crl0
- https://d.symcb.com/rpa0@
- http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
- http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0
Embedded domains
- www.solarwinds.com
- thwackfeeds.solarwinds.com
- sv.symcb.com
- d.symcb.com
- www.symauth.com
- s1.symcb.com
- s.symcb.com
- ts-crl.ws.symantec.com
- ts-aia.ws.symantec.com
- t.name
- a.name
- tf.name
- s.name
- aefd.nelreports.net
- inference.location.live.net
Embedded IP addresses
- 2.1.4.21
- 2.1.1.2
- 2.1.1.5
- 2.1.1.4
- 2.1.1.6
- 2.1.1.1
- 1.1.1.1
- 4.1.9.9
- 109.1.1.1
- 1.1.2.1
- 1.1.1.28
- 1.1.20.0
- 1.20.1.1
- 1.1.5.3
- 1.1.1.2
- 2.1.25.3
- 3.1.2.0
- 4.1.9.2
- 2.1.25.2
- 4.1.23.2
- 27.2.1.3
- 27.2.1.6
- 27.2.1.4
- 27.2.1.5
- 27.2.1.7
File paths
- C:\buildAgent\temp\buildTmp\Obj\SolarWinds.Orion.Core.BusinessLayer\Release\SolarWinds.Orion.Core.BusinessLayer.pdb
- C:\{1}{0}.dat
More Sunburst samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report