MALICIOUS — 3372c1edab46837f1e973164fa2d726c5c5e17bcb888828ccd7c4dfcc234a370
MALICIOUS — 3372c1edab46837f1e973164fa2d726c5c5e17bcb888828ccd7c4dfcc234a370 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Teslacrypt family. 11 of 52 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
3372c1edab46837f1e973164fa2d726c5c5e17bcb888828ccd7c4dfcc234a370 - SHA-1:
e654d39cd13414b5151e8cf0d8f5b166dddd45cb - MD5:
209a288c68207d57e0ce6e60ebf60729 - imphash:
41bde7e296ed20c37e477bd256a1b6dc - ssdeep:
3072:rYXT8PUsMNL8V4tD2My/JAAbQoM29wlV58lbNnolY7VgsYiVTPtiTu/q:rowUsML8g2j0o9wb0bNoaKsYImui - TLSH:
T1BD458EB8423A6205E7B3FFA898981F4D0073B008E0B95DD54183D17D16F6CABA867E57 - Submitted as: 3372c1edab46837f1e973164fa2d726c5c5e17bcb888828ccd7c4dfcc234a370
- File type: pe · Size: 290816 bytes
- Verdict: malicious (100/100) · Family: Teslacrypt
Detections (11 of 52 engines)
- YARA: MalwareAnalyser built-in: Ransomware_Note_Language
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- ClamAV (daily): {MD5}bin.trojan.teslacrypt.9309.UNOFFICIAL
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- Cyble Vision: Cyble Vision: TeslaCrypt
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Ransom:Win32/Tescrypt!pz
- Emsisoft (Emergency Kit): Gen:Heur.Ransom.Imps.3
- trellix-stinger: Ransom-FYG!209A288C6820
MITRE ATT&CK
YARA
- Ransomware_Note_Language
Why this verdict
The malicious score of 100/100 is the fusion of 15 weighted signals:
- ClamAV (daily) flagged {MD5}bin.trojan.teslacrypt.9309.UNOFFICIAL (rule
{MD5}bin.trojan.teslacrypt.9309.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Cyble Vision flagged Cyble Vision: TeslaCrypt (rule
Cyble Vision: TeslaCrypt) - engine signal, weight 0.90, confidence 0.95 - Common ransomware note phrasing (rule
Ransomware_Note_Language) - yara signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged Ransom:Win32/Tescrypt!pz (rule
Ransom:Win32/Tescrypt!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Heur.Ransom.Imps.3 (rule
Gen:Heur.Ransom.Imps.3) - engine signal, weight 0.55, confidence 0.85 - trellix-stinger flagged Ransom-FYG!209A288C6820 (rule
Ransom-FYG!209A288C6820) - engine signal, weight 0.55, confidence 0.85 - YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://34r6hq26q2h4jkzj.tor2web.fi, http://34r6hq26q2h4jkzj.onion.cab, http://torproject.org - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://34r6hq26q2h4jkzj.tor2web.fi
- http://34r6hq26q2h4jkzj.onion.cab
- http://torproject.org
- http://34r6hq26q2h4jkzj.onion/
- https://7tno4hib47vlep5o.tor2web.fi
- https://7tno4hib47vlep5o.tor2web.blutmagie.de
- https://7tno4hib47vlep5o.tor2web.org
- https://34r6hq26q2h4jkzj.tor2web.org
- https://34r6hq26q2h4jkzj.tor2web.fi
- https://www.torproject.org/projects/torbrowser.html.en
Embedded domains
- 7tno4hib47vlep5o.tor2web.fi
- 7tno4hib47vlep5o.tor2web.blutmagie.de
- 7tno4hib47vlep5o.tor2web.org
- 34r6hq26q2h4jkzj.tor2web.fi
- torproject.org
- bitcoin.toshi.io
- blockchain.info
- www.torproject.org
- 34r6hq26q2h4jkzj.tor2web.org
- 34r6hq26q2h4jkzj.onion.cab
- 34r6hq26q2h4jkzj.onion
Embedded IP addresses
- 50.7.138.132
More Teslacrypt samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report