MALICIOUS — 363a622be722fd2576bf45338e0e95a3ce992a3aa51b98c9c2cdab5f7201fa2e
MALICIOUS — 363a622be722fd2576bf45338e0e95a3ce992a3aa51b98c9c2cdab5f7201fa2e is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Porcupine family. 4 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
363a622be722fd2576bf45338e0e95a3ce992a3aa51b98c9c2cdab5f7201fa2e - SHA-1:
5703a3d6fd3ccdbcf891f71e7debdb6a6ebe296a - MD5:
7d95873a43d075568c0ea610b41f3731 - imphash:
9973fdd4b86d866b3faa39fa66cf7e0a - ssdeep:
3072:8jWZn0v1R4Z0cneF6lncRlNx4vvxaBdnK4GkyLrcO9wnX5RsjkmJb:8jMIv4Z0unWlvBdnKpkyfcQwnX5RsHZ - TLSH:
T13A419E1501877613D1FBDD60680CCDAE9451F8E870BA4BAD4203D22F92F4977B8B91EA - Submitted as: 363a622be722fd2576bf45338e0e95a3ce992a3aa51b98c9c2cdab5f7201fa2e
- File type: pe · Size: 193440 bytes
- Verdict: malicious (97/100) · Family: Porcupine
Detections (4 of 55 engines)
- ClamAV feed: SaneSecurity foxhole_generic: Porcupine.Malware.58887.UNOFFICIAL
- Microsoft Defender: Worm:Win32/Xolxo.A
- Emsisoft (Emergency Kit): Dropped:Generic.Malware.SNm.77E31C26
- Kaspersky (KVRT): P2P-Worm.Win32.Delf.aj
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 5 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Porcupine.Malware.58887.UNOFFICIAL (rule
Porcupine.Malware.58887.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload: minidump_upload.exe - dynamic signal, weight 0.62, confidence 0.90
- Contacted 23 external host(s) at runtime (23 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://cygwin.com/problems.html, http://gnu.org/licenses/gpl.html, http://www.gnu.org/software/diffutils/ - static signal, weight 0.35, confidence 0.60
- 1 behavioral detection(s): Discovery: enumerates installed security software [low] (rule
tl-security-software-discovery) - dynamic signal, weight 0.20, confidence 0.90
Dynamic analysis (windows)
38156 behavior events · 0 ATT&CK techniques · 54 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- licensing.mp.microsoft.com
- oneocsp.microsoft.com
- www.msn.com
Dropped files
- C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jfr.exe -
3e27cc6407fc7d7b6e26495c6ff849c23cf3b6e9c8a885ea742ad7b3109af536 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\keytool.exe -
aab998ad4940a31dafe2a5930cdc7bb815ee93ec3a9d455742c59d284e3b1489 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\ktab.exe -
51e57fdf672acec905dc11fb467293a6c1251683cb92e769d451e46b9e0e92d6 - C:\Program Files\Internet Explorer\iexplore.exe- -
64875da3790d4e1b636173715d8b8888f095def0dbf339bb8d443351644e6348 - C:\Program Files\LibreOffice\program\gengal.exe -
0e03675850241d06080af9ec470649ca4a006222c4ff5d1b05029f1751fecf91 - bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 -
bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jrunscript.exe -
3c6d62569a6dbad19d57ab33039ea0626a3eaf4386fa8b207c136957b26005ab - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jabswitch.exe -
c4c65264e0d3b9b31c5262259ec4b8af6ec62a1fff918a98910aabf17f015959 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jfr.exe -
fc8a6c8c74b8ad01290b3958195a39b71a6c9ff6f4142ae28de91be5655f398b - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\ktab.exe -
e9d25579690a5a4e20d8dc158033008fb0632eba882caf050a0c82e0371d141a - C:\Program Files\Internet Explorer\ielowutil.exe -
4e307bc9c49a98187e384a9309fbbf49e4fde50b2b989cede11bb8eb2c8debdc - C:\Program Files\LibreOffice\program\minidump_upload.exe -
1edffe08651f08b2d29e28608f4e5cff5cca4fd53156e06c01451d67681ee070 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jrunscript.exe -
801330670bd5b6d67d3b9da45ca732f052028e09b7ba3327ae5e08b55468eecd - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\java.exe -
a88c5caf128cd44fd1e456ed156bfe3abcd879e3e5d906d35bdfe39f2c918d90 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\java.exe -
8c435a45123e88410f42259fcb3b303b5f60ce00e01d8d4a9c5bd342bf51e184
Embedded URLs
- http://cygwin.com/problems.html
- http://gnu.org/licenses/gpl.html
- http://www.gnu.org/software/diffutils/
- http://www.gnu.org/gethelp/
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787813742&P2=404&P3=2&P4=a%2fp753AyTXrlZJX5GgCHN%2fA1oRAO%2ffoGUkiKKjeUgyiQhn%2fUX%2fgVzQSrjT4tTtgJ1Z4dh49BXFM3nNGQh9Fhlw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787813811&P2=404&P3=2&P4=TVqK%2baQraByB5ERvZrTTfc%2fDDP5hq27eQ2%2bLZomHc4qj2qE3y7l3WUIF7uCpY7l9zWW%2fSh2yyUHi7wOwc%2bMtcA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- cygwin.com
- gnu.org
- www.gnu.org
- crl.microsoft.com
- www.microsoft.com
Embedded IP addresses
- 192.168.137.1
- 255.255.255.0
- 4.150.223.98
- 20.247.185.124
- 48.211.4.16
- 4.230.171.124
- 85.210.196.11
- 74.179.77.204
- 20.184.175.20
- 135.233.95.135
- 74.178.76.128
- 20.112.250.133
- 52.123.128.14
- 40.84.97.4
- 203.26.79.13
- 135.233.45.221
- 74.179.71.159
- 52.148.114.188
- 125.56.205.57
- 125.56.205.32
- 72.153.5.61
- 135.233.45.222
- 92.223.78.30
- 52.110.12.2
- 52.110.12.28
Registry keys
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePl
File paths
- C:\My
- C:\WINNT\system32\actmovie.exe
- C:\Windows\SysWOW64\setx.exe
- C:\Windows\SysWOW64\icsunattend.exe
- C:\cygwin64\bin\getent.exe
- C:\cygwin64\usr\share\zoneinfo\right\Asia\Ashgabat
- C:\cygwin64\bin\sdiff.exe
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe
More Porcupine samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report