MALICIOUS — 37e5d8cc2c376e9b54823d6e095856ac1868ead9e3113baa4eabf165bd3e451e
MALICIOUS — 37e5d8cc2c376e9b54823d6e095856ac1868ead9e3113baa4eabf165bd3e451e is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the AntiDebug family. 8 of 56 detection engines flagged it.
Identification
- SHA-256:
37e5d8cc2c376e9b54823d6e095856ac1868ead9e3113baa4eabf165bd3e451e - SHA-1:
a4b6f805e2f64df95e59355d2a0fd05ae0979d38 - MD5:
2889faae7bb03a264b9c948bcd301e6f - imphash:
6d58d46cb4da553c2a028fd56457c4dc - ssdeep:
6144:K6OCSulgh7LKlWTXz8dQo+U+Bvl2rTXbwSihFCinOh:aCncLTsdQnU+Bvl2rTXbmFCiO - TLSH:
T1DA49AECD621DB705E6338E765D424A9E1847A0F488BA340C5E57C03E22F1CE7E8B65B9 - Submitted as: 37e5d8cc2c376e9b54823d6e095856ac1868ead9e3113baa4eabf165bd3e451e
- File type: pe · Size: 409424 bytes
- Verdict: malicious (100/100) · Family: AntiDebug
Detections (8 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): Win.Packed.Generic-9909532-0
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- LIEF (executable format parser): lief:invalid-authenticode
- Microsoft Defender: Trojan:Win32/Raccoon.AD!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Ransom.Loki.17756
- Trellix Stinger (McAfee): Packed-GDT!2889FAAE7BB0
- Kaspersky (KVRT): UDS:DangerousObject.Multi.Generic
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Packed.Generic-9909532-0 (rule
Win.Packed.Generic-9909532-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Raccoon.AD!MTB (rule
Trojan:Win32/Raccoon.AD!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Ransom.Loki.17756 (rule
Gen:Variant.Ransom.Loki.17756) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Packed-GDT!2889FAAE7BB0 (rule
Packed-GDT!2889FAAE7BB0) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:DangerousObject.Multi.Generic (rule
UDS:DangerousObject.Multi.Generic) - engine signal, weight 0.55, confidence 0.85 - Contacted 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Extracted RedLine config (0 C2) - engine signal, weight 0.45, confidence 0.60
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-sections:.text (rule
high-entropy-sections:.text) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://sv.symcb.com/sv.crl0a, https://d.symcb.com/rpa0, http://sv.symcb.com/sv.crt0 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
17 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- desktop-hsgcbep
- login.live.com
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- fe3cr.delivery.mp.microsoft.com
- slscr.update.microsoft.com
- v10.events.data.microsoft.com
- settings-win.data.microsoft.com
- www.bing.com
Dropped files
- 48e70966930f1453a8436585a30962045b92a2d71e9c3e23fd162774276c52c0 -
48e70966930f1453a8436585a30962045b92a2d71e9c3e23fd162774276c52c0 - 6e48da4feec81ce78c78490bd2c6108c0ba3058b980fcc53fb3f2ac087a7018a -
6e48da4feec81ce78c78490bd2c6108c0ba3058b980fcc53fb3f2ac087a7018a - 17d9004fc511ca8f0414cf2c41b425dda6b59da48228886291396a6336605ade -
17d9004fc511ca8f0414cf2c41b425dda6b59da48228886291396a6336605ade
Embedded URLs
- http://crl.thawte.com/ThawteTimestampingCA.crl0
- http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
- http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
- http://sv.symcb.com/sv.crl0a
- https://d.symcb.com/rpa0
- http://sv.symcb.com/sv.crt0
- http://www.symauth.com/cps0
- http://www.symauth.com/rpa00
- http://s1.symcb.com/pca3-g5.crl0
- http://s.symcb.com/universal-root.crl0
- https://d.symcb.com/rpa0@
- http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
- http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- crl.thawte.com
- ts-aia.ws.symantec.com
- ts-crl.ws.symantec.com
- sv.symcb.com
- d.symcb.com
- www.symauth.com
- s1.symcb.com
- s.symcb.com
Embedded IP addresses
- 5.9.42.91
- 7.4.53.21
- 20.184.175.7
- 52.123.252.227
- 4.230.171.124
- 74.179.77.164
- 74.178.240.61
- 172.215.188.225
- 4.150.223.103
- 20.184.175.16
- 4.144.132.114
- 20.247.185.124
- 172.178.240.161
- 52.110.12.37
- 52.110.12.32
File paths
- f:\dd\vctools\crt_bld\self_x86\crt\src\stdenvp.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\stdargv.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\a_env.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\ioinit.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\tidtable.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\onexit.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\mbctype.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\mlock.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\output.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\_getbuf.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\_file.c
- C:\nub.pdb
- f:\dd\vctools\crt_bld\self_x86\crt\src\dbgheap.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\crt0msg.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\dbgrpt.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\winsig.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\tcscpy_s.inl
- f:\dd\vctools\crt_bld\self_x86\crt\src\expand.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\localref.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\isctype.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\errmode.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\tcscat_s.inl
- f:\dd\vctools\crt_bld\self_x86\crt\src\tcsncpy_s.inl
- f:\dd\vctools\crt_bld\self_x86\crt\src\intel\fp8.c
- f:\dd\vctools\crt_bld\self_x86\crt\prebuild\conv\cvt.c
More AntiDebug samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report