MALICIOUS — 3af947e9ce4d3337793bf99c451bcdeb0e2310a699877890bebc0877b44fb849
MALICIOUS — 3af947e9ce4d3337793bf99c451bcdeb0e2310a699877890bebc0877b44fb849 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Picsys family. 6 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
3af947e9ce4d3337793bf99c451bcdeb0e2310a699877890bebc0877b44fb849 - SHA-1:
b5b8ba0abb01de3861143cd79b7b1411d28bea5c - MD5:
5fc4fc6dc1cfa6b29c63a86062294857 - imphash:
359d89624a26d1e756c3e9d6782d6eb0 - ssdeep:
1536:y4QQ6NSyM61l19piO+LV8YEoI/EU9RUe4m6NK8ea80oaR6oO1whbN5xYm:y4X6NSyfnpijeYEoIcq4nN38IkoOEbNX - TLSH:
T1E93902849881B8A8ED8FCAA04CEB5E7C1DE3677D21D63B4C76CD603C180F057D9A15A4 - Submitted as: 3af947e9ce4d3337793bf99c451bcdeb0e2310a699877890bebc0877b44fb849
- File type: pe · Size: 84671 bytes
- Verdict: malicious (100/100) · Family: Picsys
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Worm.Picsys-6804101-0
- Detect It Easy (packer/type): DIE:Turbo Linker
- Microsoft Defender: Worm:Win32/Yoof!pz
- Trellix Stinger (McAfee): W32/Picsys.worm!2DB56C7ACE80
- Kaspersky (KVRT): P2P-Worm.Win32.Picsys.b
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Worm.Picsys-6804101-0 (rule
Win.Worm.Picsys-6804101-0) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s) across 1 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged Worm:Win32/Yoof!pz (rule
Worm:Win32/Yoof!pz) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged W32/Picsys.worm!2DB56C7ACE80 (rule
W32/Picsys.worm!2DB56C7ACE80) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged P2P-Worm.Win32.Picsys.b (rule
P2P-Worm.Win32.Picsys.b) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 1 external host(s) and 18 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 a#¤, Turbo Linker - static signal, weight 0.25, confidence 0.55
- Dropped 24 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
127 behavior events · 1 ATT&CK techniques · 27 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- v7x3a5l9.hypermart.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
Dropped files
- C:\Windows\System32\macromd\kill osama bin laden game.exe -
d3a3deea11b530a525d4ad4bc4b6fa99d0b2f8369bb4a6806f3f9cec6a9232d4 - C:\Windows\System32\macromd\Winzip.exe -
c1b2c705970621761c2b959a341af17cd97f606071d06c2abfd3b5438e6d20a9 - C:\Windows\System32\macromd\cute girl giving head.exe -
fdc9fe92acbdae4a3537c60f61d9bd1816eb9bbd7d3616e6277c5c98fcbae7aa - C:\Windows\System32\macromd\siemens unlocker.exe -
ed75bf4e73471fa508a322314c95a4724b5ea7554bef60c3f2f36856a8fc7d84 - C:\Windows\System32\macromd\16 year old on beach.exe -
220217640cd2b0a30bc8110ff2c753eb5755be98c083b5f45cfe79cfa2989f82 - C:\Windows\System32\macromd\Choke on cum (sodomy, rape).mpg.exe -
8ea9e291476e606d04a0209e7eb93af6f88dcf4ce88b0d42618b781fa41640b5 - C:\Windows\System32\macromd\Norton antivirus 2002.exe -
e23ff1fc37bcc172d3402cd660fa07adf450871093b5ed009c1396cbfe6a531b - C:\Windows\System32\macromd\play station emulator crack.exe -
6d3209f0ef97b3bd04d33accd12e707cde3ec8d6b2a84136ae4bb534cbf174df - C:\Windows\System32\macromd\divx pro.exe -
f438ec09368995577b31aacdafc6b86fb030628ce720e4bf34e738ffa50e6479 - C:\Windows\System32\macromd\15 year old webcam.mpg.pif -
6bdfa95bfb79e63cce44f404c17089cd4efb51d22e873b89e53f6f7dcdeae42c - C:\Windows\System32\macromd\Teen Violent Forced Gangbang.exe -
0a720e3f72ee40cfcd6f018a2f2132f9e62ea4d90bd0730077a8d30f9401d636 - C:\Windows\System32\macromd\illgal incest preteen porn cum.mpg.exe -
20bacddd2ce49b76fde2b63aa2ca50ac23f1406ea20312cd9597052cbd7a5f95 - C:\Windows\System32\macromd\girls gone wild.mpg.exe -
1aab8d2debed4fffc754073760d9b66972d734f9e3f4e26f55ee095f83f3b5ab - C:\Windows\System32\macromd\hotmailhacker.exe -
b8c9c2c01f3c376b4ed08949fc44f1cb732d234ed31eba8b11ca8c83e22c4207 - C:\Windows\System32\macromd\AIM Password Stealer.exe -
d21179e789010ce1ecef0b1374b25e78626c75f98e07cb7e3ebb312a6cee0e99
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- http://v7x3a5l9.hypermart.net/cgi-bin/w.cgi?192.168.122.116A5992B8998C8395D54917756E3F0
Embedded domains
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- v7x3a5l9.hypermart.net
Embedded IP addresses
- 4.150.223.104
- 4.230.171.124
- 4.247.188.233
- 20.247.184.197
- 74.179.77.204
- 74.178.240.51
- 20.42.65.91
- 20.165.94.63
- 48.211.4.16
- 38.113.1.151
- 72.145.35.109
- 52.148.114.188
- 52.110.12.2
- 52.110.12.4
More Picsys samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report