MALICIOUS — 3f520754ca8df533b6c264ca01cfe7aa11bc23d0746b0919b55c01b37ee97fdb
MALICIOUS — 3f520754ca8df533b6c264ca01cfe7aa11bc23d0746b0919b55c01b37ee97fdb is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Brontok family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
3f520754ca8df533b6c264ca01cfe7aa11bc23d0746b0919b55c01b37ee97fdb - SHA-1:
ba047a51ceedf9cbb0f18247a0931c3be565698a - MD5:
4c2a97c739b8115f9d098b70b9d2d8c7 - imphash:
1b675db9a912fecbf83526e2fd37cf23 - ssdeep:
6144:2WC4YgB9Giy8mWC4YgB9Giy8mWC4YgB9GiygWC4YgB9GiyMWC4YgB9Giy8mWC4Yb:FtJ9Gi7VtJ9Gi7VtJ9GiatJ9GiKtJ9Gn - TLSH:
T13D45E1C3653A3616DED7B4FA2084150F67A9C4801C7BECD44E6B81187B2872B68FD867 - Submitted as: 3f520754ca8df533b6c264ca01cfe7aa11bc23d0746b0919b55c01b37ee97fdb
- File type: pe · Size: 281421 bytes
- Verdict: malicious (98/100) · Family: Brontok
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): Petite
- ClamAV (daily): Win.Malware.Brontok-10037995-0
- Detect It Easy (packer/type): DIE:Petite 2.2
- Kaspersky (KVRT): Email-Worm.Win32.Brontok.am
- Microsoft Defender: Worm:Win32/Rahiwi!pz
- Emsisoft (Emergency Kit): Gen:Variant.Worm.VB.75
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Malware.Brontok-10037995-0 (rule
Win.Malware.Brontok-10037995-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a suspicious payload: e90fc4c090ec1e6c330a769d7736c70d26a0ada8403704dd63b36c47724c7b20 - dynamic signal, weight 0.50, confidence 0.90
- Contacted 39 external host(s) at runtime (13 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:Petite 2.2 (rule
DIE:Petite 2.2) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Petite, high-entropy-sections:.petite, Petite 2.2 - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
6215 behavior events · 1 ATT&CK techniques · 21 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- settings-win.data.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- licensing.mp.microsoft.com
- www.bing.com
- tas02.sls.update.microsoft.com
- v10.events.data.microsoft.com
- to-do.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/20305/files/e90fc4c090ec1e6c330a769d7736c70d26a0ada8403704dd63b36c47724c7b20 -
e90fc4c090ec1e6c330a769d7736c70d26a0ada8403704dd63b36c47724c7b20 - /opt/CAPEv2/storage/analyses/20305/files/8b12410061765f7c415aed0e5f986efc28de03d76f78a2da314a1982f0e2a36d -
8b12410061765f7c415aed0e5f986efc28de03d76f78a2da314a1982f0e2a36d - /opt/CAPEv2/storage/analyses/20305/files/574a3a546332854d82e4f5b54cc5e8731fe9828e14e89a728be7e53ed21f6bad -
574a3a546332854d82e4f5b54cc5e8731fe9828e14e89a728be7e53ed21f6bad - /opt/CAPEv2/storage/analyses/20305/files/08bd22b955c405924527fd0a22617eacc12c8ff5aad4ab49a5f64f55587f9f8e -
08bd22b955c405924527fd0a22617eacc12c8ff5aad4ab49a5f64f55587f9f8e - /opt/CAPEv2/storage/analyses/20305/files/8c879d22f3ec353c05008aa33f72dc08830f5c7b3963cb98be3abfdef72a1267 -
8c879d22f3ec353c05008aa33f72dc08830f5c7b3963cb98be3abfdef72a1267 - /opt/CAPEv2/storage/analyses/20305/files/55322883d5736dcbfc892e216871f1be08234961f3c48a22acf9e22dcb3498ef -
55322883d5736dcbfc892e216871f1be08234961f3c48a22acf9e22dcb3498ef - /opt/CAPEv2/storage/analyses/20305/files/898288bd3b21d0e7d5f406df2e0b69a5bbfa4f241baf29a2cdf8a3cf4d4619f2 -
898288bd3b21d0e7d5f406df2e0b69a5bbfa4f241baf29a2cdf8a3cf4d4619f2 - /opt/CAPEv2/storage/analyses/20305/files/2465a7566e49e6a8828594b36fa0afe6996f5fc2609cae26bb49bbb338e76086 -
2465a7566e49e6a8828594b36fa0afe6996f5fc2609cae26bb49bbb338e76086 - /opt/CAPEv2/storage/analyses/20305/files/285ebd0bae3cfd4cc65d425a8721b283f9718a174c83838577344b2bc044f17a -
285ebd0bae3cfd4cc65d425a8721b283f9718a174c83838577344b2bc044f17a - /opt/CAPEv2/storage/analyses/20305/files/4ff3447beb1c587162f7104ae99d35de89dcddf730c064ca4419c94a4cc80683 -
4ff3447beb1c587162f7104ae99d35de89dcddf730c064ca4419c94a4cc80683 - /opt/CAPEv2/storage/analyses/20305/files/1f4d839302703696d01658eae324c5d407be960a9f2b3a1a041a9f450f346f9f -
1f4d839302703696d01658eae324c5d407be960a9f2b3a1a041a9f450f346f9f - /opt/CAPEv2/storage/analyses/20305/files/9bd8b7d006c19529cd2e678cd9ae096c020cedf6c96942e886837288806bc0bd -
9bd8b7d006c19529cd2e678cd9ae096c020cedf6c96942e886837288806bc0bd - /opt/CAPEv2/storage/analyses/20305/files/b1d5bbda0b0d76bd7d184b451a083526efccd8462d8ff2da607d52b6762c8bd1 -
b1d5bbda0b0d76bd7d184b451a083526efccd8462d8ff2da607d52b6762c8bd1 - /opt/CAPEv2/storage/analyses/20305/files/716d2f79871e2f289a895709bf3ae6897d96480896048cebced2d1ba0f3928a8 -
716d2f79871e2f289a895709bf3ae6897d96480896048cebced2d1ba0f3928a8 - /opt/CAPEv2/storage/analyses/20305/files/5d8fb4fd4e58a08523bd8f33e229315fe9789ff4d1d10e98044669a18c7d187d -
5d8fb4fd4e58a08523bd8f33e229315fe9789ff4d1d10e98044669a18c7d187d
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 51.116.246.105
- 52.123.252.212
- 4.230.171.124
- 85.210.193.152
- 52.253.84.76
- 57.154.63.210
- 20.165.94.63
- 20.76.201.171
- 135.233.45.223
- 52.123.252.236
- 20.112.250.133
- 20.42.65.93
- 52.123.252.235
- 20.50.201.206
- 52.123.252.198
- 72.145.35.99
- 74.178.76.44
- 52.110.12.45
More Brontok samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report