MALICIOUS — 3f89be262bb4ce63d7008fe398cf9b772b47221e2c710e6694ebe8f156b1074c
MALICIOUS — 3f89be262bb4ce63d7008fe398cf9b772b47221e2c710e6694ebe8f156b1074c is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Picsys family. 6 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
3f89be262bb4ce63d7008fe398cf9b772b47221e2c710e6694ebe8f156b1074c - SHA-1:
c5b3029e8d5b3357ca58e6229422ce149b778ac1 - MD5:
34cb1207c01d80c19db2e07e67ecbdc9 - imphash:
359d89624a26d1e756c3e9d6782d6eb0 - ssdeep:
1536:y4QQ6NSyM61l19piO+LV8YEoI/EU9RUe4m/lEVfGb8xDzaO:y4X6NSyfnpijeYEoIcq4pVU8lza - TLSH:
T1C238124976912C7CDC9FE89A0CBF6A7D0DD1925E22AF354C16CCA036490F04BE871B59 - Submitted as: 3f89be262bb4ce63d7008fe398cf9b772b47221e2c710e6694ebe8f156b1074c
- File type: pe · Size: 81920 bytes
- Verdict: malicious (100/100) · Family: Picsys
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Worm.Picsys-6804101-0
- Detect It Easy (packer/type): DIE:Turbo Linker
- Microsoft Defender: Worm:Win32/Yoof!pz
- Trellix Stinger (McAfee): W32/Picsys.worm!F8173648638C
- Kaspersky (KVRT): P2P-Worm.Win32.Picsys.b
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Worm.Picsys-6804101-0 (rule
Win.Worm.Picsys-6804101-0) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s) across 1 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged Worm:Win32/Yoof!pz (rule
Worm:Win32/Yoof!pz) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged W32/Picsys.worm!F8173648638C (rule
W32/Picsys.worm!F8173648638C) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged P2P-Worm.Win32.Picsys.b (rule
P2P-Worm.Win32.Picsys.b) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 1 external host(s) and 19 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 a#¤, Turbo Linker - static signal, weight 0.25, confidence 0.55
- Dropped 23 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
127 behavior events · 1 ATT&CK techniques · 27 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- v7x3a5l9.hypermart.net
- ctldl.windowsupdate.com
- login.live.com
- update.googleapis.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
Dropped files
- C:\Windows\System32\macromd\siemens unlocker.exe -
bcd7f4d3608d0b4736ec1ba4065413c89fd683d44699bbcee7ab04e286958063 - C:\Windows\System32\macromd\Another bang bus victim forced rape sex cum.mpg.exe -
e25608c8f7199e7caa24a757cfe308727affda7b7cf7735a92aae7fa7f77aa33 - C:\Windows\System32\macromd\yahoo cracker.exe -
9ad2dd4882acf23217bb7255451bc0ac3aae798a01c2a9b3631367421c0850e3 - C:\Windows\System32\macromd\jenna jameson - xxx nurse scene.mpg.pif -
f930c1da9d32a2582bb5fb8503b6f2db3ae0c1f1a04542b3c65b19ecdb1c6286 - C:\Windows\System32\macromd\Kama Sutra Tetris.exe -
38719c66992ce4554b45430917b5d91c979d34d1d45dc2a51febff6b1a4edc37 - C:\Windows\System32\macromd\15 year old webcam.mpg.pif -
9b74fb00ccf5ffc0661ec02b7efcf2a1967cb1fdd6c7e2521bcf45fd6ee94478 - C:\Windows\System32\macromd\MSN.exe -
7bfeb72dc52688099c07faabe2d9b6801b273a4b7cc3a5111c52b25226c2850d - C:\Windows\System32\macromd\Counter Strike CD Keygen.exe -
8d5395676e5ae2f9f8c83a2ce0ed5934f873c18cf361f0f5c03f70a351f60573 - C:\Windows\System32\macromd\pamela anderson naked.mpg.exe -
a7f65f46b8107e9602b77d8a1afd6f90fac9438e16eceb55e114d28d9e38cf8e - C:\Windows\System32\macromd\play station emulator crack.exe -
69057208d711358908e1ed7b9cba69fec090227a92013983b1ad592d7e437c18 - C:\Windows\System32\macromd\Pamela Anderson And Tommy Lee Home Video (Part 1).mpg.exe -
35ec482d7e5dc209f5a26bfc53e7820fdeaebb8f8224173cbc2f0ae21c3cd392 - C:\Windows\System32\macromd\AOL.exe -
e1ce48579c5fb297e7b7a3207db0643b9e3f38c12a65ed75052ce9bdd1c84a1e - C:\Windows\System32\macromd\illegal porno - 15 year old raped by two men on boat.mpg.pif -
33cd0506000b4ccd1c511586599b435b3a97c34e4e2edb26973c42a640a721a4 - C:\Windows\System32\macromd\Pamela Anderson.exe -
3cf5eec1d380c05ff444c98a871af3671f7bac1cade7613b51269c73dc0e156c - C:\Windows\System32\macromd\preteen sucking huge cock illegal.mpg.exe -
961d3b351a745a22f6cee11876f43bebee549bed589167d3459068b2086c49fc
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- http://v7x3a5l9.hypermart.net/cgi-bin/w.cgi?192.168.122.106A3806B8451C9597D30327757E3F0
Embedded domains
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- v7x3a5l9.hypermart.net
Embedded IP addresses
- 52.168.117.171
- 48.211.4.16
- 4.144.132.114
- 4.230.171.124
- 4.247.188.224
- 74.179.77.204
- 74.179.77.164
- 52.168.112.66
- 74.178.240.61
- 172.64.154.167
- 162.159.142.9
- 125.56.205.42
- 125.56.205.32
- 4.247.188.233
- 52.168.117.175
- 52.168.117.170
- 38.113.1.151
- 72.145.35.111
- 92.223.78.30
- 52.148.114.188
- 52.110.12.8
- 52.110.12.10
More Picsys samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report