MALICIOUS — 42a2e61a257eb64229a74a6c633e0420cc5ed217871d36d1e4e4577ae494421f.msi
MALICIOUS — 42a2e61a257eb64229a74a6c633e0420cc5ed217871d36d1e4e4577ae494421f.msi is a office-ole sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Qwexlafiba family. 4 of 51 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
42a2e61a257eb64229a74a6c633e0420cc5ed217871d36d1e4e4577ae494421f - SHA-1:
aa213b51f38739dcb8d371f060b4ee78bdc39832 - MD5:
864158094e09512792570b2fa7791ca6 - ssdeep:
393216:Np1s7O5Sz3ds708J/LrRQLJg3g9DGH0bpZlJjfFx3O1lP1ICVmTovfYwOv4QS0V:F1qNgBQL+3g9DGHWjdxyICVo - TLSH:
T11E7612889A77A347CD43BBC3191386DCDE430887BA795249C2C1889F9A71573BB721D2 - Submitted as: 42a2e61a257eb64229a74a6c633e0420cc5ed217871d36d1e4e4577ae494421f.msi
- File type: office-ole · Size: 28986880 bytes
- Verdict: malicious (99/100) · Family: Qwexlafiba
Detections (4 of 51 engines)
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Trojan:Win32/Qwexlafiba!rfn
- Kaspersky (KVRT): HEUR:Trojan.Multi.RUHC.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 14 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Qwexlafiba!rfn (rule
Trojan:Win32/Qwexlafiba!rfn) - engine signal, weight 0.55, confidence 0.85 - Obfuscated powershell script: dynamic-exec, shellcode-injection, defense-evasion (layers: base64+concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 540 external host(s) at runtime (6 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded executable payload carved at offset 89600 - static signal, weight 0.40, confidence 0.70
- Extracted RemoteUtilitiesRAT config (0 C2) - engine signal, weight 0.45, confidence 0.60
- Document contains macros/active content: vba - static signal, weight 0.35, confidence 0.75
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://purl.org/dc/elements/1.1/, http://sv.symcb.com/sv.crl0a, https://d.symcb.com/rpa0 - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
4108 behavior events · 2 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- secure.globalsign.com
- inpaCoin.com
- binance.com
- kraken.com
- royalcash.com.ua
- 100monet.com
- 8161.uk
- obmenka.ua
- medoc.ua
- pfu.gov.ua
- exchange24.com.ua
- ankores.com.ua
- kurs.com.ua
- ezvit.org.in
- coinbase.com
- bitcoin.ua
- windowsupd.to
- coin.ua
Dropped files
- tmp_tmp.yNE5gEJEK4 -
b3a5d26d0faefdbe517162504b0ff7b6c32068b63d89a3cef9101c9ba94a37ef
Embedded URLs
- http://ocsp.globalsign.com/rootr30
- http://secure.globalsign.com/cacert/root-r3.crt06
- http://crl.globalsign.com/root-r3.crl0G
- https://www.globalsign.com/repository/0
- http://ocsp.globalsign.com/codesigningrootr450F
- http://secure.globalsign.com/cacert/codesigningrootr45.crt0A
- http://secure.globalsign.com/cacert/gsgccr45evcodesignca2020.crt0
- http://ns.adobe.com/xap/1.0/
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://ns.adobe.com/xap/1.0/rights/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/sType/ResourceRef#
- http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/photoshop/1.0/
- http://logo.verisign.com/vslogo.gif0
- http://sv.symcb.com/sv.crl0a
- https://d.symcb.com/rpa0
- http://sv.symcb.com/sv.crt0
- http://www.symauth.com/cps0
- http://www.symauth.com/rpa00
- http://s1.symcb.com/pca3-g5.crl0
- http://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
Embedded domains
- empty.name
- media.name
- control.name
- used.name
- www.remoteutilities.com
- table.no
- file.no
- taken.no
- mismatch.no
- dialog.no
- cacerts.digicert.com
- crl3.digicert.com
- ocsp.globalsign.com
- secure.globalsign.com
- crl.globalsign.com
- www.globalsign.com
- ns.adobe.com
- www.w3.org
- purl.org
- logo.verisign.com
- sv.symcb.com
- d.symcb.com
- www.symauth.com
- s1.symcb.com
- www.digicert.com
Embedded IP addresses
- 27.0.0.58
- 149.154.167.99
- 74.178.240.61
- 172.172.255.218
- 52.123.252.224
- 52.110.12.50
- 203.26.79.13
- 4.230.171.124
- 4.144.132.223
- 74.178.240.51
- 20.184.175.23
- 74.178.76.128
- 135.233.45.223
- 135.233.45.221
- 176.107.176.66
- 176.107.178.12
- 176.107.176.3
- 176.107.176.89
- 176.107.177.6
- 176.107.177.52
- 176.107.176.2
- 176.107.177.47
- 176.107.176.121
- 176.107.177.10
- 176.107.178.74
File paths
- X:\:`:d:h:l:p:t:
- T:\:d:l:t:
- n:\=
- I:\B
- v:\l(
- w:\K
- c:\R
- k:\A
- e:\g
More Qwexlafiba samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report