MALICIOUS — 42a9882d713586d4e53037b5a2857f7c0cbdb6b81a83f6fc80f3611f1bfb6093
MALICIOUS — 42a9882d713586d4e53037b5a2857f7c0cbdb6b81a83f6fc80f3611f1bfb6093 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Neshuta family. 4 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
42a9882d713586d4e53037b5a2857f7c0cbdb6b81a83f6fc80f3611f1bfb6093 - SHA-1:
9577ec295afadd7f93731be344ebab96a09bafe1 - MD5:
4fdc0d316e39ed7bb3693930d87153cd - imphash:
9f4693fc0c511135129493f2161d1e86 - ssdeep:
768:eyxqjQl/EMQt4Oei7RwsHxyP7nbxzOQdJ0xP:JxqjQ+P04wsmJCZ - TLSH:
T12F314A764B1B7E57E924C37654C0B7AE1023B8787425988B62AB842F73F8C53769023D - Submitted as: 42a9882d713586d4e53037b5a2857f7c0cbdb6b81a83f6fc80f3611f1bfb6093
- File type: pe · Size: 41472 bytes
- Verdict: malicious (100/100) · Family: Neshuta
Detections (4 of 56 engines)
- ClamAV (daily): Win.Trojan.Neshuta-1
- Microsoft Defender: Virus:Win32/Neshta.A
- Emsisoft (Emergency Kit): Win32.Neshta.A
- Kaspersky (KVRT): Virus.Win32.Neshta.a
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Neshuta-1 (rule
Win.Trojan.Neshuta-1) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Neshuta): MsMpEng.exe - dynamic signal, weight 0.62, confidence 0.90
- Microsoft Defender flagged Virus:Win32/Neshta.A (rule
Virus:Win32/Neshta.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Neshta.A (rule
Win32.Neshta.A) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.Neshta.a (rule
Virus.Win32.Neshta.a) - engine signal, weight 0.55, confidence 0.85 - Contacted 2 external host(s) and 17 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Extracted Neshta config (0 C2) - engine signal, weight 0.45, confidence 0.60
- 1 behavioral detection(s) across 1 rule(s): Discovery: enumerates installed security software [low] (rule
tl-security-software-discovery) - dynamic signal, weight 0.20, confidence 0.90
Dynamic analysis (windows)
31516 behavior events · 0 ATT&CK techniques · 26 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- edgedl.me.gvt1.com
- desktop-hsgcbep
- login.live.com
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
Dropped files
- C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\Microsoft.SharePoint.NativeMessagingClient.exe -
fb9b710f48d80b6e83b8d3a17a7f5e01f6c439f6e3183104fb5e0565cf5e98fb - C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCopyAccelerator.exe -
9f1cbe263d2d08858f5701c829e14eda10e0700dc08a0d55a17a649cfa6b669f - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe -
3bdbc8046efdc04af985b5a76002a6d3e5a39a129c46daa438642022946bc770 - C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.261.11\MicrosoftEdgeComRegisterShellARM64.exe -
b889a3f63436e1dc3e095b771fcdd25add073cfab58511107b25ef999e84db91 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileCoAuth.exe -
5358f23617ee658d748c3f62bc59051a880c5b1d481387d6a7f1106be27b53ea - C:\Program Files (x86)\Microsoft\Edge\Application\150.0.4078.105\BHO\ie_to_edge_stub.exe -
e6e8751d7d732c0f942f6b05dd3b73fc4301afee88d356f32269ef03392c2b2e - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\FileSyncHelper.exe -
c3acdd74a6409c1bee178ff9d5f03946259f5a1b058e9ad350f492eb97781584 - C:\Users\analyst\AppData\Local\Temp\tmp5023.tmp -
a1305f4eb463f5a63dda445aa2298f90d630563af1c47be2bd0292d9caa0af93 - C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\ConfigSecurityPolicy.exe -
6beff00da511f29b9f12548f62fd6ef56d9d50af44abc8e4fcef3acb3a7cffe7 - C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\mpextms.exe -
4f9f195ebb589f59f5372c271ff8f9ec5112753a33d97f979514ad345aedb0da - C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\DefenderAgentScan.exe -
7ed29abe42bad4603fb7671181a0f6f8608480ffe3f943ce83453e7dbad3b44a - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\FileSyncConfig.exe -
95ebfec562ac9b1e1553e727814c667fe0b1bd3fa4a301a9771b8df3803c7571 - C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpDlpService.exe -
b5bf77075dea39cd8013639ebe5f35402ce7f02c9a68f30550cf639abee97cf7 - C:\Program Files (x86)\Microsoft\EdgeCore\151.0.4129.101\mscopilot.exe -
84f73bf962ed4204cd65c98528fcd3ae3a6edf057dd74d13a0458717230fdb9e - C:\Python3\Lib\site-packages\pip\_vendor\distlib\w32.exe -
475021c13b0ac8d03dcb78cf87e9a9ae780cfc3cae376fe38f8e0e17d23db7ce
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- http://203.26.79.13/filestreamingservice//files/ea98f53a-04cb-4f17-b9d9-db88a4e098c7/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/ea98f53a-04cb-4f17-b9d9-db88a4e098c7?P1=1785377842&P2=404&P3=2&P4=l1E6ID%2bdP67CJpKOjU%2fX%2fGF9WXhFVyGpnE3i5Cg1PBeyqvAXwFOIHh5%2fQdq0yf4r1ZEEidf68dZXH8WxKtak%2fA%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 20.42.65.89
- 52.123.252.198
- 4.230.171.124
- 20.42.179.204
- 74.179.77.164
- 74.179.77.204
- 20.247.184.142
- 52.168.117.174
- 52.123.252.243
- 92.223.78.30
- 162.159.142.9
- 74.178.240.61
- 4.247.188.233
- 52.123.252.229
- 34.104.35.123
- 172.64.154.167
- 4.209.250.170
- 20.42.65.85
- 203.26.79.13
- 72.154.7.110
- 52.148.114.188
- 52.110.12.38
- 52.110.12.2
- 20.184.175.21
More Neshuta samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report