MALICIOUS — 4314df0a740340c721a7e9049e2c917302126a0ddb9bd5958a871bf2b3e9f504
MALICIOUS — 4314df0a740340c721a7e9049e2c917302126a0ddb9bd5958a871bf2b3e9f504 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Fileinfector family. 5 of 55 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
4314df0a740340c721a7e9049e2c917302126a0ddb9bd5958a871bf2b3e9f504 - SHA-1:
a97010310e1107b8415af577d1f8fe78a3d872d6 - MD5:
d8b982edf8c616037e202a16546d86df - imphash:
895fbb56c02c3d2bca3125cef5da8730 - ssdeep:
768:ae2mxDMm+STZ5UW0Z080t0M06EdXUs1ZmxDMm+SSD0y0xWDwM0Z92cu22TZ3PAy:txft5gdEsyxfw0yPDwtZ92z2UfAPtJD - TLSH:
T1F93AB4D672447710EDB0F904AD44EC2CB1A2D9A622363BD86402D47F34B5BF746EA81E - Submitted as: 4314df0a740340c721a7e9049e2c917302126a0ddb9bd5958a871bf2b3e9f504
- File type: pe · Size: 94208 bytes
- Verdict: malicious (99/100) · Family: Fileinfector
Detections (5 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Dropper.Fileinfector-9832222-0
- Detect It Easy (packer/type): DIE:MinGW
- Microsoft Defender: Trojan:Win32/Vindor!pz
- Kaspersky (KVRT): Virus.Win32.Lamer.ks
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Win.Dropper.Fileinfector-9832222-0 (rule
Win.Dropper.Fileinfector-9832222-0) - engine signal, weight 0.90, confidence 0.95 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Terminates Browser, Office or Security Processes [medium] (rule
tl-process-kill) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 57 external host(s) at runtime (27 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082, T1622, T1497, T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:MinGW (rule
DIE:MinGW) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://www.pinkworld.com, http://www.youporn.com, http://www.redtube.com - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: UPX, high-entropy-sections:UPX1, MinGW - static signal, weight 0.25, confidence 0.55
- Dropped 15 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
75226 behavior events · 2 ATT&CK techniques · 28 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- www.freeav.com
- www.avira.com
- script.crazyegg.com
- www.webassetscdn.com
- nexus.ensighten.com
- assets.adobedtm.com
- t.nc0.co
- doh.cq0.co
- s.go-mpulse.net
- widget.trustpilot.com
Dropped files
- C:\Windows\WindowsUpdate.log -
dab0e99186c1031abcd53756fbe582bc2c68d7a02511182a5d5311c83e8ee267 - C:\Windows\System32\msvcp140_codecvt_ids.dll -
c1871fc06bb19fd4aed8a7d4ef5634b14a1d38007970b6768d1a95868e14f716 - C:\Windows\System32\vcruntime140_threads.dll -
e49dfbcfb904f9b495e01a5f01a597e4e1d0b113a21204a8d2af88382b3347d5 - C:\Windows\System32\NOISE.DAT -
d28710c7e52124b23ff4e988fb5aa926e5557f6368f4939a246265062ce376e2 - C:\Windows\System32\msvcp140_2.dll -
5472af88fc1cf0aa1af5292e3937cf9702810a91ad3df613d4ea304a513e6341 - C:\Windows\System32\msvcp140.dll -
e8a83b3bcc0e3867e97b676f0ea362407cb065b7c2e3f32ee27ea25041a197d7 - C:\Windows\System32\vccorlib140.dll -
1546d343ac7288a2ba0848ccb2773f7ef03a0b865c94c786859720bb3dddfa5e - C:\Windows\Professional.xml -
7599d4e863c2f8faa5e371fd424a61c7131b8b295d2d8d5dee683d540ea778cf - C:\Windows\System32\concrt140.dll -
c7974f6836f2781b3f0bc9a3287a30a34d638e6f9b92d12dd0fbe0183ec13f40 - C:\Windows\System32\msvcp140_atomic_wait.dll -
eed104c9897fcc6a6e4c7434223342f0335cc62b6a5a02322a121f1dc727fd73 - C:\Windows\System32\msvcp140_1.dll -
25f6e1fcd72d57fdcb6fcb545c89b1febffdef63cf9434eab880dedd869a3cd3 - C:\Windows\System32\license.rtf -
c540468fc654e6b9c6613dcddfebc6dc74ca8456664deea6da40ce63cdf86c95 - C:\Windows\lsasetup.log -
5116d9c52e6cdd3e53ab641f4c1b2bf6264eec74a376202bbb513cc725f5edeb - C:\Windows\SysmonDrv.sys -
a7392b6eeaaca3dc3fa9dc1e189ebe421846e1451d3be42d315e783388ef4679 - C:\Windows\System32\PrintConfig.dll -
14c689e72af4a9fe8d68c0d8d3ff5135b2f1d2e1d3cc63b839d636a0e12f93a0
Embedded URLs
- http://www.pinkworld.com
- http://www.youporn.com
- http://www.redtube.com
- http://www.assparade.com/
- http://www.freeav.com/
- http://www.antispyware.com/
- http://www.antivirus.com/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787803581&P2=404&P3=2&P4=SXECgEBaE4BHv%2b%2fMjuEyNd0UZBZJw7ZU%2fXOTZjaOfVE%2fSd5bgSngy7lOjv4IcdBnDPsBLtm39kgz37ErvO4q7A%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787803617&P2=404&P3=2&P4=fxrWtbfDYCXmIOebcZswhzO1H1eqcsdzlbndGbhJN1WnjOL8o9pVIaZC8avf9DkiIRdO15on4Pv1F7wlPrp5kQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- www.pinkworld.com
- www.youporn.com
- www.redtube.com
- www.assparade.com
- www.freeav.com
- www.antispyware.com
- www.antivirus.com
- www.avira.com
- script.crazyegg.com
- nexus.ensighten.com
- assets.adobedtm.com
- www.webassetscdn.com
- t.nc0.co
- doh.cq0.co
- s.go-mpulse.net
- widget.trustpilot.com
- dpm.demdex.net
- symantec.demdex.net
- symantec.tt.omtrdc.net
- data.privacy.ensighten.com
- www.nortonlifelock.com
- mhubc.avira.com
- rmbyy5ra.avira.com
- oms.avira.com
- getrockerbox.com
Embedded IP addresses
- 4.150.223.114
- 52.123.252.193
- 52.253.84.76
- 40.84.97.4
- 4.230.171.124
- 135.233.95.144
- 135.232.92.97
- 20.184.175.8
- 20.184.175.12
- 20.236.44.162
- 52.123.128.14
- 52.123.129.14
- 135.234.160.244
- 135.233.45.221
- 135.232.92.34
- 203.26.79.13
- 52.148.114.188
- 20.50.73.5
- 48.199.12.1
- 52.58.28.12
- 13.70.178.62
- 4.195.116.8
- 142.250.183.40
- 72.145.35.105
- 63.140.56.138
File paths
- C:\Program
More Fileinfector samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report