MALICIOUS — 443429b9244f524ee135fad2fddceccc79256f3a6bb4482b1b0b7abc56702333
MALICIOUS — 443429b9244f524ee135fad2fddceccc79256f3a6bb4482b1b0b7abc56702333 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100), attributed to the Renos family. 7 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
443429b9244f524ee135fad2fddceccc79256f3a6bb4482b1b0b7abc56702333 - SHA-1:
1be32c62a83437f0ffbfb625929c0dc315238540 - MD5:
abc3a201dc297c3c2b994e9794844025 - imphash:
550dd69808331246f4c88041f53579e0 - ssdeep:
3072:mUg/TjjkNGLC6FDOaVV4/PNQiPkfr97dQ2Xj9WkRVk:mUgLnkN6HOaM/PSikJrj9L - TLSH:
T10040F1B7D657B2C4C82EC761E368348D8742F2CE6968A04C8815E47E7B56ECB34921DC - Submitted as: 443429b9244f524ee135fad2fddceccc79256f3a6bb4482b1b0b7abc56702333
- File type: pe · Size: 165376 bytes
- Verdict: malicious (94/100) · Family: Renos
Detections (7 of 53 engines)
- capa (capabilities): capture keystrokes
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:CODE
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: TrojanDownloader:Win32/Renos
- Emsisoft (Emergency Kit): Gen:Variant.Renos.24
- Kaspersky (KVRT): Packed.Win32.Katusha.n
- Trellix Stinger (McAfee): Downloader-CEW.ck
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 6 weighted signals:
- Memory forensics: 5 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 8188) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged TrojanDownloader:Win32/Renos (rule
TrojanDownloader:Win32/Renos) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Renos.24 (rule
Gen:Variant.Renos.24) - engine signal, weight 0.55, confidence 0.85 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:CODE - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
18 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- staging.to-do.officeppe.com
- www.bing.com
- desktop-hsgcbep
- config.edge.skype.com
- tas02.sls.update.microsoft.com
- dns.msftncsi.com
- settings-win.data.microsoft.com
- ctldl.windowsupdate.com
- to-do.microsoft.com
- staging.to-do.microsoft.com
- edge.microsoft.com
- teams.microsoft.com
- aps.prod.windows.com
- watson.events.data.microsoft.com
- 192.168.122.107
- 192.168.122.1
- 192.168.122.255
- 224.0.0.252
Embedded domains
- staging.to-do.officeppe.com
More Renos samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report