MALICIOUS — 4acd7adff5c2193e7b0b9a6f8235534d67772ff3d7fa59b1215de011d7455ad9.exe
MALICIOUS — 4acd7adff5c2193e7b0b9a6f8235534d67772ff3d7fa59b1215de011d7455ad9.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the Kepavll family. 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4acd7adff5c2193e7b0b9a6f8235534d67772ff3d7fa59b1215de011d7455ad9 - SHA-1:
27adcb8fc4c6685c35819569895a8afac75f1b1d - MD5:
5397d935f89da936fe739139a99c7b47 - imphash:
8c28c1d8d4f05a3acc2fa65d54252437 - ssdeep:
12288:RPhnbZIqgm1W6GTt/nUWxwsLkzEc3lktyamaghtXhDmZA83bTe6rbBpcYm:DnbZVs6G3NLkzEGlu6zWrTeobBpc - TLSH:
T142545B20C1C667F0E222F5B6A510EFBD0FA55CCBCB9B5F191BA5BD250A4F44B2D24188 - Submitted as: 4acd7adff5c2193e7b0b9a6f8235534d67772ff3d7fa59b1215de011d7455ad9.exe
- File type: pe · Size: 1127424 bytes
- Verdict: malicious (89/100) · Family: Kepavll
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:Win32/Kepavll!rfn
- Emsisoft (Emergency Kit): Gen:Variant.Yogi.37703
- Kaspersky (KVRT): Trojan.Win32.Agent.xcexuh
MITRE ATT&CK
Why this verdict
The malicious score of 89/100 is the fusion of 6 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Kepavll!rfn (rule
Trojan:Win32/Kepavll!rfn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Yogi.37703 (rule
Gen:Variant.Yogi.37703) - engine signal, weight 0.55, confidence 0.85 - Contacted 24 external host(s) at runtime (17 HTTP) - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
1546 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- config.edge.skype.com
- desktop-hsgcbep
- www.bing.com
- v10.events.data.microsoft.com
- edge.microsoft.com
- officeclient.microsoft.com
- ctldl.windowsupdate.com
- ocsp.digicert.com
- oneocsp.microsoft.com
- odc.officeapps.live.com
- v20.events.data.microsoft.com
- aps.prod.windows.com
- dns.msftncsi.com
- tas02.sls.update.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- slscr.update.microsoft.com
- watson.events.data.microsoft.com
- ecs.office.com
- g.live.com
Dropped files
- bb109cf20fd2ab4b282eb71a64659ca8af0fa9ea69576568ed12fcb246027890 -
bb109cf20fd2ab4b282eb71a64659ca8af0fa9ea69576568ed12fcb246027890 - 420546b57f7d840078918a9631ca89d58e56d7c80a2b909d33692cf9da42a9aa -
420546b57f7d840078918a9631ca89d58e56d7c80a2b909d33692cf9da42a9aa - 2fd3c17c2c54e838a5c797a8bc474018529a2faa67475da94a0bf9793a3ee8ca -
2fd3c17c2c54e838a5c797a8bc474018529a2faa67475da94a0bf9793a3ee8ca
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- oneclient.sfx.ms
Embedded IP addresses
- 150.171.22.17
- 20.42.73.25
- 23.33.238.114
- 150.171.27.11
- 23.40.52.209
- 23.40.52.85
- 74.178.240.61
- 74.178.240.51
- 151.101.30.172
- 52.168.117.171
- 23.40.52.211
- 150.171.109.17
- 23.11.36.157
- 40.84.97.4
- 131.253.33.203
- 172.178.240.161
- 92.223.78.30
- 23.40.52.174
- 20.190.167.149
- 20.184.175.4
- 23.214.54.132
- 52.110.12.37
- 52.110.12.8
- 52.123.252.218
More Kepavll samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report