MALICIOUS — 4b4a89d15c8b8a558f52b8c07f93273200fbbb3173173d96f45f8d424a197653
MALICIOUS — 4b4a89d15c8b8a558f52b8c07f93273200fbbb3173173d96f45f8d424a197653 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Filerepmalware family. 6 of 56 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
4b4a89d15c8b8a558f52b8c07f93273200fbbb3173173d96f45f8d424a197653 - SHA-1:
d737fbaa22da9d75ef5f43632e8a10d81c1e4d44 - MD5:
5392380a3c34af6e684f42d3dc3e6f9f - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
12288:dwfePUfjKdZcUgiDTlKLp8j6udOsjs1X:dwmPK2XcUgitnORx1 - TLSH:
T11E491286CCA94C33D1A71F10F9A0E8EE2F6A58C7DAC80A8DD3155121A378B97754D3B1 - Submitted as: 4b4a89d15c8b8a558f52b8c07f93273200fbbb3173173d96f45f8d424a197653
- File type: pe · Size: 418304 bytes
- Verdict: malicious (100/100) · Family: Filerepmalware
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): Win.Packed.Filerepmalware-9908276-0
- Microsoft Defender: Trojan:MSIL/AgentTesla.DKM!MTB
- Emsisoft (Emergency Kit): Trojan.Crypt
- Trellix Stinger (McAfee): PWS-FCUF!5392380A3C34
- Kaspersky (KVRT): HEUR:Trojan-PSW.MSIL.Agensla.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Packed.Filerepmalware-9908276-0 (rule
Win.Packed.Filerepmalware-9908276-0) - engine signal, weight 0.90, confidence 0.95 - 3 behavioral detection(s) across 3 rule(s): Defense Evasion: disable AV / Defender [high] (rule
tl-defender-tamper) - dynamic signal, weight 0.66, confidence 0.90 - Microsoft Defender flagged Trojan:MSIL/AgentTesla.DKM!MTB (rule
Trojan:MSIL/AgentTesla.DKM!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Crypt (rule
Trojan.Crypt) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PWS-FCUF!5392380A3C34 (rule
PWS-FCUF!5392380A3C34) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan-PSW.MSIL.Agensla.gen (rule
HEUR:Trojan-PSW.MSIL.Agensla.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1082, T1497 - dynamic signal, weight 0.40, confidence 0.75
- Extracted AgentTesla config (0 C2) - engine signal, weight 0.45, confidence 0.60
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-sections:.text (rule
high-entropy-sections:.text) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
19019 behavior events · 1 ATT&CK techniques · 26 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- settings-win.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- odc.officeapps.live.com
- www.msn.com
- licensing.mp.microsoft.com
- assets.msn.com
- www.bing.com
- edge.microsoft.com
- time.windows.com
- geo.prod.do.dsp.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive -
98ba26e314f3c3177c06d56557342e3f7f6daefe55a3b52a85fc1f23d7c1ff82 - C:\Users\analyst\AppData\Local\Temp\__PSScriptPolicyTest_ybwrzpsn.ajq.psm1 -
96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7 - C:\Users\analyst\AppData\Local\Temp\tmp6D27.tmp -
1d7dec506a534e67a20d1c7ada898e6410b087c8196a07dbbbd5b88766317d49 - fa77933b2fb6b5a7b6f5af8ff169adb8df4be0e705151a3f6a3107929de25d3d -
fa77933b2fb6b5a7b6f5af8ff169adb8df4be0e705151a3f6a3107929de25d3d - b9be8273c1b712dd0f39633fa74814bb6fd3d2965476fce9673cffe9b96e1198 -
b9be8273c1b712dd0f39633fa74814bb6fd3d2965476fce9673cffe9b96e1198 - 6fa5bb1691d66454eb5cd332b4bd2e16c2025e87e8178a6ee988bea6262f536b -
6fa5bb1691d66454eb5cd332b4bd2e16c2025e87e8178a6ee988bea6262f536b - b2bd44db8493b996aa0358586495929044669dddd4dbfc98188084200de01234 -
b2bd44db8493b996aa0358586495929044669dddd4dbfc98188084200de01234 - 91655863c7906a8d20c7c782144f553c027843a72f2fdab2b1ccc80808083af0 -
91655863c7906a8d20c7c782144f553c027843a72f2fdab2b1ccc80808083af0 - 1e0d6f68860cc06db8b8e919ce602b8b1a6e5967141140845a39287eaa65314a -
1e0d6f68860cc06db8b8e919ce602b8b1a6e5967141140845a39287eaa65314a - 115c65bf97d7bfe9cace917076a4c50dba0eae17f6fdb8eab907601d85c48f13 -
115c65bf97d7bfe9cace917076a4c50dba0eae17f6fdb8eab907601d85c48f13 - 419a91e1beb641351d19c035b57b71df7f265ae36a2abc2364be2ed24c79ea9a -
419a91e1beb641351d19c035b57b71df7f265ae36a2abc2364be2ed24c79ea9a - 6f1871872f3c6dfca51fd9cf51312616cd8ea564215475791f2b8a686a7c2517 -
6f1871872f3c6dfca51fd9cf51312616cd8ea564215475791f2b8a686a7c2517 - cb030ed94652ff370bd847f1f76c8a6ec40fd98f2772472ca57976d2ba87fd22 -
cb030ed94652ff370bd847f1f76c8a6ec40fd98f2772472ca57976d2ba87fd22 - 8dfdfd848fce66c94f8d8c1526dd5c82f421235b13d2d96ca8547a25b182dafc -
8dfdfd848fce66c94f8d8c1526dd5c82f421235b13d2d96ca8547a25b182dafc - 176e3162c67251de5d3b71ab9c4e280fe4b11d809e617850c472e15c033550fb -
176e3162c67251de5d3b71ab9c4e280fe4b11d809e617850c472e15c033550fb
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- 5.ws
Embedded IP addresses
- 57.155.104.224
- 51.105.71.136
- 4.230.171.124
- 20.247.184.142
- 4.247.188.233
- 72.153.5.141
- 52.148.114.188
- 52.110.12.8
- 52.110.12.55
More Filerepmalware samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report