MALICIOUS — 4b4af0c83f3c3e54e61afda0703eb5dcef5bf09fc733412e7b00661cd8d8fce1
MALICIOUS — 4b4af0c83f3c3e54e61afda0703eb5dcef5bf09fc733412e7b00661cd8d8fce1 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Nevereg family. 5 of 56 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4b4af0c83f3c3e54e61afda0703eb5dcef5bf09fc733412e7b00661cd8d8fce1 - SHA-1:
a02fcab4ff21ba5cb8a5ed3d7adeeec842e5b284 - MD5:
77c5a48bb3b45f7e3309001bde6d754e - imphash:
ed240876b9293af2891f19d47bc5c522 - ssdeep:
768:9GvbqsQdX5BhGEnOsIzfJ4i4g5p0syi+hvN18K3H8T6++3Kd8VVrTw:4zqsQ5PIt4+/yfeB6rXVrc - TLSH:
T17E335CBE1B176727EEECC23214017F9E0972BE7A07A4808A16BB576CB3D9C13685051D - Submitted as: 4b4af0c83f3c3e54e61afda0703eb5dcef5bf09fc733412e7b00661cd8d8fce1
- File type: pe · Size: 48962 bytes
- Verdict: malicious (99/100) · Family: Nevereg
Detections (5 of 56 engines)
- ClamAV (daily): Win.Malware.Nevereg-9916351-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Worm:Win32/Nevereg!pz
- Trellix Stinger (McAfee): Dropper-FZS!77C5A48BB3B4
- Kaspersky (KVRT): Email-Worm.Win32.Nevereg
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Malware.Nevereg-9916351-0 (rule
Win.Malware.Nevereg-9916351-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Worm:Win32/Nevereg!pz (rule
Worm:Win32/Nevereg!pz) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Dropper-FZS!77C5A48BB3B4 (rule
Dropper-FZS!77C5A48BB3B4) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Email-Worm.Win32.Nevereg (rule
Email-Worm.Win32.Nevereg) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Contacted 9 external host(s) and 14 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
1849 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- 85.52.40.23.in-addr.arpa.
- ecs.office.com
- update.googleapis.com
- desktop-hsgcbep
- self.events.data.microsoft.com
- ctldl.windowsupdate.com
- login.live.com
- settings-win.data.microsoft.com
- 166.142.190.20.in-addr.arpa
- 1.0.240.10.in-addr.arpa
- 40.85.84.40.in-addr.arpa
- 85.52.40.23.in-addr.arpa
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 92.223.78.30
- 40.84.85.40
- 135.233.95.144
- 4.150.223.101
- 20.42.179.192
- 4.150.223.107
- 52.123.129.14
- 52.168.112.67
- 13.89.179.15
- 4.150.223.115
- 52.148.114.188
- 72.145.35.97
- 72.145.35.102
- 20.42.65.91
- 52.110.12.20
- 4.230.171.124
- 52.253.84.76
- 4.150.223.110
- 74.179.77.204
- 57.155.104.224
- 20.184.175.22
More Nevereg samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report