MALICIOUS — 4e56fbd1290a16b015bf8442eb774d4350b38ecb7cd48572298d4aae01475e10
MALICIOUS — 4e56fbd1290a16b015bf8442eb774d4350b38ecb7cd48572298d4aae01475e10 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the Crypted family. 6 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
4e56fbd1290a16b015bf8442eb774d4350b38ecb7cd48572298d4aae01475e10 - SHA-1:
2cf6d7e8ff11011123656a456f9ca1883d48b575 - MD5:
3e44e7e7b1ae71943cf8a38d11c9a4e2 - imphash:
c2a87fabf96470db507b2e6b43bd92eb - ssdeep:
6144:ydByb5EAe0vPsoCoxBZ9mANb5EAe0vPsoCo:ypAdPsoHBEAdPso - TLSH:
T18E435A97D585894BECE092D94098FDBFC290C0512D78CBD707D7AA960B4B487E62B38C - Submitted as: 4e56fbd1290a16b015bf8442eb774d4350b38ecb7cd48572298d4aae01475e10
- File type: pe · Size: 229376 bytes
- Verdict: malicious (93/100) · Family: Crypted
Detections (6 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): Win.Trojan.Crypted-29
- Microsoft Defender: Backdoor:Win32/Berbew!pz
- Emsisoft (Emergency Kit): GenPack:Generic.Dacic.1.Backdoor.Hangup.A.8D3133A2
- Trellix Stinger (McAfee): Trojan-FUGH!3E44E7E7B1AE
- Kaspersky (KVRT): Trojan-Proxy.Win32.Qukart.vjh
MITRE ATT&CK
Why this verdict
The malicious score of 93/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypted-29 (rule
Win.Trojan.Crypted-29) - engine signal, weight 0.90, confidence 0.95 - Contacted 25 external host(s) and 21 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
- Dropped 98 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
3088 behavior events · 1 ATT&CK techniques · 98 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Dropped files
- C:\Windows\System32\Mmpjlk32.exe -
cfa2a2a328a6f4e29fe7dff5c700ffc0acf4031b53f1823b8b47aa528fef9dee - C:\Windows\System32\Glgpdbil.exe -
b20a46db722215458747bde05cf465e6fded62f8d429a956ac9b941dd4ab528f - C:\Windows\System32\Odnjma32.dll -
a585cca3c5b764127422c3c44debf9058dd846ad1a9ac4d51900584bf4993f9e - C:\Windows\System32\Jdagdn32.exe -
ef3db532af8a2642263ede738967f1bae5d17d968ba27dba35fb3270c29a4948 - C:\Windows\System32\Abfoeohi.dll -
6a01fc0a5a2409ee09771b70d4e7ebea0bc486a46472defcf1146eee2a5298a2 - C:\Windows\System32\Qobdkieo.dll -
4993349af27d7bde09b5db43dc75e3cf1052f190fe8b9f19f214392609e679fc - C:\Windows\System32\Nqmhbhif.dll -
a27c83caff7fcc0fb659ff2afdafe89efc7445c8eb55f5533e528d771e11743e - C:\Windows\System32\Ponchpbm.exe -
4c7fd33238603e19ff0c29628baf9834176fd5d73108bb14bcebae063e728a68 - C:\Windows\System32\Dobgmj32.dll -
c8dcb0b8a094315b0e1199294766fc963e202f1e5da1274eb22e208d8941f3b9 - C:\Windows\System32\Kqkkna32.exe -
17938d0376f6614e6e27829e401e1dc926e44b6a27c7baf01565efda134ea8fa - C:\Windows\System32\Dfgpcg32.exe -
7f1c23d0236adb9c809239010a4dab6ddb766be0cd926ebe55f675dac42163d6 - C:\Windows\System32\Hoecomob.dll -
4e1516526a12786383b35e7b6a4407b40eca9152009539851ee09a45b8eb57a4 - C:\Windows\System32\Clgcef32.exe -
e7dcb94eebf939d891983da525388071e2176388067766660fbf06bfa423b5cd - C:\Windows\System32\Llgclg32.dll -
d4e42b0ef8c220cadaf51ff5f108fad598efd39ccb84b07374dd772b16eef1ad - C:\Windows\System32\Bbcopb32.exe -
cea023e2a6486dd37372fb0eb75602186a5ad9d4063a6162fb078bcd7b55d362
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9?P1=1787946363&P2=404&P3=2&P4=dRWF%2byKbYYCY48GblNttM3HoDzESsfutkE%2bBR%2bl8z4r3I0siQPPINFJdfx4yvqbQgdky%2fWUmD7kPNE4NTYhbjg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787946392&P2=404&P3=2&P4=UGdioOa0UYIqAhB4bfyDdqhFDyBNCGRNpjtWaxM%2f7RBpnjk4G3drZtIutGkTHv3IVOSbGqjvr0PsuE6MDodTXA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 20.184.175.9
- 4.230.171.124
- 20.247.184.197
- 172.215.188.225
- 74.178.240.61
- 135.233.95.135
- 20.42.73.25
- 20.76.201.171
- 52.123.129.14
- 52.123.128.14
- 4.150.223.101
- 172.178.240.161
- 203.26.79.13
- 52.123.252.236
- 20.165.94.46
- 20.42.179.192
- 52.110.12.18
- 52.148.114.188
- 52.110.12.54
- 52.123.252.245
- 72.145.35.110
- 172.178.240.163
- 92.223.78.30
- 52.110.12.55
- 52.110.12.47
More Crypted samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report