MALICIOUS — 4f85aac69f12c2faca087a5a90398fc81ef4714c6a51ea9ef794f25104ba8cc5
MALICIOUS — 4f85aac69f12c2faca087a5a90398fc81ef4714c6a51ea9ef794f25104ba8cc5 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Fileinfector family. 4 of 56 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
4f85aac69f12c2faca087a5a90398fc81ef4714c6a51ea9ef794f25104ba8cc5 - SHA-1:
37d6c8045dcc47f48c4c8fb94a2641a372c1ae96 - MD5:
ef513514b95abfee0c8335e2ff72c90b - imphash:
d66b543d0999c7628a55690ef9b1c96e - ssdeep:
768:JCJgi9KOCJgi9KOCJgi9KOCJgi9KOCJgi9Kb:JCeICeICeICeICeB - TLSH:
T186416372B3545ACFEDD668408C815A5D3A533EEB70FC25CCA2C255B760AEC83503A1DA - Submitted as: 4f85aac69f12c2faca087a5a90398fc81ef4714c6a51ea9ef794f25104ba8cc5
- File type: pe · Size: 189566 bytes
- Verdict: malicious (100/100) · Family: Fileinfector
Detections (4 of 56 engines)
- ClamAV (daily): Win.Malware.Fileinfector-9831622-0
- Microsoft Defender: flagged
- Trellix Stinger (McAfee): Trojan-FUGE!EF513514B95A
- Kaspersky (KVRT): Trojan.Win32.Scar.oyg
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 14 weighted signals:
- ClamAV (daily) flagged Win.Malware.Fileinfector-9831622-0 (rule
Win.Malware.Fileinfector-9831622-0) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s) across 1 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged flagged (rule
flagged) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Trojan-FUGE!EF513514B95A (rule
Trojan-FUGE!EF513514B95A) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Scar.oyg (rule
Trojan.Win32.Scar.oyg) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 1 external host(s) and 6 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497, T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://www.pinkworld.com, http://www.youporn.com, http://www.redtube.com - static signal, weight 0.35, confidence 0.60
- Dropped 24 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
91489 behavior events · 3 ATT&CK techniques · 38 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- officeclient.microsoft.com
- www.msn.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- th.bing.com
- fe3cr.delivery.mp.microsoft.com
Dropped files
- C:\Windows\System32\msvcp140_2.dll -
ce39a3f8352552e79ae3e672fc686fc65bccccf8c95507b631d666ccb87f7c03 - C:\Windows\SysmonDrv.sys -
5e21365671915fe4398cc39f54923c268f2e20a0e404321afd98f9d73aaabd8c - C:\Windows\System32\mfcm140u.dll -
f0f3396f0d0b8f3dd43a9011a171ec3cec4ad73b8b6b0fc5aa2bb3917f973998 - C:\Windows\System32\opencl.dll -
f03f0536968d439b2ef5230f3ee616eb38f31d4c58a9e0eb74fc8a5f46076ad8 - C:\Windows\System32\crAcker.exe -
4ab8e9cb58fbee2b26c29d61631c9b25a91e29500b4d1578b115a7f3f5546177 - C:\Windows\pyshellext.amd64.dll -
f9d7334cedb6e904e90b3883076eed2b5c98aa71daa180d15cd0944c4a1c579a - C:\Windows\System32\vccorlib140.dll -
1c2b311003f80424db98efb3d2e9afdc46963fc407c146e33d994cb1ff3a69c9 - C:\Windows\System32\msvcp140.dll -
f4c746e47450132b843ad4da44da361d45574d3624df46d7c02ac78876c5f7f7 - C:\Windows\System32\dssec.dat -
b6d12c789e84a7f030cc8f3121765bfc91570bb73c91fdfbc86e9ccd3b051929 - C:\Windows\WindowsUpdate.log -
09596b9eb91cca628e71a9f210cb421ca7ea4706e19a06e1987e57f4492b5483 - C:\Windows\setuperr.log -
a62c5e3036be2e88945076087d52e6b996c9d83a9fab5a54ce2821eabb07e447 - C:\Windows\lsasetup.log -
507c1c0472d7af7466c9568223fa952238e2957171ddc58c3ca81e38b2735fe3 - C:\Windows\System32\mfc140u.dll -
d2002a30e94cbbad7bf3f79299930689003eb4691d0265a693645ec88c55166d - C:\Windows\DtcInstall.log -
14d260591cb48e519d70095df1a96baecb0cff0d96cc539d77c3406193e776a2 - C:\Windows\System32\mfc140.dll -
6a3bc032eb3d0ab7818a250f4f5f51dccc471277ae98788a4d6fdc92522fe520
Embedded URLs
- http://www.pinkworld.com
- http://www.youporn.com
- http://www.redtube.com
- http://www.assparade.com/
- http://www.freeav.com/
- http://www.antispyware.com/
- http://www.antivirus.com/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- www.pinkworld.com
- www.youporn.com
- www.redtube.com
- www.assparade.com
- www.freeav.com
- www.antispyware.com
- www.antivirus.com
Embedded IP addresses
- 4.150.223.108
- 57.154.63.210
- 20.247.185.124
- 4.230.171.124
- 4.247.188.224
- 74.178.240.51
- 20.184.175.15
- 135.233.95.144
- 172.64.154.167
- 135.232.92.137
- 162.159.142.9
- 52.110.12.26
- 52.110.12.20
- 172.178.240.163
- 52.178.17.232
- 72.145.35.103
- 52.148.114.188
- 104.208.16.94
- 52.110.12.11
- 52.110.12.44
Registry keys
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl]
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Themes!Start]
- HKEY_CURRENT_USER\Control
- HKEY_CLASSES_ROOT\AppID\{48da6741-1bf0-4a44-8325-293086c79077}!DllSurrogate]
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ACPI
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced!Start_SearchFiles]
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartMenu\StartPanel\SearchFiles\FullIndex!DefaultValue]
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartMenu\StartPanel\SearchFiles\NoSearch!DefaultValue]
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartMenu\StartPanel\SearchFiles\UserOnly!DefaultValue]
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NDIS\Parameters]
More Fileinfector samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report