MALICIOUS — 4fdacfdd38da97e267ec8990e8aed569440dfcafdafcafd62e9b01394dc8d3d3
MALICIOUS — 4fdacfdd38da97e267ec8990e8aed569440dfcafdafcafd62e9b01394dc8d3d3 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the Blocker family. 6 of 52 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
4fdacfdd38da97e267ec8990e8aed569440dfcafdafcafd62e9b01394dc8d3d3 - SHA-1:
fe3f3145fe820bab87047811667f8170756d1ad8 - MD5:
8014ec34e9b460e1dbc214b095dc60c4 - imphash:
ea28f662ab831803e9a8c823439760d0 - ssdeep:
6144:/t8IhVYFVED7l08BkjIf0r9b5if7/F0ZiCs+9O8IKOCzHDA6qMwfuNvE:/t8vVED3Bk0Mr9Vif7/F1hIIabDA6JI1 - TLSH:
T11346CF794A083399CCA0FE54CC3A69BE5F3A2DA65BB7134D3E5B5039D980943C06E097 - Submitted as: 4fdacfdd38da97e267ec8990e8aed569440dfcafdafcafd62e9b01394dc8d3d3
- File type: pe · Size: 309637 bytes
- Verdict: malicious (95/100) · Family: Blocker
Detections (6 of 52 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Trojan.Blocker-391
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- Kaspersky (KVRT): Trojan-Ransom.Win32.Blocker.jgb
- Microsoft Defender: Worm:Win32/Drolnux!pz
- Trellix Stinger (McAfee): W32/Worm-FFX!8014EC34E9B4
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Blocker-391 (rule
Win.Trojan.Blocker-391) - engine signal, weight 0.90, confidence 0.95 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://www.ibayme.eb2a.com/dwn.dmp, http://www.ibayme.eb2a.com/ad.php, 1.9.0.5 - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://www.ibayme.eb2a.com/dwn.dmp
- http://www.ibayme.eb2a.com/ad.php
Embedded domains
- www.ibayme.eb2a.com
- s.com
Embedded IP addresses
- 1.9.0.5
Registry keys
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
File paths
- c:\windows\system32\syssh32.dll
- C:\RECYCLER\bilbilal.exe
- C:\MusicMP3
- c:\WINDOWS\system32\shell32.dll
More Blocker samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report