MALICIOUS — 572fbcc2f146ae25d1e8f0c00ca72c98f3c6603e0909c9080776a052ef625d81
MALICIOUS — 572fbcc2f146ae25d1e8f0c00ca72c98f3c6603e0909c9080776a052ef625d81 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the RedLine family. 4 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
572fbcc2f146ae25d1e8f0c00ca72c98f3c6603e0909c9080776a052ef625d81 - SHA-1:
8e7617af23dfeec8216fba76a1e244dcaac0dcc7 - MD5:
968a818bfa455984c7dd78d041c07372 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
6144:jeGseZNqkNj8C7UmgX93JdkGap8G3TBqhp57lXb00sr:yvMqIj97Umo93JdkOY0sr - TLSH:
T12347539A8A6C6C55CCBF815F1BBD8D4B45EB92EC5F73760E022C04714AA423B8B21177 - Submitted as: 572fbcc2f146ae25d1e8f0c00ca72c98f3c6603e0909c9080776a052ef625d81
- File type: pe · Size: 336792 bytes
- Verdict: malicious (100/100) · Family: RedLine
Detections (4 of 56 engines)
- LIEF (executable format parser): lief:invalid-authenticode
- Emsisoft (Emergency Kit): IL:Trojan.MSILZilla.9531
- Trellix Stinger (McAfee): AgentTesla-FDDZ!968A818BFA45
- Kaspersky (KVRT): UDS:Trojan-Spy.MSIL.Stealer.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- Extracted RedLine config (1 C2) - engine signal, weight 0.80, confidence 0.90
- Memory forensics: 1 finding(s) attributed to the sample across 1 technique(s), e.g. process hollowing in tsk_f798eb379d (pid 5780) (rule
windows.hollowprocesses.HollowProcesses) - memory signal, weight 0.70, confidence 0.85 - Emsisoft (Emergency Kit) flagged IL:Trojan.MSILZilla.9531 (rule
IL:Trojan.MSILZilla.9531) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged AgentTesla-FDDZ!968A818BFA45 (rule
AgentTesla-FDDZ!968A818BFA45) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:Trojan-Spy.MSIL.Stealer.gen (rule
UDS:Trojan-Spy.MSIL.Stealer.gen) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 1 external host(s) and 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
5893 behavior events · 2 ATT&CK techniques · 13 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- aefd.nelreports.net
- settings-win.data.microsoft.com
- edge.microsoft.com
- watson.events.data.microsoft.com
Dropped files
- 5d1a24a6d7fb9bda2961dacd85272b625571e79d1700709a3305c59be4bffcd9 -
5d1a24a6d7fb9bda2961dacd85272b625571e79d1700709a3305c59be4bffcd9 - 66d7cdee074890a05d4666b57dca76f7b1588dea47b67b5fd35d33108b180aa2 -
66d7cdee074890a05d4666b57dca76f7b1588dea47b67b5fd35d33108b180aa2 - c2cd767ad89f3b3dc61e1930e294388f8a9d480ab1590257ac95283aec231fe8 -
c2cd767ad89f3b3dc61e1930e294388f8a9d480ab1590257ac95283aec231fe8 - b1b170af8963f30bd8d009901061e1887c590b43cc644dcf8d0e23dff0801046 -
b1b170af8963f30bd8d009901061e1887c590b43cc644dcf8d0e23dff0801046 - ca1c3761737ac4ad7602ec98d4624ba4d6e8b1014397d62b55dde8246c410015 -
ca1c3761737ac4ad7602ec98d4624ba4d6e8b1014397d62b55dde8246c410015 - a74f2c025c20ec9ef97267f1f5d2e3a07aff50e4fb53d0285423ad92a9c976e0 -
a74f2c025c20ec9ef97267f1f5d2e3a07aff50e4fb53d0285423ad92a9c976e0 - 5ec6c45b190639a4ef20e63f2b8611e394b9fd99c8afaebdf13e0cf0c0cb8a8f -
5ec6c45b190639a4ef20e63f2b8611e394b9fd99c8afaebdf13e0cf0c0cb8a8f - 2c14e640b6ff78f04bb9d343255d3b5ddb7c01b48afbdc1df17c194e0ba9cf6b -
2c14e640b6ff78f04bb9d343255d3b5ddb7c01b48afbdc1df17c194e0ba9cf6b - 774965e45a5a5de31399197f3efc5014ccf911030548810c443f396e5957790d -
774965e45a5a5de31399197f3efc5014ccf911030548810c443f396e5957790d - def99639b1a15c4780680dbe5f3313512f6716d38c67aa462a466ec37ab27d30 -
def99639b1a15c4780680dbe5f3313512f6716d38c67aa462a466ec37ab27d30 - a9127fc8a80497894ba0d216aa59985036a2ab1462b2a9cbd7df3be0d5988c89 -
a9127fc8a80497894ba0d216aa59985036a2ab1462b2a9cbd7df3be0d5988c89 - 12cb13016783dc3782a51465b97dbe460f622b3ecd4742c6e15e328504b0de12 -
12cb13016783dc3782a51465b97dbe460f622b3ecd4742c6e15e328504b0de12 - dba7b21781b22f410525bec95a7291f1d8faef4f0fd559d0e10a82372c7503a0 -
dba7b21781b22f410525bec95a7291f1d8faef4f0fd559d0e10a82372c7503a0
Embedded URLs
- http://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
- https://www.digicert.com/CPS0
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- www.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- cacerts.digicert.com
- aefd.nelreports.net
Embedded IP addresses
- 20.42.65.85
- 52.253.84.76
- 52.123.252.212
- 4.230.171.124
- 80.85.138.229
- 172.215.188.225
- 135.233.45.223
- 172.215.188.232
- 184.84.165.136
- 72.153.5.128
- 52.148.114.188
- 52.110.12.47
- 52.110.12.37
More RedLine samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report