MALICIOUS — 57a8f2d6b5ff73777f118624e66ab433fbefeaf7af74d14fb4240b2035115de1
MALICIOUS — 57a8f2d6b5ff73777f118624e66ab433fbefeaf7af74d14fb4240b2035115de1 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the PolyRansom family. 6 of 56 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
57a8f2d6b5ff73777f118624e66ab433fbefeaf7af74d14fb4240b2035115de1 - SHA-1:
be164dc311b67c020e9d859d76e0c3737ddaf858 - MD5:
c17bbb7100d39423f03275ebaa7ff6f5 - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
3072:EVjRSxgZYyxvafWVr1wVRE9diE8KPDWPJX+7JaTOIkOW03Fvs2PNd:qjRSgZYyUfFgcX+COgW03Fvs2PNd - TLSH:
T11B413A91045E0CFE9BDAB0113F70963D7B418A2F0B663548DD4122EAC6292AFC6B4D5B - Submitted as: 57a8f2d6b5ff73777f118624e66ab433fbefeaf7af74d14fb4240b2035115de1
- File type: pe · Size: 189952 bytes
- Verdict: malicious (100/100) · Family: PolyRansom
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): BC.Win.Virus.Ransom-9157.A
- Microsoft Defender: Virus:Win32/Nabucur.A
- Emsisoft (Emergency Kit): Win32.Virlock.Gen.4
- Trellix Stinger (McAfee): W32/VirRansom
- Kaspersky (KVRT): Virus.Win32.PolyRansom.a
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 15 weighted signals:
- ClamAV (daily) flagged BC.Win.Virus.Ransom-9157.A (rule
BC.Win.Virus.Ransom-9157.A) - engine signal, weight 0.90, confidence 0.95 - 2 behavioral detection(s) across 2 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.63, confidence 0.90 - Memory forensics: 2 finding(s) attributed to the sample across 1 technique(s), e.g. RWX/private injected region in vcIYEIkQ.exe (pid 9180) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Virus:Win32/Nabucur.A (rule
Virus:Win32/Nabucur.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Virlock.Gen.4 (rule
Win32.Virlock.Gen.4) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged W32/VirRansom (rule
W32/VirRansom) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.PolyRansom.a (rule
Virus.Win32.PolyRansom.a) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 3 external host(s) and 7 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-sections:.text (rule
high-entropy-sections:.text) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
- Dropped 16 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. RWX/private injected region in vcIYEIkQ.exe (pid 2356) (rule
windows.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
16054 behavior events · 3 ATT&CK techniques · 33 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- google.com
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
- licensing.mp.microsoft.com
- www.bing.com
- fe3cr.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\rAIEwQkM.bat -
e4bab86604904338a7b590fc7a5b7f7c9626acd11e81fc7933a55897273bec11 - C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png.exe -
bd00f291c91137deb53d495d286f2d9b88cb2b00501bd5cd7c1d3f1a213b16f5 - C:\Users\analyst\AppData\Local\Temp\tsk_45b773856d7b421d -
b4d63843e206503fc2135cd719ba9f956e88ac604c7d34d700e59cd95c04f395 - bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 -
bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 - C:\Users\analyst\AppData\Local\Temp\lgwcEQwE.bat -
7eb0e2e73c88d8d76f8ecd50abde8641742d73e35d6680663b6c67da4dba2355 - C:\ProgramData\xiocAsMc\yKgEskQE.inf -
ee961f970a26219dfb90f4e957c7264c4a8daa003fcc585b1b6e158818dd8e0d - C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.exe -
5bdd99a3fedd6c8479baca9a647f7da0c090f400c6a5314322035634b08857c3 - C:\Users\analyst\AppData\Local\Temp\XkYoowUY.bat -
f2f2a3305fecec1316c9f7b6445fb82a2d1c70a415872308abb0d82feab5acd1 - C:\ProgramData\xiocAsMc\yKgEskQE.exe -
1d49d4794582f67b76349c74ecb71195548a7707534dd25bfe730ac03750e2da - C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png.exe -
57d6d7ff13e91f3cea90d4311e139cedb06e09f0e17717aebffd2af3066526f0 - C:\Users\analyst\rSwIoccE\vcIYEIkQ.exe -
27c30b5a3f41d7d9860c63be1a5f22308146899186c0d784f4992c7d8b985736 - C:\Users\analyst\AppData\Local\Temp\yUQy.ico -
bcb253ea3735a0cf0a8c6ee06c14c884937c64ddeacedb17240e40d403577620 - C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png -
d3e8d47e8c1622ec10adef672ca7a8992748c4f0a4e75f877462e7e661069698 - C:\Users\analyst\AppData\Local\Temp\oEwsoUAU.bat -
0245b7f2040522793f4ad8edc568d6feae746fc52854c3fce5ea724a309e51e1 - C:\Users\analyst\rSwIoccE\vcIYEIkQ -
ed546affb4adae23597f72a1e76c8edd5c6d64543067c0a03f1e792fcf8291a7
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://google.com/
Embedded IP addresses
- 4.150.223.104
- 52.123.252.216
- 4.230.171.124
- 57.154.63.210
- 4.144.132.114
- 4.247.188.233
- 74.178.76.54
- 20.42.73.30
- 135.233.95.144
- 52.168.112.67
- 200.87.164.69
- 200.119.204.12
- 190.186.45.170
- 20.42.179.204
- 52.148.114.188
- 135.234.160.246
- 52.110.12.42
- 52.110.12.50
- 72.145.35.102
More PolyRansom samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report