MALICIOUS — 5b70f56221dab86139bca9fbf02ded70bac00dee5aff8e854ffc4c1ae8424de1
MALICIOUS — 5b70f56221dab86139bca9fbf02ded70bac00dee5aff8e854ffc4c1ae8424de1 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the Python family. 4 of 56 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5b70f56221dab86139bca9fbf02ded70bac00dee5aff8e854ffc4c1ae8424de1 - SHA-1:
ee897ff541f314c2d950685929d6844fe2fd73de - MD5:
2eb6793bee948a44713871b7247452d5 - imphash:
3f34dc1401b498affe4f4057d6ccbb64 - ssdeep:
196608:FVpK9xzn/RNrlHAjoG+II9onJ5hrZEKte9tGPqKNkSEaTbBuF9egxcw9Nq:NK9xbZxlHOFI9c5hlEKdPN/v3OegL9 - TLSH:
T18E693306422323F2E7FAF9215D855CCCC973F11EBCB0E1295A83D95D20D5837A6B261A - Submitted as: 5b70f56221dab86139bca9fbf02ded70bac00dee5aff8e854ffc4c1ae8424de1
- File type: pe · Size: 8382704 bytes
- Verdict: malicious (91/100) · Family: Python
Detections (4 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): Microsoft Visual C/C++
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:Microsoft Visual C/C++
- Kaspersky (KVRT): HEUR:Trojan.Python.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 91/100 is the fusion of 8 weighted signals:
- Kaspersky (KVRT) flagged HEUR:Trojan.Python.Agent.gen (rule
HEUR:Trojan.Python.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Contacted 2 external host(s) and 4 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:Microsoft Visual C/C++ (rule
DIE:Microsoft Visual C/C++) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged Microsoft Visual C/C++ (rule
Microsoft Visual C/C++) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Microsoft Visual C/C++ - static signal, weight 0.25, confidence 0.55
- Dropped 30 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
1438 behavior events · 0 ATT&CK techniques · 30 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- settings-win.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- officeclient.microsoft.com
- windows.msn.com
- odc.officeapps.live.com
- www.msn.com
- assets.msn.com
- www.bing.com
- th.bing.com
- fe3cr.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\_MEI14802\api-ms-win-core-datetime-l1-1-0.dll -
3b68d7ab0641de6b3e81d209b7c0d3896e4ffa76617bbadd01eb54036cdd1b07 - C:\Users\analyst\AppData\Local\Temp\_MEI14802\api-ms-win-core-file-l1-1-0.dll -
56de091efe467fe23cc989c1ee21f3249a1bdb2178b51511e3bd514df12c5ccb - C:\Users\analyst\AppData\Local\Temp\_MEI14802\api-ms-win-core-rtlsupport-l1-1-0.dll -
cdc4cfebf9cba85b0d3979befdb258c1f2cfcb79edd00da2dfbf389d080e4379 - C:\Users\analyst\AppData\Local\Temp\_MEI14802\api-ms-win-core-processenvironment-l1-1-0.dll -
ea2972fec12305825162ae3e1ae2b6c140e840be0e7ebb51a7a77b7feeda133a - C:\Users\analyst\AppData\Local\Temp\_MEI14802\api-ms-win-core-synch-l1-1-0.dll -
50a1542d16b42ecb3edc1edd0881744171ea52f7155e5269ad39234f0ea691de - C:\Users\analyst\AppData\Local\Temp\_MEI14802\api-ms-win-core-string-l1-1-0.dll -
854db7d2085caacf83d6616761d8bdcbacb54a06c9a9b171b1c1a15e7dc10908 - C:\Users\analyst\AppData\Local\Temp\_MEI14802\api-ms-win-core-libraryloader-l1-1-0.dll -
8e01eb923fc453f927a7eca1c8aa5643e43b360c76b648088f51b31488970aa0 - C:\Users\analyst\AppData\Local\Temp\_MEI14802\api-ms-win-core-console-l1-1-0.dll -
9f3608c15c5de2f577a2220ce124b530825717d778f1e3941e536a3ab691f733 - C:\Users\analyst\AppData\Local\Temp\_MEI14802\api-ms-win-core-debug-l1-1-0.dll -
55574f9e80d313048c245acefd21801d0d6c908a8a5049b4c46253efaf420f89 - C:\Users\analyst\AppData\Local\Temp\_MEI14802\api-ms-win-core-memory-l1-1-0.dll -
c2e887a17875d39099d662a42f58c120b9cc8a799afd87a9e49adf3faddd2b68 - C:\Users\analyst\AppData\Local\Temp\_MEI14802\api-ms-win-crt-heap-l1-1-0.dll -
af47aebe065af2f045a19f20ec7e54a6e73c0c3e9a5108a63095a7232b75381a - C:\Users\analyst\AppData\Local\Temp\_MEI14802\api-ms-win-crt-filesystem-l1-1-0.dll -
610332203d29ab218359e291401bf091bb1db1a6d7ed98ab9a7a9942384b8e27 - C:\Users\analyst\AppData\Local\Temp\_MEI14802\api-ms-win-core-interlocked-l1-1-0.dll -
5cd00ff4731691f81ff528c4b5a2e408548107efc22cc6576048b0fdce3dfbc9 - C:\Users\analyst\AppData\Local\Temp\_MEI14802\api-ms-win-core-localization-l1-2-0.dll -
a07cc878ab5595aacd4ab229a6794513f897bd7ad14bcec353793379146b2094 - C:\Users\analyst\AppData\Local\Temp\_MEI14802\api-ms-win-core-file-l2-1-0.dll -
1ea267a2e6284f17dd548c6f2285e19f7edb15d6e737a55391140ce5cb95225e
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- 4.ml
- 6.fi
- t.cn
- 20u.gg
- cryptography.x509.name
Embedded IP addresses
- 52.182.143.212
- 57.154.63.210
- 52.123.252.234
- 20.247.184.142
- 4.230.171.124
- 85.210.193.152
- 74.178.240.51
- 74.179.77.204
- 20.184.175.16
- 104.18.33.89
- 52.110.12.54
- 52.110.12.51
- 52.110.12.15
- 52.110.12.48
File paths
- C:\-r
- I:\L}
More Python samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report