MALICIOUS — 5e0bffb9f65c10f473634669b9768e6ad841aa5d009400b12faeee9e09722f72
MALICIOUS — 5e0bffb9f65c10f473634669b9768e6ad841aa5d009400b12faeee9e09722f72 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Picsys family. 6 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
5e0bffb9f65c10f473634669b9768e6ad841aa5d009400b12faeee9e09722f72 - SHA-1:
d66286fa93786e8deaf4eb21653ae230b9660346 - MD5:
c448ad3ba7193ed6ce8b6430aa949450 - imphash:
359d89624a26d1e756c3e9d6782d6eb0 - ssdeep:
1536:y4QQ6NSyM61l19piO+LV8YEoI/EU9RUe4mVm4waQXYOYf8aT:y4X6NSyfnpijeYEoIcq4Om1XYgaT - TLSH:
T1E83802D864013C68EDAF88A95C9FC6BE48CAA21D12AB7B0D9DC97125102D05FE8717CD - Submitted as: 5e0bffb9f65c10f473634669b9768e6ad841aa5d009400b12faeee9e09722f72
- File type: pe · Size: 79558 bytes
- Verdict: malicious (100/100) · Family: Picsys
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Worm.Picsys-6804101-0
- Detect It Easy (packer/type): DIE:Turbo Linker
- Microsoft Defender: Worm:Win32/Yoof!pz
- Trellix Stinger (McAfee): W32/Picsys.worm!4F37C7C21D88
- Kaspersky (KVRT): P2P-Worm.Win32.Picsys.b
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Worm.Picsys-6804101-0 (rule
Win.Worm.Picsys-6804101-0) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s) across 1 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged Worm:Win32/Yoof!pz (rule
Worm:Win32/Yoof!pz) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged W32/Picsys.worm!4F37C7C21D88 (rule
W32/Picsys.worm!4F37C7C21D88) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged P2P-Worm.Win32.Picsys.b (rule
P2P-Worm.Win32.Picsys.b) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 1 external host(s) and 22 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 a#¤, Turbo Linker - static signal, weight 0.25, confidence 0.55
- Dropped 25 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
128 behavior events · 1 ATT&CK techniques · 27 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- v7x3a5l9.hypermart.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
Dropped files
- C:\Windows\System32\macromd\msncracker.exe -
5f912a44c063f84a54edcddf165430ecf087832270aa1f2b2c8dd482aa3bc8c2 - C:\Windows\System32\macromd\chubby girl fucked from all angles xxx.exe -
de37355e7398cd622f891ef3cd3a5b505c732d866542750122a99537600f0abc - C:\Windows\System32\macromd\Teen Violent Forced Gangbang.exe -
a1081a3cc2cde7348081ea8898721bb86fc65c2f76995a52ad38cb89bcfe122e - C:\Windows\System32\macromd\illgal incest preteen porn cum.mpg.exe -
6f363580a79ff25bafa44b88b99164eb9d1eb33b4cf55897236679875f886280 - C:\Windows\System32\macromd\15 year old on beach.mpg.exe -
64f743e3f3f4d681e27754e8e3e52d5e09042b14f4c799937c9ae7b5266d811e - C:\Windows\System32\macromd\Harry Potter and the sorcerors stone.divx.exe -
cf3028bb738d48c421edc725ca562f9a75f6e0cb0c05d1485b1bd76a283080c1 - C:\Windows\System32\macromd\ICQ Hackingtools.exe -
803ecfc4b966718d2084d79420aba40fd0ec5678d36baf0ebffbb6f39c09a8ca - C:\Windows\System32\macromd\Want to see a massive horse cock in a tight little teen's pussy.mpg.pif -
2b48ad28b55c2aa680a1b12634cbcbb12663fa08ddfce14b57f8588f3dd828b7 - C:\Windows\System32\macromd\nikki nova sex scene huge dick blowjob.mpg.exe -
d863fff74600cae9d7cfbd02695c8e3051736a01adcf2625c00991aee71f712a - C:\Windows\System32\macromd\Website Hacker.exe -
51363d1a15502ed3914953e239b3b90c03fafbf0cec271780ee21f2b85976316 - C:\Windows\System32\macromd\Pamela Anderson And Tommy Lee Home Video (Part 1).mpg.exe -
6b96a068a83be70c0d7a9e10a47ab43889fd311ec3d0ef42206d1e56356be96f - C:\Windows\System32\macromd\Counter Strike CD Keygen.exe -
9b2407c9f2ea4a458a7cf627c58b1e23c36898519bbd54a3ef938efb354ce4c2 - C:\Windows\System32\macromd\16 year old webcam.mpg.exe -
230f51f71a9bcfceee6aca815bf3770567c4b1bb0d794690f3b697926f489dbf - C:\Windows\System32\macromd\virtua girl - adriana.pif -
f53ba36ccafb0ae67004cb48b92bcb62f68b2a245f8e72b43b1a9a242787e857 - C:\Windows\System32\macromd\GTA 3 Crack.exe -
9b47adfaa962ca4732ab8545abf07224853668837969b8e06298e452ec5546f1
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- http://c.pki.goog/r/gsr1.crl
- http://c.pki.goog/r/r4.crl
- http://v7x3a5l9.hypermart.net/cgi-bin/w.cgi?192.168.122.112A2645B8286C9307D17257756E3F0
Embedded domains
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- v7x3a5l9.hypermart.net
Embedded IP addresses
- 13.89.179.12
- 20.247.184.142
- 4.230.171.124
- 57.154.63.210
- 135.233.95.144
- 20.184.175.15
- 74.178.76.54
- 4.207.44.76
- 20.184.175.6
- 52.168.117.168
- 172.66.2.5
- 92.223.78.30
- 52.123.252.234
- 172.64.154.167
- 38.113.1.151
- 72.154.7.98
- 52.148.114.188
- 52.110.12.49
- 52.110.12.20
More Picsys samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report