MALICIOUS — 5ec09f8cfbe1097280ce6e47dda459f2d9aeb1865a4ac59848aac7e2b33f6e6c
MALICIOUS — 5ec09f8cfbe1097280ce6e47dda459f2d9aeb1865a4ac59848aac7e2b33f6e6c is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Seraph family. 3 of 56 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
5ec09f8cfbe1097280ce6e47dda459f2d9aeb1865a4ac59848aac7e2b33f6e6c - SHA-1:
8f4df4c370b48f5c28c0de6eaba5a2aeac55d7c8 - MD5:
f2a2898461c39c2556038944df785676 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
6144:U1UPD+GZ6hb3qs3udb2wlsCgr+3W6agPimsZWDfQwPjjhqb7/gVIqRd+:QTGZUb3biSwlXgr+MgqmJjhqb7/0 - TLSH:
T1ED4C4A5791349495D8D9B5C03803876CB9878C3F443A1FAEC5858F1A61EEEBB4B2DA30 - Submitted as: 5ec09f8cfbe1097280ce6e47dda459f2d9aeb1865a4ac59848aac7e2b33f6e6c
- File type: pe · Size: 539136 bytes
- Verdict: malicious (100/100) · Family: Seraph
Detections (3 of 56 engines)
- ClamAV (daily): Win.Packed.njRAT-9938210-1
- Emsisoft (Emergency Kit): Trojan.Agent
- Kaspersky (KVRT): HEUR:Trojan-Downloader.MSIL.Seraph.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Win.Packed.njRAT-9938210-1 (rule
Win.Packed.njRAT-9938210-1) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 2 finding(s) attributed to the sample across 2 technique(s), e.g. process hollowing in RegAsm.exe (pid 1720) (rule
windows.hollowprocesses.HollowProcesses) - memory signal, weight 0.75, confidence 0.85 - 2 behavioral detection(s) across 2 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.63, confidence 0.90 - Emsisoft (Emergency Kit) flagged Trojan.Agent (rule
Trojan.Agent) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan-Downloader.MSIL.Seraph.gen (rule
HEUR:Trojan-Downloader.MSIL.Seraph.gen) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 3 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- Extracted AsyncRAT config (0 C2) - engine signal, weight 0.45, confidence 0.60
- Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
11757 behavior events · 1 ATT&CK techniques · 17 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- odc.officeapps.live.com
- www.msn.com
- assets.msn.com
- www.bing.com
- g.live.com
- oneclient.sfx.ms
- ecs.office.com
- edge.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\RegAsm.exe -
3ca2e12301fdc8fd4db6cf25674d0762e0c0bc5f71f900699d74b1fadb64c984 - 46907ab4ff3a6b71d7a55cd0f7378596a87d0550eab4d2b8006ca71ac344efef -
46907ab4ff3a6b71d7a55cd0f7378596a87d0550eab4d2b8006ca71ac344efef - 259e293ae34ae346b26403dff78ac4296a25e3400bae5c4dfabd33016e5ae5f2 -
259e293ae34ae346b26403dff78ac4296a25e3400bae5c4dfabd33016e5ae5f2 - 09c2330ddeaba131210771214bb39b3397fcc9d7a7d3dd3b2c154c8f8b102b2a -
09c2330ddeaba131210771214bb39b3397fcc9d7a7d3dd3b2c154c8f8b102b2a - ce3163666fc2cad7e859f74c010166aba7619bcaa2766490ecd7fe14575c6c9c -
ce3163666fc2cad7e859f74c010166aba7619bcaa2766490ecd7fe14575c6c9c - 403eb07dd104babaab6cdd59c325e4a44b8dbbdff92d905a441e701a0d7f2106 -
403eb07dd104babaab6cdd59c325e4a44b8dbbdff92d905a441e701a0d7f2106 - 722710598d1ae3437fa0095b1c26d15830ea5d05062af0c03b4416b64f75b31b -
722710598d1ae3437fa0095b1c26d15830ea5d05062af0c03b4416b64f75b31b - 9a9a2033d78fad898dd8ecf510b6855a32b47b2f802abc62bb8c9c8ff87edb7e -
9a9a2033d78fad898dd8ecf510b6855a32b47b2f802abc62bb8c9c8ff87edb7e - 63bbcbb59f71f13091c37d419bf74d93cc6de0e84898135cd785d2877c5843e1 -
63bbcbb59f71f13091c37d419bf74d93cc6de0e84898135cd785d2877c5843e1 - 29e02170c199a660bb9c6955abc62ab4e7e47543e26f8244261116a96ba6f654 -
29e02170c199a660bb9c6955abc62ab4e7e47543e26f8244261116a96ba6f654 - 27f944917db46b7302473bafd0a1e61eb58df6634b4c81c631f9b396822823a7 -
27f944917db46b7302473bafd0a1e61eb58df6634b4c81c631f9b396822823a7 - 08c488e0c52061b1731ef51d2cf17cab8eb044c94c88c2850332aa957d997ff2 -
08c488e0c52061b1731ef51d2cf17cab8eb044c94c88c2850332aa957d997ff2 - 059a3846e884223eaed2858209aeb991c8cf7bb2fc269598ff652e4159343f3a -
059a3846e884223eaed2858209aeb991c8cf7bb2fc269598ff652e4159343f3a - 7ed42710f7849d3b7f243eb8d08ed588e69d3498f5305339018649188813b861 -
7ed42710f7849d3b7f243eb8d08ed588e69d3498f5305339018649188813b861 - 27e9d25f49ca0c81b619a02c19756691a06042f2ba61a854a8071c5daaa50fff -
27e9d25f49ca0c81b619a02c19756691a06042f2ba61a854a8071c5daaa50fff
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://schemas.microsoft.com/SMI/2016/WindowsSettings
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- schemas.microsoft.com
- oneclient.sfx.ms
Embedded IP addresses
- 0.0.0.4
- 0.0.0.61
- 0.0.0.1
- 0.0.5.3
- 52.110.12.19
- 20.52.64.200
- 20.247.185.124
- 52.110.12.33
- 4.230.171.124
- 217.64.149.101
- 52.123.128.14
- 172.215.188.232
- 52.110.12.24
- 52.148.114.188
- 52.110.12.30
- 72.153.5.128
More Seraph samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report