MALICIOUS — WinAIHService.exe
MALICIOUS — WinAIHService.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Lazy family. 3 of 55 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
613dd576ff9f6b44e958e1f7df34123b1ded45aff7063577af83665d2483a32d - SHA-1:
169e170d5292837e788a83a1418a79c829e5db77 - MD5:
4c1293917a95a9be8e4ec5cbcf6f10b9 - imphash:
625d0a18dbb020bd758a0eba4f9f2fc8 - ssdeep:
98304:tXYplJMZdC1Zn3pletD1/5gVFBeG77eS:tX+JQAjZleP9G7 - TLSH:
T1946D3BDD47352EAAD8EA645868AE83CC4213F8CE1277AF08C523D57464C9173ACF9097 - Submitted as: WinAIHService.exe
- File type: pe · Size: 12544512 bytes
- Verdict: malicious (97/100) · Family: Lazy
Detections (3 of 55 engines)
- capa (capabilities): capability:execution/powershell
- ClamAV (daily): Win.Malware.Lazy-10060471-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Malware.Lazy-10060471-0 (rule
Win.Malware.Lazy-10060471-0) - engine signal, weight 0.90, confidence 0.95 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Contacted 18 external host(s) at runtime (16 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.years, http://.jpg, http://www.interpretation - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60 - Extracted generic config (2 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
177 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- config.edge.skype.com
- v20.events.data.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.years
- http://.jpg
- http://www.interpretation
- https://www.recent
- http://www.wencodeURIComponent
- http://www.icon
- http://www.hortcut
- http://www.w3.org/shortcut
- http://.css
- http://www.css
- https://aka.ms/GlobalizationInvariantMode
- http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarygroupsi
- http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlywindowsdevicegrou
- http://schemas.microsoft.com/ws/2008/06/identity/claims/primarygroupsi
- http://schemas.microsoft.com/ws/2008/06/identity/claims/rol
- http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsdevicegrou
- http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsuserclai
- http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nam
- http://www.w3.org/2001/XMLSchem
- http://www.w3.org/2001/XMLSchema#integer6
- http://www.w3.org/2001/XMLSchema#uinteger6
- http://www.w3.org/2003/11/xpath-datatype
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Embedded domains
- github.com
- www.w3.org
- thing.org
- dressclipsroomsonkeymobilmain.name
- tos.org
- people.in
- the.com
- proprietaryoriginatingprestigiousgrammaticalexperience.to
- www.world
- w3.org
- this.name
- listbox.name
- instruction.name
- caption.name
- schemas.microsoft.com
- schemas.xmlsoap.org
- www.years
- .jpg
- www.interpretation
- www.recent
- www.wencodeuricomponent
- www.icon
- www.hortcut
- .css
- www.css
Embedded IP addresses
- 4.2.1.0
- 5.29.10.5
- 29.19.5.29
- 152.5.29.3
- 5.29.35.5
- 29.37.5.29
- 17.5.29.141
- 0.0.27.0
- 1.12.10.1
- 1.9.16.1
- 1.9.16.2
- 1.9.16.3
- 3.2.8.1
- 1.101.2.1
- 1.101.3.4
- 239.255.255.250
- 142.250.207.14
- 40.79.167.10
- 4.230.171.124
- 40.84.85.40
- 52.253.84.76
- 135.232.92.137
- 135.232.92.97
- 20.42.65.90
- 20.231.239.246
File paths
- C:\Users\dev\Desktop\WinNetService
More Lazy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report