MALICIOUS — 6409b8c54cdbbd2e34be3429ec142d7747fd57445de1287487d23af5c464eb7d
MALICIOUS — 6409b8c54cdbbd2e34be3429ec142d7747fd57445de1287487d23af5c464eb7d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Azorult family. 6 of 55 detection engines flagged it.
Identification
- SHA-256:
6409b8c54cdbbd2e34be3429ec142d7747fd57445de1287487d23af5c464eb7d - SHA-1:
ea549ad000ee8b8a4b232f96994d4ac944d90e76 - MD5:
a055077236ecd28a4d4dd3238088da75 - imphash:
8a60cb5b452f4bdbf9698ee60f40d39c - ssdeep:
49152:fwjSTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTT:fw - TLSH:
T10D6C6BBE30E57061EA72B61069AB622F5D32D11AC777BF049C8BE507F57099342C806B - Submitted as: 6409b8c54cdbbd2e34be3429ec142d7747fd57445de1287487d23af5c464eb7d
- File type: pe · Size: 11914752 bytes
- Verdict: malicious (98/100) · Family: Azorult
Detections (6 of 55 engines)
- ClamAV (daily): Win.Trojan.Generic-9906195-0
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Trojan:Win32/Azorult.RW!MTB
- Emsisoft (Emergency Kit): Gen:Heur.Mint.Zard.52
- Trellix Stinger (McAfee): Packed-GDT!A055077236EC
- Kaspersky (KVRT): HEUR:Backdoor.Win32.Tofsee.gen
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Generic-9906195-0 (rule
Win.Trojan.Generic-9906195-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - Contacted 26 external host(s) at runtime (17 HTTP) - network signal, weight 0.40, confidence 0.80
- Extracted Tofsee config (0 C2) - engine signal, weight 0.45, confidence 0.60
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 55.9.42.91, 2.8.50.21 - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
15 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- settings-win.data.microsoft.com
Dropped files
- ecac1f774712981d8976fd6d43c1f2f74dc8d6414d79116bc0e0dcae73e94ea9 -
ecac1f774712981d8976fd6d43c1f2f74dc8d6414d79116bc0e0dcae73e94ea9 - 448e8aeb2dcd412f100bd4271b6bc0f87d6922877f96d874d74144ec811de88c -
448e8aeb2dcd412f100bd4271b6bc0f87d6922877f96d874d74144ec811de88c - 4b60ffaa88d1a01d4cedd578f35220f39e0d9fd82cbe8baa9515548c44a7af9e -
4b60ffaa88d1a01d4cedd578f35220f39e0d9fd82cbe8baa9515548c44a7af9e
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9?P1=1787941906&P2=404&P3=2&P4=FKurFeV68%2fUIL%2fjiLHzMZEzupVHrVUMoGe%2fOr5TrMNlPvmDW5v8KKF8MAQgB%2bafJMwJSraIeE7bcAz9KC4oHkQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Embedded IP addresses
- 55.9.42.91
- 2.8.50.21
- 52.178.17.235
- 52.123.252.232
- 4.230.171.124
- 40.84.85.40
- 4.144.132.114
- 74.178.240.61
- 135.232.92.97
- 13.69.109.130
- 40.104.4.2
- 20.76.201.171
- 52.123.129.14
- 40.99.134.2
- 52.123.128.14
- 20.42.65.90
- 52.123.252.212
- 135.233.45.223
- 203.26.79.13
- 52.110.12.53
- 52.110.12.14
- 162.159.142.9
- 172.178.240.163
- 135.233.95.80
- 72.154.7.16
File paths
- f:\dd\vctools\crt_bld\self_x86\crt\src\_file.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\_sftbuf.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\ioinit.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\stdenvp.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\stdargv.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\w_env.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\tidtable.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\mbctype.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\mlock.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\_getbuf.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\onexit.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\output.c
- C:\namos\todejomixeme22\pojebe.pdb
- X:\:`:d:h:l:p:t:x:
- D:\:`:
- f:\dd\vctools\crt_bld\self_x86\crt\src\puts.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\strtol.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\_flsbuf.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\fwrite.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\fileno.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\dbgrpt.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\dbgheap.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\crt0msg.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\intel\fp8.c
- f:\dd\vctools\crt_bld\self_x86\crt\prebuild\conv\cvt.c
More Azorult samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report