MALICIOUS — 6f2439bc31e6c29a74f5ef42afe1f3b80f7efc7a243fe53ac860c051b98b070a
MALICIOUS — 6f2439bc31e6c29a74f5ef42afe1f3b80f7efc7a243fe53ac860c051b98b070a is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Autorunner family. 9 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
6f2439bc31e6c29a74f5ef42afe1f3b80f7efc7a243fe53ac860c051b98b070a - SHA-1:
b9ae5df2c7312687a061728701de777d17e68ffb - MD5:
1599c0e78f144d5fa9a79830ea2adba2 - imphash:
d50a56fe2fe20efe02049287d3cb46cc - ssdeep:
49152:+ENvof5pKU6/iv1btL2tL1CWlIssZLi5lKr+gDzx:nofaU6/mV2VyGUPDF - TLSH:
T1A35C2B88071E1982D0BD99503884CD7C6D4FFDA820B95C0BD2C7E86E5EFA5A3943B179 - Submitted as: 6f2439bc31e6c29a74f5ef42afe1f3b80f7efc7a243fe53ac860c051b98b070a
- File type: pe · Size: 2460740 bytes
- Verdict: malicious (100/100) · Family: Autorunner
Detections (9 of 52 engines)
- capa (capabilities): capability:collection/keylog
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:
- ClamAV (daily): Win.Malware.Generic-9863791-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:Win32/Vindor!pz
- Emsisoft (Emergency Kit): Gen:Heur.Mint.Autorunner.1
- Kaspersky (KVRT): Worm.Win32.AutoRun.vx
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Win.Malware.Generic-9863791-0 (rule
Win.Malware.Generic-9863791-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 4 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 5252) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Win32/Vindor!pz (rule
Trojan:Win32/Vindor!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Heur.Mint.Autorunner.1 (rule
Gen:Heur.Mint.Autorunner.1) - engine signal, weight 0.55, confidence 0.85 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://gnu.org/licenses/gpl.html, http://www.gnu.org/software/diffutils/, http://www.gnu.org/gethelp/ - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-sections:, Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
21778 behavior events · 1 ATT&CK techniques · 21 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- www.bing.com
- desktop-hsgcbep
- tas02.sls.update.microsoft.com
- config.edge.skype.com
- dns.msftncsi.com
- settings-win.data.microsoft.com
- to-do.microsoft.com
- ctldl.windowsupdate.com
- staging.to-do.microsoft.com
- teams.microsoft.com
- edge.microsoft.com
- watson.events.data.microsoft.com
- aps.prod.windows.com
Dropped files
- /opt/CAPEv2/storage/analyses/4441/files/4f148136730865d308e0fe852d137913937ac32e62aff6bbb2fd3d233ca24967 -
4f148136730865d308e0fe852d137913937ac32e62aff6bbb2fd3d233ca24967 - /opt/CAPEv2/storage/analyses/4441/files/6c2cf1da4094776f4b2f4c88bbc172435220f7d57c78fba2576773d93dca547c -
6c2cf1da4094776f4b2f4c88bbc172435220f7d57c78fba2576773d93dca547c - /opt/CAPEv2/storage/analyses/4441/files/6006019d114213bbe25f919ebbdac5286502d9fa12e681f368278b883b1a6f7f -
6006019d114213bbe25f919ebbdac5286502d9fa12e681f368278b883b1a6f7f - /opt/CAPEv2/storage/analyses/4441/files/b0345c9daa156eeb795c08ed1f52ac542fd3d754287a58b64523c8c14b174c92 -
b0345c9daa156eeb795c08ed1f52ac542fd3d754287a58b64523c8c14b174c92 - /opt/CAPEv2/storage/analyses/4441/files/942ae022a78872f912fb8247a73151875b74c61d6a8269bf6f0275b67a634f61 -
942ae022a78872f912fb8247a73151875b74c61d6a8269bf6f0275b67a634f61 - /opt/CAPEv2/storage/analyses/4441/files/39b3b4cae02e9f4e584523db9b3694c6a1306307e8df3080658cc4ceb81468fb -
39b3b4cae02e9f4e584523db9b3694c6a1306307e8df3080658cc4ceb81468fb - /opt/CAPEv2/storage/analyses/4441/files/2a93f78621cc9ada373d94412fe78fa3f299e91a866b6518b7434e17b41b2109 -
2a93f78621cc9ada373d94412fe78fa3f299e91a866b6518b7434e17b41b2109 - /opt/CAPEv2/storage/analyses/4441/files/a650eb705e0c34b5bf80ba0dca4bffc160b051cf2fa3465610d00779c0dcfdc3 -
a650eb705e0c34b5bf80ba0dca4bffc160b051cf2fa3465610d00779c0dcfdc3 - /opt/CAPEv2/storage/analyses/4441/files/2ec7d351d625d29e8197c5077670d39501497b12a4a7b48cfcd907501e405da2 -
2ec7d351d625d29e8197c5077670d39501497b12a4a7b48cfcd907501e405da2 - /opt/CAPEv2/storage/analyses/4441/files/0e521f15bc59625d451d24130171038f36b8d54ae76b0a3578e484163f4ece1a -
0e521f15bc59625d451d24130171038f36b8d54ae76b0a3578e484163f4ece1a - /opt/CAPEv2/storage/analyses/4441/files/4b5a03fb3820b402c0edda42ed2035b0252b2baeed38ba38d4dcd6de3294ec57 -
4b5a03fb3820b402c0edda42ed2035b0252b2baeed38ba38d4dcd6de3294ec57 - /opt/CAPEv2/storage/analyses/4441/files/e83ea265c2bfbb961ed76dc2ed5205b5b3fc7b812269dc182715321f7ae94dde -
e83ea265c2bfbb961ed76dc2ed5205b5b3fc7b812269dc182715321f7ae94dde - /opt/CAPEv2/storage/analyses/4441/files/596f30adadf5bea38afff4c549e84390c7fc5782507821f0839b54d85c6503ad -
596f30adadf5bea38afff4c549e84390c7fc5782507821f0839b54d85c6503ad - /opt/CAPEv2/storage/analyses/4441/files/0dd5d28c544b18abd2ade72225c37f0c20f4486b6c4f9b1104e227b4780e6898 -
0dd5d28c544b18abd2ade72225c37f0c20f4486b6c4f9b1104e227b4780e6898 - /opt/CAPEv2/storage/analyses/4441/files/cd9fa7370de7b5f810d0acfeb281a4b43b4f4caf2e34049f30266ddd030dc8ab -
cd9fa7370de7b5f810d0acfeb281a4b43b4f4caf2e34049f30266ddd030dc8ab
Embedded URLs
- http://gnu.org/licenses/gpl.html
- http://www.gnu.org/software/diffutils/
- http://www.gnu.org/gethelp/
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/CheckMachineStatusRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/CheckMachineStatusResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetEntitlementsForOlsIdentityRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetEntitlementsForOlsIdentityResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetEntitlementForMachineKeyRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetEntitlementForMachineKeyResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetKeyRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetKeyResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetLicenseRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetLicenseResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetOlsLicenseRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetOlsLicenseResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetSessionTokenRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetSessionTokenResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetTokenRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetTokenResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetWpkBindingRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetWpkBindingResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/ReportActivationRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/IOlsClient/ReportActivationResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/Api/ServerFault
Embedded domains
- gnu.org
- cygwin.com
- www.gnu.org
- schemas.microsoft.com
- schemas.datacontract.org
- crl.microsoft.com
- www.microsoft.com
- office.microsoft.com
- w.mx
- cacerts.digicert.com
- crl4.digicert.com
- crl3.digicert.com
- www.digicert.com
- ols.officeapps.live.com
- staging.to-do.officeppe.com
File paths
- F:\Office\Target\x86\ship\postc2r\x-none\olicenseheartbeat.pdb
- R:\:{:
- X:\:h:l:x:
- C:\Loggers\MyLogger.dll;OutputAsHTML
- C:\My.dll
- C:\Logger.dll
- f:\dd\tools\devdiv\FinalPublicKey.snk
- f:\dd\vsproject\xmake\XMakeCommandLine\objr\amd64\MSBuild.pdb
- d:\dbs\el\oc\target\x86\ship\postc2r\x-none\vpreview.pdb
- A:\:w:
- X:\:`:d:h:l:p:t:x:
- H:\:l:p:t:
- c:\jenkins\workspace\8-2-build-windows-amd64-cygwin\jdk8u261\295\build\windows-amd64\jdk\objs\policytool_objs\policytool.pdb
More Autorunner samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report