MALICIOUS — 70977d91650a5b8b2eb95deeeb2d6581dee4af3efbb2f95d8189211e532e8427
MALICIOUS — 70977d91650a5b8b2eb95deeeb2d6581dee4af3efbb2f95d8189211e532e8427 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the AsyncRAT family. 5 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
70977d91650a5b8b2eb95deeeb2d6581dee4af3efbb2f95d8189211e532e8427 - SHA-1:
cbca94f554c9febb95d832d592c5089aada00409 - MD5:
8889f872eff9e2c85e2a071816ac7067 - imphash:
731a8eb2a2e4c8bec7d14e3ab3066ac8 - ssdeep:
196608:T8DvXCc0mVKuOHijsysQnToUk+h2s6RVYqY3RITQ96dgyQUP4q:AXCtWzjTf62q - TLSH:
T1B26E5BF082572211E1F8EE40F03288DC944BF949A5712ECC5216D5AE41D8FBBE6F64A7 - Submitted as: 70977d91650a5b8b2eb95deeeb2d6581dee4af3efbb2f95d8189211e532e8427
- File type: pe · Size: 14416901 bytes
- Verdict: malicious (98/100) · Family: AsyncRAT
Detections (5 of 55 engines)
- YARA: ESET research: atollon
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: PhishingKit (t4d): PK_Result_Mailer
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Trojan:Win32/Wacatac.B!ml
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 10 weighted signals:
- Extracted AsyncRAT config (167 C2) - engine signal, weight 0.80, confidence 0.65
- YARA: ESET research flagged atollon (rule
atollon) - engine signal, weight 0.70, confidence 0.70 - Microsoft Defender flagged Trojan:Win32/Wacatac.B!ml (rule
Trojan:Win32/Wacatac.B!ml) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - YARA: PhishingKit (t4d) flagged PK_Result_Mailer (rule
PK_Result_Mailer) - engine signal, weight 0.60, confidence 0.70 - Contacted 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://www.torproject.org/download/download#warning, https://www.torproject.org/documentation.html, https://blog.torproject.org/blog/lifecycle-of-a-new-relay - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. RWX/private injected region in SppExtComObj.E (pid 5900) (rule
windows.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- desktop-hsgcbep
- login.live.com
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- www.msftconnecttest.com/connecttest.txt
Embedded URLs
- https://www.torproject.org/download/download#warning
- https://www.torproject.org/documentation.html
- https://blog.torproject.org/blog/lifecycle-of-a-new-relay
- https://www.torproject.org/docs/faq.html#BestOSForRelay
- https://trac.torproject.org/8742
- http://freehaven.net/anonbib/#hs-attack06
- https://trac.torproject.org/projects/tor/ticket/14917
- https://trac.torproject.org/projects/tor/ticket/21155
- https://www.torproject.org/
- http://www.openssl.org/support/faq.html
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- openssl.org
- big.int
- xml.name
- pkix.name
- reflect.name
- runtime.name
- golang.org
- www.w3.org
- atomic.store
- runtime.name.name
- reflectlite.name.name
- unicode.in
- unicode.to
- reflect.name.name
- rand.int
- eq.net.mx
- eq.net
- github.com
- www.torproject.org
- wiki.torproject.org
- blog.torproject.org
- lists.torproject.org
- trac.torproject.org
- freehaven.net
- www.google.com
Embedded IP addresses
- 5.4.32.5
- 4.52.5.4
- 62.5.4.72
- 5.4.82.5
- 5.4.102.5
- 4.112.5.4
- 4.1.1.1
- 4.9.1.1
- 4.12.1.1
- 4.14.1.1
- 4.14.2.1
- 2.2.1.1
- 2.3.1.1
- 1.1.1.1
- 0.2.5.15
- 0.2.9.3
- 0.2.9.1
- 0.2.7.5
- 0.2.4.19
- 0.2.4.8
- 0.3.0.8
- 0.3.5.7
- 0.1.2.17
- 0.2.4.18
- 0.2.9.5
More AsyncRAT samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report