MALICIOUS — virussign.com_75219502d9b4dffd6bfa6cae94ed0a90.vir
MALICIOUS — virussign.com_75219502d9b4dffd6bfa6cae94ed0a90.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the CobaltStrike family. 12 of 53 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
718af0577c6f4016d21887f6d452bff5da2990d1891ade602de2b711e6fa6820 - SHA-1:
60dc9d59ab82f36cc2dc57c4b59c96b40c1fbd88 - MD5:
75219502d9b4dffd6bfa6cae94ed0a90 - imphash:
500dc0c0888bd55c4e50048a30cd52d7 - ssdeep:
98304:4emTLkNdfE0pZaJ56utgpPFotBER/mQ32lUb:j+R56utgpPF8u/7b - TLSH:
T179657DF24A61E797DAD7F0B4906097BC6893E05D71760EEC2623DB24BCC4A530AAF444 - Submitted as: virussign.com_75219502d9b4dffd6bfa6cae94ed0a90.vir
- File type: pe · Size: 6066404 bytes
- Verdict: malicious (100/100) · Family: CobaltStrike
Detections (12 of 53 engines)
- YARA: MalwareAnalyser built-in: Suspicious_PowerShell_Download_Exec
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- ClamAV (daily): Win.Trojan.CobaltStrike-8091534-0
- YARA: Google GCTI: GCTI_CobaltStrike_Beacon
- YARA: Intezer community: INTEZER_Linux_XMRig_Miner
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: MalwareAnalyser community pack: TL_Suspicious_PowerShell_Download
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:Win64/CoinMiner
- Kaspersky (KVRT): Trojan-Downloader.Win32.Banload.abipe
MITRE ATT&CK
YARA
- Suspicious_PowerShell_Download_Exec
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 100/100 is the fusion of 19 weighted signals:
- ClamAV (daily) flagged Win.Trojan.CobaltStrike-8091534-0 (rule
Win.Trojan.CobaltStrike-8091534-0) - engine signal, weight 0.90, confidence 0.95 - Encoded/hidden PowerShell download-and-exec (rule
Suspicious_PowerShell_Download_Exec) - yara signal, weight 0.70, confidence 0.90 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - Microsoft Defender flagged Trojan:Win64/CoinMiner (rule
Trojan:Win64/CoinMiner) - engine signal, weight 0.55, confidence 0.85 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Contacted 14 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Extracted CobaltStrikeBeacon config (0 C2) - engine signal, weight 0.45, confidence 0.60
- YARA: Google GCTI flagged GCTI_CobaltStrike_Beacon (rule
GCTI_CobaltStrike_Beacon) - engine signal, weight 0.35, confidence 0.70 - YARA: Intezer community flagged INTEZER_Linux_XMRig_Miner (rule
INTEZER_Linux_XMRig_Miner) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Suspicious_PowerShell_Download (rule
TL_Suspicious_PowerShell_Download) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 3.120.209.58 - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - inject code into another process (rule
inject code into another process) - capa signal, weight 0.12, confidence 0.60
Dynamic analysis (windows)
12 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- v20.events.data.microsoft.com
- desktop-hsgcbep
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- licensing.mp.microsoft.com
- assets.msn.com
- www.bing.com
- watson.events.data.microsoft.com
- http://www.msftconnecttest.com/connecttest.txt
- www.msftconnecttest.com/connecttest.txt
- ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?27505116182ebe91
- ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?4de257e60034dd93
- 23.40.52.209
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- donate.v2.xmrig.com
- big.int
- idna.info
- pkix.name
- reflect.name
- runtime.name
- s3.us-east-2.amazonaws.com
- golang.org
- atomic.store
- runtime.name.name
- unicode.to
- reflect.name.name
- hash.net
- eq.net
- runtime.work
- go.itab.net
- go.itab.io
- unicode.cc
- unicode.cf
- unicode.co
- unicode.me
- unicode.nl
- unicode.no
- reflect.link
- reflect.fun
Embedded IP addresses
- 3.120.209.58
- 23.40.52.209
- 13.69.109.130
- 150.171.22.17
- 20.190.142.165
- 4.230.171.124
- 52.230.59.222
- 135.234.160.244
- 23.33.238.114
- 23.33.238.173
- 52.110.12.15
- 52.110.12.19
- 23.198.40.44
- 23.33.238.178
- 199.232.138.172
File paths
- C:\Windows\System\
- C:\Users\SKOL-NOTE\Desktop\Loader
- V:\::;Q;k
More CobaltStrike samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report