MALICIOUS — 71d2b0fc05c2713c15ee56b8a02d0277317def80bf6b85b4efd2854b6ffa8176
MALICIOUS — 71d2b0fc05c2713c15ee56b8a02d0277317def80bf6b85b4efd2854b6ffa8176 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (82/100). 3 of 56 detection engines flagged it.
Identification
- SHA-256:
71d2b0fc05c2713c15ee56b8a02d0277317def80bf6b85b4efd2854b6ffa8176 - SHA-1:
79ec4e335aafc4d4d12cd4323a45e732992b2b13 - MD5:
c18d3cd5f7669c36af3d855b6c1aa7d1 - imphash:
57c665d568d2c3ae8daa80428cd4f0c1 - ssdeep:
196608:igyE1MVZbrQy70FfOuufF2/KDMMWqYBUpmZ5hvbL:LyE1IbrTXtyKDNWJnx - TLSH:
T16F673398E27EA44FD9B39A2E0B41488FE7D8CC4DA35F2C55485014B4543874FA0FA9EB - Submitted as: 71d2b0fc05c2713c15ee56b8a02d0277317def80bf6b85b4efd2854b6ffa8176
- File type: pe · Size: 7180128 bytes
- Verdict: malicious (82/100)
Detections (3 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- Detect It Easy (packer/type): DIE:Turbo Linker
- Kaspersky (KVRT): HEUR:Trojan.Win32.Agent.gen
Why this verdict
The malicious score of 82/100 is the fusion of 6 weighted signals:
- Kaspersky (KVRT) flagged HEUR:Trojan.Win32.Agent.gen (rule
HEUR:Trojan.Win32.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 4 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1, Turbo Linker - static signal, weight 0.25, confidence 0.55
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
88 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- desktop-hsgcbep
- login.live.com
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- odc.officeapps.live.com
- www.msn.com
- settings-win.data.microsoft.com
- assets.msn.com
- licensing.mp.microsoft.com
- www.bing.com
- th.bing.com
- tas02.sls.update.microsoft.com
Dropped files
- 002db41bb4e7bb33ff36446de2b4d90c58c6b1018ca5d19e3e27b60f18af53f1 -
002db41bb4e7bb33ff36446de2b4d90c58c6b1018ca5d19e3e27b60f18af53f1
Embedded URLs
- http://crl3.digicert.com/ha-cs-2011a.crl0
- http://crl4.digicert.com/ha-cs-2011a.crl0L
- https://www.digicert.com/CPS0
- http://www.digicert.com/ssl-cps-repository.htm0
- http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
- http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
- http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
- http://crl3.digicert.com/sha2-ha-cs-g1.crl00
- http://crl4.digicert.com/sha2-ha-cs-g1.crl0L
- http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
- http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0O
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- cacerts.digicert.com
Embedded IP addresses
- 51.132.193.104
- 4.247.188.224
- 4.230.171.124
- 52.230.59.222
- 135.233.95.144
- 74.179.77.164
- 51.105.71.137
- 51.116.253.170
- 104.18.33.89
- 135.233.45.221
- 52.110.12.26
- 52.110.12.28
File paths
- N:\0UO
- i:\;
- i:\]2
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report