MALICIOUS — 772b26cc918d6eb54b567773a416e169ab4c966f5835920de972e562da345c13
MALICIOUS — 772b26cc918d6eb54b567773a416e169ab4c966f5835920de972e562da345c13 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Crypted family. 4 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
772b26cc918d6eb54b567773a416e169ab4c966f5835920de972e562da345c13 - SHA-1:
76b24f694e7afb0588d4b8ef54b7b9dff2281c09 - MD5:
01248932e9a47f0e2475b11128b2de22 - imphash:
62ec3dce1eba1b68f6a4511bb09f8c2c - ssdeep:
6144:ve49lTbUsgxYhOGF3DDX3mseI4lTbUsgxYhOGF3DDX3Z/QN+llTbUsgxYhOGF3D:TnUszf7SnUszfKNMnUszf7SnUszf - TLSH:
T12F4A3923D6289BA1EDE9820D7109F9ACD1BB211520E5FFD5A132B248B4477BBE3450DC - Submitted as: 772b26cc918d6eb54b567773a416e169ab4c966f5835920de972e562da345c13
- File type: pe · Size: 450560 bytes
- Verdict: malicious (99/100) · Family: Crypted
Detections (4 of 56 engines)
- ClamAV (daily): Win.Trojan.Crypted-29
- Microsoft Defender: Backdoor:Win32/Berbew.AA!MTB
- Emsisoft (Emergency Kit): Generic.Dacic.1.Backdoor.Hangup.A.C86DA622
- Kaspersky (KVRT): Trojan-Proxy.Win32.Qukart.vih
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypted-29 (rule
Win.Trojan.Crypted-29) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Backdoor:Win32/Berbew.AA!MTB (rule
Backdoor:Win32/Berbew.AA!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Generic.Dacic.1.Backdoor.Hangup.A.C86DA622 (rule
Generic.Dacic.1.Backdoor.Hangup.A.C86DA622) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-Proxy.Win32.Qukart.vih (rule
Trojan-Proxy.Win32.Qukart.vih) - engine signal, weight 0.55, confidence 0.85 - Contacted 2 external host(s) and 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Dropped 86 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
2805 behavior events · 1 ATT&CK techniques · 86 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- th.bing.com
- watson.events.data.microsoft.com
- edge.microsoft.com
- time.windows.com
Dropped files
- C:\Windows\System32\Fccfcj32.dll -
313ccf5c8cec4ebc2a6f28a244d994ab2e296e3162151d948d9909bf7bfbe27f - C:\Windows\System32\Edkgca32.dll -
110d1b921e350bb3fa9bc7df7e338c58a50337b2aaee571f7330983e583115ed - C:\Windows\System32\Hefkng32.exe -
2f12720c7a1443c76444dc0bbefcb50d8388a66397cf1956098d823edf509d45 - C:\Windows\System32\Bndppm32.exe -
77290bf1e5dfacf8f6096f51b9087393a4ac7a4af30d8eec50edc628ed4f3263 - C:\Windows\System32\Emeqcaop.dll -
3297d367710dd5c9ee358a210a15c91515fee20e613c662e2d5792e0f9c5bf71 - C:\Windows\System32\Kmqjhdmd.dll -
a1f27ae9f359c5af87deff885949e381e6bf57dca3678085f81fff3e89acd01e - C:\Windows\System32\Flidcd32.exe -
8d5608ab6c92372fb1a52a7a9cef3d69f0d497a2a69b357dc44a6369a5e163c4 - C:\Windows\System32\Hjfbcl32.dll -
d535540b021695c9a45dc4c4115b9b67b167a7979f7a038c496250151e14256a - C:\Windows\System32\Hpcpaeam.dll -
27e5d395140653eced4bb4d374b0e92fc74bb46be16cfa7f81e54a77fc475acd - C:\Windows\System32\Lhkjko32.dll -
5903c216037c1011e61d27415dcb55d905cf778967eb3259b24fd2cf0be6b048 - C:\Windows\System32\Obpokebd.dll -
663efd6d1a0a36d7cbe9684d348ec6dcb36710b0624ff8effde9aaf855f872c4 - C:\Windows\System32\Qkhgbd32.exe -
90a05487751486b6b8a4cd9d1f5356f8399b67ea0a1d8c989b259c7cab2cd59f - C:\Windows\System32\Lmhkiknd.exe -
b508aebb0fbc023d53e7e5e9cc7b3fcc232a83bdd777fc374d6045476fe39607 - C:\Windows\System32\Obkndj32.dll -
42db96838e48c13220dce7609082b3e3c7d2ba48bb6a126b954c9112e0a249ea - C:\Windows\System32\Bhimbp32.exe -
0650e0287fb838a13a69657fc9d13a5adc2f47c6d43b8df135123da80e85f0be
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 20.42.72.131
- 52.110.12.8
- 52.110.12.55
- 52.230.59.222
- 52.123.252.240
- 4.230.171.124
- 104.18.33.89
- 135.233.45.223
- 57.155.101.212
- 72.154.7.102
- 20.42.65.94
- 51.116.246.105
- 92.223.78.30
- 52.148.114.188
- 52.110.12.1
- 52.110.12.24
More Crypted samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report