MALICIOUS — 7824eb5f173c43574593bd3afab41a60e0e2ffae80201a9b884721b451e6d935
MALICIOUS — 7824eb5f173c43574593bd3afab41a60e0e2ffae80201a9b884721b451e6d935 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the Tedy family. 4 of 51 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
7824eb5f173c43574593bd3afab41a60e0e2ffae80201a9b884721b451e6d935 - SHA-1:
3ed2d4e3682d678ea640aadbfc08311c6f2081e8 - MD5:
83763fe02f41c1b3ce099f277391732a - imphash:
92077db37175526b9c84a0536426d056 - ssdeep:
12288:S4vOXCKKNqjgf6gMyHLsfViQrIiIOI9tJHGOeio7rYKczoG8yTgu0:OXCKaqEi6LsfViQIOIdoio7rYVzJPZ0 - TLSH:
T16F4F8C2181033232F5F6EE58AC5048ECC032F5AC64B5E89D6647ECADA0E9D73E6E11D5 - Submitted as: 7824eb5f173c43574593bd3afab41a60e0e2ffae80201a9b884721b451e6d935
- File type: pe · Size: 733696 bytes
- Verdict: malicious (89/100) · Family: Tedy
Detections (4 of 51 engines)
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Emsisoft (Emergency Kit): Gen:Variant.Tedy.794601
MITRE ATT&CK
Why this verdict
The malicious score of 89/100 is the fusion of 9 weighted signals:
- Emsisoft (Emergency Kit) flagged Gen:Variant.Tedy.794601 (rule
Gen:Variant.Tedy.794601) - engine signal, weight 0.55, confidence 0.85 - Contacted 14 external host(s) at runtime (2 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://curl.haxx.se/docs/http-cookies.html, 1.101.3.4 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60 - Extracted generic config (2 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
143 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- config.edge.skype.com
- aefd.nelreports.net
- www.bing.com
- v20.events.data.microsoft.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- licensing.mp.microsoft.com
- login.live.com
- desktop-hsgcbep
- g.live.com
- ecs.office.com
- oneclient.sfx.ms
- dns.msftncsi.com
- watson.events.data.microsoft.com
- self.events.data.microsoft.com
- http://www.msftconnecttest.com/connecttest.txt
- www.msftconnecttest.com/connecttest.txt
- 23.33.238.110
Embedded URLs
- https://curl.haxx.se/docs/http-cookies.html
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- curl.haxx.se
- example.com
- aefd.nelreports.net
- oneclient.sfx.ms
Embedded IP addresses
- 1.101.3.4
- 23.46.10.19
- 4.144.132.223
- 20.42.65.85
- 23.40.52.85
- 154.213.21.27
- 135.233.45.221
- 150.171.109.24
- 52.123.252.240
- 20.190.167.149
- 52.110.12.40
- 52.110.12.19
- 52.168.117.175
- 23.40.52.69
- 23.33.238.110
More Tedy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report