MALICIOUS — 7fa8d9e05333ae673b326f88e3d6aa0f0be14b77826759e2b7c6c6bf795999d0
MALICIOUS — 7fa8d9e05333ae673b326f88e3d6aa0f0be14b77826759e2b7c6c6bf795999d0 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the VBChinky family. 4 of 56 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
7fa8d9e05333ae673b326f88e3d6aa0f0be14b77826759e2b7c6c6bf795999d0 - SHA-1:
1cd270958b6da713be9a1643139e4a37e58d9ea6 - MD5:
058c09276350d5f5ad26f1207eb46873 - imphash:
8f2109bfd0c2448e82e61102807c50c7 - ssdeep:
768:sduwfCcZl+IBlNc82SYtedP34DGltCJWx+7AppL4zG4dslM8lP+wgG0SXdkUr9A:sdFRnl1zlN+aLHM8WSXjy6 - TLSH:
T1ED3C10D3D1868886D6A836BB1D5AB6EC20CCCD00253254727FFCEA4F7981AB7A05571C - Submitted as: 7fa8d9e05333ae673b326f88e3d6aa0f0be14b77826759e2b7c6c6bf795999d0
- File type: pe · Size: 114176 bytes
- Verdict: malicious (100/100) · Family: VBChinky
Detections (4 of 56 engines)
- ClamAV (daily): Html.Trojan.VBChinky-1
- Microsoft Defender: Worm:Win32/Vobfus!pz
- Emsisoft (Emergency Kit): Gen:Trojan.Chinky.2
- Kaspersky (KVRT): Worm.Win32.VBNA.agdg
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Html.Trojan.VBChinky-1 (rule
Html.Trojan.VBChinky-1) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s) across 1 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged Worm:Win32/Vobfus!pz (rule
Worm:Win32/Vobfus!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Trojan.Chinky.2 (rule
Gen:Trojan.Chinky.2) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Worm.Win32.VBNA.agdg (rule
Worm.Win32.VBNA.agdg) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 1 external host(s) and 6 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
21052 behavior events · 3 ATT&CK techniques · 5 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ns1.thepicturehut.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- www.bing.com
- assets.msn.com
- th.bing.com
- watson.events.data.microsoft.com
- edge.microsoft.com
Dropped files
- C:\Users\analyst\wueoxat.exe -
7b317a40a90c77acea1942134833a787231fb0bbabf04cb57c15c1354a57e453 - C:\Users\analyst\AppData\Local\Temp\~DFA78B2A560EE74B85.TMP -
50d6ac29bc8418dcf474f72673ebb1d9b9741885835ea572af8fd3ce70ea0c32 - 101accd272eb516391108c663f3042fcc622f97c492722b9a6b6842fad365342 -
101accd272eb516391108c663f3042fcc622f97c492722b9a6b6842fad365342 - 45f5fce27c6d443720f80b5228ccd39c0e67a2b34e795efdc74d50e49d051c20 -
45f5fce27c6d443720f80b5228ccd39c0e67a2b34e795efdc74d50e49d051c20 - 8a23bec8622b95861badc756dd21b00175591ce39709af3b175b6bc3eb2b82f0 -
8a23bec8622b95861badc756dd21b00175591ce39709af3b175b6bc3eb2b82f0
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- ns1.thepicturehut.net
Embedded IP addresses
- 4.150.223.104
- 52.253.84.76
- 4.230.171.124
- 172.64.154.167
- 135.234.160.245
- 52.110.12.45
- 52.110.12.2
- 57.155.104.224
- 172.178.240.163
- 72.145.35.104
- 52.110.12.22
- 52.148.114.188
- 52.110.12.55
More VBChinky samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report