MALICIOUS — 802406ed0b6608fc8dcc370c566c362fdf66eef86060b515c8604ae0fff1643c
MALICIOUS — 802406ed0b6608fc8dcc370c566c362fdf66eef86060b515c8604ae0fff1643c is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 56 detection engines flagged it.
Identification
- SHA-256:
802406ed0b6608fc8dcc370c566c362fdf66eef86060b515c8604ae0fff1643c - SHA-1:
dc9b1dd5c65077a437fb305efe0292e237995534 - MD5:
1083965993320b2607a25ef624209d99 - imphash:
d953fbdfd860278b8bd3f7cac3ac1a88 - ssdeep:
1536:eqXHUW45amJxEEFs5yxFyFF+FoqtMeaXiwdMv3+3xbKZ/HMsQt1TZ/IiLowN9Z+:eqXHUDlEaoSyqtMfMv3+3xbKZ/HMsQt - TLSH:
T1F0388D4D42A666A2E2F6DC5C6C408ADC8416B5EC2072B94C1F07C9BE95D0E33DCF3699 - Submitted as: 802406ed0b6608fc8dcc370c566c362fdf66eef86060b515c8604ae0fff1643c
- File type: pe · Size: 81920 bytes
- Verdict: malicious (92/100)
Detections (4 of 56 engines)
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Trojan:Win32/Wacatac.B!ml
- Emsisoft (Emergency Kit): Win32.Virtob.Gen.12
- Kaspersky (KVRT): Virus.Win32.Virut.ce
Why this verdict
The malicious score of 92/100 is the fusion of 5 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Wacatac.B!ml (rule
Trojan:Win32/Wacatac.B!ml) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Virtob.Gen.12 (rule
Win32.Virtob.Gen.12) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.Virut.ce (rule
Virus.Win32.Virut.ce) - engine signal, weight 0.55, confidence 0.85 - Contacted 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis (windows)
11 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- officeclient.microsoft.com
- www.msn.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- assets.msn.com
- www.bing.com
- th.bing.com
- fe3cr.delivery.mp.microsoft.com
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- a.name
Embedded IP addresses
- 4.150.223.97
- 52.123.252.224
- 4.230.171.124
- 4.247.188.224
- 20.247.184.142
- 135.232.92.97
- 20.42.65.84
- 74.178.240.61
- 104.18.33.89
- 74.178.76.128
- 135.234.160.245
- 92.223.78.30
- 52.110.12.55
- 52.110.12.56
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report