MALICIOUS — 818153c1692c8eb58fcb3a0e9095933f40f62ee2344884b0747988f84c41e169
MALICIOUS — 818153c1692c8eb58fcb3a0e9095933f40f62ee2344884b0747988f84c41e169 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Ramnit family. 3 of 56 detection engines flagged it.
Identification
- SHA-256:
818153c1692c8eb58fcb3a0e9095933f40f62ee2344884b0747988f84c41e169 - SHA-1:
1fc22c16ebdcd4605b2cb325c89acd6267423b98 - MD5:
16587cfc066678a814955a7b2cd6e327 - imphash:
4ab132a12948f33e7c5a471369279fe5 - ssdeep:
98304:93fLVB6XZDEHAX16JRj16J9vJHCjyOgUEXYkhCWkwE2m8e:/B6JDvFQZuJHeyOtrkkw3Pe - TLSH:
T17063334560E6B711D8EE1A7406888DBF177BFAE32677088A2FD707C2375A6C3B611106 - Submitted as: 818153c1692c8eb58fcb3a0e9095933f40f62ee2344884b0747988f84c41e169
- File type: pe · Size: 5000982 bytes
- Verdict: malicious (98/100) · Family: Ramnit
Detections (3 of 56 engines)
- ClamAV (daily): Win.Trojan.Ramnit-9753960-0
- Emsisoft (Emergency Kit): Trojan.Generic.38594655
- Kaspersky (KVRT): UDS:DangerousObject.Multi.Generic
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Ramnit-9753960-0 (rule
Win.Trojan.Ramnit-9753960-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged Trojan.Generic.38594655 (rule
Trojan.Generic.38594655) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:DangerousObject.Multi.Generic (rule
UDS:DangerousObject.Multi.Generic) - engine signal, weight 0.55, confidence 0.85 - Contacted 2 external host(s) and 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- Embedded network infrastructure: http://nsis.sf.net/NSIS_Error - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1069 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- officeclient.microsoft.com
- www.msn.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
- licensing.mp.microsoft.com
- www.bing.com
- th.bing.com
- fe3cr.delivery.mp.microsoft.com
Embedded URLs
- http://nsis.sf.net/NSIS_Error
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- nsis.sf.net
- 8.pl
- p.sg
Embedded IP addresses
- 4.150.223.98
- 52.123.252.198
- 57.155.104.224
- 4.230.171.124
- 20.247.184.142
- 74.178.240.51
- 4.150.223.111
- 74.178.240.61
- 104.18.33.89
- 51.132.193.105
- 92.223.78.30
- 52.110.12.14
- 52.110.12.18
- 72.153.5.63
- 52.148.114.188
- 52.110.12.16
- 52.110.12.42
File paths
- x:\}
More Ramnit samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report