MALICIOUS — tl-all-sandboxes.exe
MALICIOUS — tl-all-sandboxes.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the AsyncRAT family. 0 of 34 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
87662eaddaaf4ec010e23d4b35d3456125bb717a19c73d58a3aec2f5dab828e4 - SHA-1:
acfe850e625d8d31d22a0c781c6c20c020486a7e - MD5:
3bb0571e6137fa234a11372175f56837 - imphash:
b17bb7c314fd2b059817ab62cad9ea81 - ssdeep:
12288:+ZklB0ws0Ljq0dfaq2mItbTYDMgWsg+Nz6MCKJVPDh7LGdB6MWv:++n0APfB27NcQ56NuM9JVPDFSB6MWv - TLSH:
T1D24D8C001112E383D4A5FFB49C89CEDC9073EA9031BF198C6396D1AE96D7D4B94C94BA - Submitted as: tl-all-sandboxes.exe
- File type: pe · Size: 602125 bytes
- Verdict: malicious (98/100) · Family: AsyncRAT
Detections (0 of 34 engines)
No engine flagged this sample.
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- 3 behavioral detection(s): Ransomware: mass file writes + ransom markers [critical] (rule
tl-ransomware-canary) - dynamic signal, weight 0.80, confidence 0.90 - Extracted AsyncRAT config (1 C2) - engine signal, weight 0.80, confidence 0.65
- Contacted 11 host(s) at runtime - network signal, weight 0.55, confidence 0.85
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.45, confidence 0.90 - 1 IDS alert(s): ThreatLens DGA-like NXDOMAIN burst - network signal, weight 0.50, confidence 0.80
- Embedded network infrastructure: http://schemas.microsoft.com/SMI/2016/WindowsSettings, 1.0.0.0 - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
7316 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- wdcp.microsoft.com
- d.1.d.1.c.4.2.1.4.9.5.2.6.e.8.b.0.0.0.0.0.0.0.0.0.0.0.0.0.8.e.f.ip6.arpa.
- 76.0.240.10.in-addr.arpa.
- 1.0.240.10.in-addr.arpa.
- 251.0.0.224.in-addr.arpa.
- 18.183.195.4.in-addr.arpa.
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 252.0.0.224.in-addr.arpa.
- wpad
- ctldl.windowsupdate.com
- 172.30.101.151.in-addr.arpa.
- settings-win.data.microsoft.com
- ff02:0:0:0:0:0:1:2
- 10.240.0.1
- 4.195.183.18
- 224.0.0.251
- 10.240.0.76
- ff02:0:0:0:0:0:0:fb
Embedded URLs
- http://schemas.microsoft.com/SMI/2016/WindowsSettings
Embedded domains
- schemas.microsoft.com
Embedded IP addresses
- 1.0.0.0
File paths
- X:\:`:d:h:l:p:t:x:
- T:\:d:l:t:
- X:\:h:x:
- T:\:d:l:x:
- T:\:h:p:
- T:\:h:
- T:\:d:p:
More AsyncRAT samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report