MALICIOUS — 21.exe
MALICIOUS — 21.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the OnlineGames family. 5 of 51 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
8abb47ca7c0c4871c28b89aa0e75493e5eb01e403272888c11fef9e53d633ffe - SHA-1:
4bed4b7f9d15e5f4cfe6b8e61f7bca865b7ce641 - MD5:
ebefee9de7d429fe00593a1f6203cd6a - imphash:
a0ce92be01226cf42a8852419d300d38 - ssdeep:
768:4EyjLgnDw5oEC+WOill+du3tOWxZtrDm9qPcQ4qWto9iP22WIps6qceX5VykiKoG:2LgDwjC+WOE+Q9FZtrDGHUuUIjgps4v - TLSH:
T1D834F1F8533971C5EBE855A1613E033D6BB860D063F99DA361D8DA0334921BB02053BB - Submitted as: 21.exe
- File type: pe · Size: 56224 bytes
- Verdict: malicious (99/100) · Family: OnlineGames
Detections (5 of 51 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): {MD5}bin.trojan.agent.7554.UNOFFICIAL
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:Win32/Vindor!pz
- Emsisoft (Emergency Kit): Gen:Variant.OnlineGames.283
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged {MD5}bin.trojan.agent.7554.UNOFFICIAL (rule
{MD5}bin.trojan.agent.7554.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Vindor!pz (rule
Trojan:Win32/Vindor!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.OnlineGames.283 (rule
Gen:Variant.OnlineGames.283) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 21 external host(s) at runtime (2 HTTP) - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1, Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
2728 behavior events · 2 ATT&CK techniques · 4 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- v10.events.data.microsoft.com
- settings-win.data.microsoft.com
- login.live.com
- v20.events.data.microsoft.com
- desktop-hsgcbep
- fd.api.iris.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- licensing.mp.microsoft.com
- assets.msn.com
- tsfe.trafficshaping.dsp.mp.microsoft.com
- watson.events.data.microsoft.com
- msedge.api.cdp.microsoft.com
- http://www.msftconnecttest.com/connecttest.txt
- www.msftconnecttest.com/connecttest.txt
Dropped files
- /opt/CAPEv2/storage/analyses/5748/files/cc7c8faec19adbed2ada843c83202276aa13aadde78983d0ff6140b9cab5e5e9 -
cc7c8faec19adbed2ada843c83202276aa13aadde78983d0ff6140b9cab5e5e9 - /opt/CAPEv2/storage/analyses/5748/files/5707e445eeca460f2e7f320d5c99eaf7840fd94632638d48e65d66a66a4ba715 -
5707e445eeca460f2e7f320d5c99eaf7840fd94632638d48e65d66a66a4ba715 - /opt/CAPEv2/storage/analyses/5748/files/5ce7c2eb8860f172dd5b68cd94307b6665f6785b207d936577bbaab196b61f33 -
5ce7c2eb8860f172dd5b68cd94307b6665f6785b207d936577bbaab196b61f33 - 24e050afeb9e68d65553b14bfa0e36f9af5d1206871f1f2f038c85281b85b316 -
24e050afeb9e68d65553b14bfa0e36f9af5d1206871f1f2f038c85281b85b316
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- inference.location.live.net
Embedded IP addresses
- 23.40.52.209
- 20.184.175.2
- 172.215.188.232
- 20.42.65.85
- 52.123.252.232
- 52.253.84.76
- 4.230.171.124
- 20.190.142.164
- 20.42.179.192
- 72.147.149.16
- 104.46.162.229
- 135.233.45.221
- 150.171.22.17
- 135.232.92.34
- 172.178.240.161
- 23.33.238.171
- 74.226.60.120
- 52.110.12.32
- 23.198.40.44
- 52.110.12.22
- 23.33.238.178
File paths
- I:\:d:u:
More OnlineGames samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report