MALICIOUS — 8d426aeabdb126c6af992785f00d1dbc176142905c4fa281bb2b6eb6b28b0fe3
MALICIOUS — 8d426aeabdb126c6af992785f00d1dbc176142905c4fa281bb2b6eb6b28b0fe3 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Qakbot family. 5 of 56 detection engines flagged it, exhibiting 6 ATT&CK techniques.
Identification
- SHA-256:
8d426aeabdb126c6af992785f00d1dbc176142905c4fa281bb2b6eb6b28b0fe3 - SHA-1:
eeaeb2e17e99c58b00664279b061457fd6b1fb8d - MD5:
19c3490dcc5550c6a2130b3de25469f1 - imphash:
69b6867f8f2741c550a03eff9f56e771 - ssdeep:
98304:3drt18drt1Pdrt18drt1Tdrt18drt1Pdrt18drCdrt18drt1Pdrt18drt1Tdrt1:t090x090+090x090/090x090+090x09 - TLSH:
T1876A8C5492269351DAF2DB587DA13E1E2073F0DA91BE29C842C3C23F3298DB7E452257 - Submitted as: 8d426aeabdb126c6af992785f00d1dbc176142905c4fa281bb2b6eb6b28b0fe3
- File type: pe · Size: 9871361 bytes
- Verdict: malicious (100/100) · Family: Qakbot
Detections (5 of 56 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Malware.Qakbot-9860983-1
- Microsoft Defender: Trojan:Win32/Gamaredon!pz
- Emsisoft (Emergency Kit): Gen:Variant.Barys.321097
- Kaspersky (KVRT): Trojan.Win32.Agent.nevpvs
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 13 weighted signals:
- ClamAV (daily) flagged Win.Malware.Qakbot-9860983-1 (rule
Win.Malware.Qakbot-9860983-1) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Gamaredon!pz (rule
Trojan:Win32/Gamaredon!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Barys.321097 (rule
Gen:Variant.Barys.321097) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Agent.nevpvs (rule
Trojan.Win32.Agent.nevpvs) - engine signal, weight 0.55, confidence 0.85 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 18 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- capa (capabilities) flagged capability:collection/keylog (rule
capability:collection/keylog) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Dropped 5 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
13594 behavior events · 1 ATT&CK techniques · 12 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- nwoccs.zapto.org
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Roaming\Microsoft\XMMC\mdata\icxml.dmp -
43ef629f5fb2772d4fda955109b0f3a20b08efb927ad6077ec5517bc76e6eff5 - C:\Users\analyst\AppData\Roaming\Microsoft\XMMC\msys.dmp -
43d48fc0e6dcb24af0148deb5bddbf69d2ddcecca43c87104bc920948ed66cdc - C:\Users\analyst\AppData\Roaming\Microsoft\XMMC\winnt32\nt32.ocx -
c3fba315ea45e3532365bd33d784a19f198d52fd3e86b2a85030c35f58d1777a - C:\Users\analyst\AppData\Roaming\Microsoft\XMMC\mdata\winnt32.img -
f3e0d8b3596a5ba2d8132d2f85f959aa8cf77cfba2560b440820c468e99f3cf6 - C:\Users\analyst\AppData\Roaming\Microsoft\XMMC\winnt32\openssh.ocx -
3fe5eec4e8a7b69e85c2048d9560ad19d9c169af75493a4c6d50c43f4440822a - C:\Users\analyst\AppData\Roaming\Microsoft\XMMC\mdata.exe -
88d2a0c72527330ef1a484d797401fdf7c333e56e7f16113ec88c70c99ee27e0 - C:\Users\analyst\AppData\Roaming\Microsoft\XMMC\mdata.dat -
248f75509003791cb3ccb65f1ae4cfbbf7eec1af61c948f443a11632b66a9b70 - C:\Users\analyst\AppData\Roaming\Microsoft\XMMC\winnt32\srv_x86.dll -
02ba7052dcaabd1b6bf515209218eb735c05793327f9d8b39f070249d43f6e76 - C:\Users\analyst\AppData\Roaming\Microsoft\XMMC\csrssys.exe -
3ba4e69a88652fe7e61def02b63ec647a4fe2743a876bedc147e517de51e9ce0 - C:\Users\analyst\AppData\Roaming\Microsoft\XMMC\msys.exe -
10550f2d4806cd22b0346d884b3683830606e002efa9f24a656be12970605d6d - C:\Users\analyst\AppData\Roaming\Microsoft\XMMC\mdata\nt32.dll -
c0da7d0611be288c3904ee0df47e8f529b0b0b9e888b9644238957c4e7317c33 - 86e3d45ea9733e32559c3e6af368f1c04eb9b2769a2b6ce3b980cdb67a76a000 -
86e3d45ea9733e32559c3e6af368f1c04eb9b2769a2b6ce3b980cdb67a76a000
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- nwoccs.zapto.org
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 4.150.223.106
- 48.211.4.16
- 20.247.184.142
- 4.230.171.124
- 4.247.188.233
- 20.50.201.203
- 74.178.76.54
- 74.178.76.128
- 4.150.223.115
- 172.64.154.167
- 57.154.63.210
- 135.233.45.223
- 125.56.205.24
- 125.56.205.26
- 20.42.65.89
- 51.105.71.136
- 52.148.114.188
- 72.154.7.106
- 52.110.12.42
- 52.110.12.28
File paths
- H:\:p:
More Qakbot samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report