MALICIOUS — moxa-uport-1200-1400-1600-series-windows-7-10-windows-server-2008-r2-2019-whql-certified-driver-v3.2.exe
MALICIOUS — moxa-uport-1200-1400-1600-series-windows-7-10-windows-server-2008-r2-2019-whql-certified-driver-v3.2.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (77/100). 0 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8e826841b93a60e12f85a660515cc2095c6578400eb57c13fc56647afed2ee7f - SHA-1:
5f8f3f1a890ea10efe6d37ab4b881231ab73c1d2 - MD5:
f2f239158968c16a9a31cb5b14323a01 - imphash:
20dd26497880c05caed9305b3c8b9109 - ssdeep:
98304:x5CHiaqivD1f4uWBjsHNOhYau30hxJ31BVO5pV9u16:x5CHUKFSUNi8Yx1BApVMk - TLSH:
T18E6123AC4B7F7BF6DD269804FA0619DE9470A648C918BC189477742CBBF0073AD4096E - Submitted as: moxa-uport-1200-1400-1600-series-windows-7-10-windows-server-2008-r2-2019-whql-certified-driver-v3.2.exe
- File type: pe · Size: 4175928 bytes
- Verdict: malicious (77/100)
Detections (0 of 55 engines)
No engine flagged this sample.
MITRE ATT&CK
Why this verdict
The malicious score of 77/100 is the fusion of 4 weighted signals:
- Memory forensics: 4 finding(s), e.g. RWX/private injected region in tsk_d0a7aed585 (pid 9024) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Contacted 32 external host(s) at runtime (28 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdline - static signal, weight 0.35, confidence 0.60
- Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
473 behavior events · 0 ATT&CK techniques · 5 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- config.edge.skype.com
- v20.events.data.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\is-JFOGI.tmp\_isetup\_setup64.tmp -
388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95 - C:\Users\analyst\AppData\Local\Temp\is-JFOGI.tmp\mxDrvHlp.dll -
57449c16942c7ab69da9e89f3d54d74f58a8489c82bb68b5a04fa59160d20756 - C:\Users\analyst\AppData\Local\Temp\is-1UPSS.tmp\tsk_d0a7aed585114b07.tmp -
9c81817acd4982632d8c7f1df3898fca1477577738184265d735f49fc5480f07 - c46fb6e1a00459cdb5360572f1d456260fa33ebf85ea9e0ae4a00e6575a12f52 -
c46fb6e1a00459cdb5360572f1d456260fa33ebf85ea9e0ae4a00e6575a12f52 - c87924ff84e7982cd8af2a47ca5b64a8d375a428ab386ec8709e5a56958f3943 -
c87924ff84e7982cd8af2a47ca5b64a8d375a428ab386ec8709e5a56958f3943
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- https://www.digicert.com/CPS0
- http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
- http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
- http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
- http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
- http://www.digicert.com/ssl-cps-repository.htm0
- http://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
- http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdline
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787744382&P2=404&P3=2&P4=YshQyuCFP7gQJBmGj2cNxBMxqOUug55AjXtWs48g%2fruzcJdWD9QLULSKQQka9%2fpiWCxrnRHBlnr6fh9NfeyogA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787744427&P2=404&P3=2&P4=bkC784hX%2bLs9ialzxAktgvJXpXcrFslduftBlNtXP8ARxdhr1HEAueWP4rSku2DszhYzF8TBKxoJYivSLAZLbg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/b56480f9-8215-4de7-ba7e-8e690088d21d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787141183&P2=404&P3=2&P4=N9JVqMB1kxL0y%2bKivRkJnIQQ6gqym%2bSALAaxaKnUXGxWlmLEId50szsdhmPP%2bJDQUG2gk7i6u9NchZ1wUf48sQ%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/b56480f9-8215-4de7-ba7e-8e690088d21d?P1=1787140676&P2=404&P3=2&P4=gx7KVJJSS3LRaPDt5y0UJWEL14GU12fVVhupDjcdb13BxdbC1HW9jSgeuXKeA6jRvrE2BPMG2PGOq2Gp0PcTsg%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- schemas.microsoft.com
- h.me
- k0.au
- crl.microsoft.com
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- cacerts.digicert.com
- www.jrsoftware.org
Embedded IP addresses
- 203.26.79.13
- 135.233.95.80
- 142.251.42.99
- 52.123.252.194
- 20.184.175.6
- 4.230.171.124
- 20.42.179.204
- 20.247.185.124
- 52.123.252.224
- 74.178.240.61
- 135.232.92.97
- 13.89.179.15
- 20.236.44.162
- 52.123.128.14
- 20.184.175.19
- 74.178.76.44
- 135.234.160.246
- 162.159.142.9
- 52.148.114.188
- 172.66.2.5
- 72.153.5.131
- 135.234.160.245
- 4.209.250.170
- 52.110.12.10
- 52.110.12.2
File paths
- h:\J3
- x:\dirname
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report