MALICIOUS — 049_Duqu2.bin
MALICIOUS — 049_Duqu2.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Duqu family. 4 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8e97c371633d285cd8fc842f4582705052a9409149ee67d97de545030787a192 - SHA-1:
2422835716066b6bcecb045ddd4f1fbc9486667a - MD5:
e8eaec1f021a564b82b824af1dbe6c4d - imphash:
248803ea355446e56e172d44fb463a71 - ssdeep:
192:Ty0m/YkX4KczWxF6Kj3IZ4ZItSfj4nHe/u2hO/tv/MFR3bddlqnLNuyKgAYmcDu:+0mDLczWxF7yvHo2p8diZuygFmu8 - TLSH:
T1CD28846D576B1351C2DA88F87334439C60C97A6F26706EED1483B298F0FA21369E6077 - Submitted as: 049_Duqu2.bin
- File type: pe · Size: 17920 bytes
- Verdict: malicious (99/100) · Family: Duqu
Detections (4 of 51 engines)
- Cyble Vision: Cyble Vision: Malicious
- Microsoft Defender: Trojan:Win32/Duqu2.F!dha
- Emsisoft (Emergency Kit): Trojan.Duqu.F
- Trellix Stinger (McAfee): PWS-Duqu.b!E8EAEC1F021A
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 6 weighted signals:
- Cyble Vision flagged Cyble Vision: Malicious (rule
Cyble Vision: Malicious) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Duqu2.F!dha (rule
Trojan:Win32/Duqu2.F!dha) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Duqu.F (rule
Trojan.Duqu.F) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PWS-Duqu.b!E8EAEC1F021A (rule
PWS-Duqu.b!E8EAEC1F021A) - engine signal, weight 0.55, confidence 0.85 - Contacted 30 external host(s) at runtime (4 HTTP) - network signal, weight 0.40, confidence 0.80
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
97 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- v10.events.data.microsoft.com
- login.live.com
- settings-win.data.microsoft.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- fd.api.iris.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- licensing.mp.microsoft.com
- tsfe.trafficshaping.dsp.mp.microsoft.com
- watson.events.data.microsoft.com
- www.bing.com
- msedge.api.cdp.microsoft.com
- edge.microsoft.com
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- www.sysinternals.com
- inference.location.live.net
- oneclient.sfx.ms
Embedded IP addresses
- 23.40.52.209
- 4.150.223.112
- 85.210.196.11
- 52.182.141.63
- 150.171.22.17
- 4.230.171.124
- 20.190.142.166
- 57.155.101.212
- 20.247.184.142
- 72.147.149.16
- 20.184.175.11
- 135.233.45.222
- 135.232.92.34
- 23.33.238.102
- 23.33.238.171
- 135.149.173.69
- 4.150.223.104
- 23.198.40.44
- 23.33.238.135
- 23.221.133.185
- 92.223.78.30
- 72.153.5.129
- 52.148.114.188
- 20.184.175.15
- 23.40.52.211
More Duqu samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report