MALICIOUS — 9145b9bf46b2ef5e0be4f6131c7eb616268126c517684b5c85038663b2fbd123
MALICIOUS — 9145b9bf46b2ef5e0be4f6131c7eb616268126c517684b5c85038663b2fbd123 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Redirect family. 5 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
9145b9bf46b2ef5e0be4f6131c7eb616268126c517684b5c85038663b2fbd123 - SHA-1:
99b2aac5a8e6ba8c9e4431b9dd8d05a83dd2bcae - MD5:
29498981cc28c2fa64dc4fa1b77f1ebf - imphash:
11b47caef64b54d3c3efa7c94546ad2b - ssdeep:
3072:mQchyinW3kIncLnntG/j/BJ5mTxjnw89JnszQcJdXV:mkin4kwcDtG/j/75YxF52dXV - TLSH:
T1E9417ABF754F6EE6E585CC22426CFB2D337DC95835C10714A83A98BF363A9A30854611 - Submitted as: 9145b9bf46b2ef5e0be4f6131c7eb616268126c517684b5c85038663b2fbd123
- File type: pe · Size: 185888 bytes
- Verdict: malicious (98/100) · Family: Redirect
Detections (5 of 52 engines)
- ClamAV (daily): Win.Trojan.Redirect-6055402-0
- Kaspersky (KVRT): Trojan.Win32.ShipUp.boq
- Microsoft Defender: Trojan:Win32/ShipUp!pz
- Emsisoft (Emergency Kit): Trojan.Ransom.Cerber.1
- Trellix Stinger (McAfee): Packed-AM!29498981CC28
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Redirect-6055402-0 (rule
Win.Trojan.Redirect-6055402-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Downware): d3d14c684db75ac98d9a034ae2800bfafa156f6d74e5933b3968813bb4f080e4 - dynamic signal, weight 0.80, confidence 0.90
- Contacted 57 external host(s) at runtime (18 HTTP) - network signal, weight 0.40, confidence 0.80
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
2424 behavior events · 1 ATT&CK techniques · 6 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- config.edge.skype.com
- v20.events.data.microsoft.com
- windows.msn.com
- licensing.mp.microsoft.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- settings-win.data.microsoft.com
- www.bing.com
Dropped files
- /opt/CAPEv2/storage/analyses/26550/files/10250c5dcf408dbf69235950c6c35b5c8ec590311e38fd35cee7c95a5f907d5a -
10250c5dcf408dbf69235950c6c35b5c8ec590311e38fd35cee7c95a5f907d5a - /opt/CAPEv2/storage/analyses/26550/files/d3d14c684db75ac98d9a034ae2800bfafa156f6d74e5933b3968813bb4f080e4 -
d3d14c684db75ac98d9a034ae2800bfafa156f6d74e5933b3968813bb4f080e4 - 84a03fd05c979d084a8d1e890a67e4a60ca10584961422b31443e87c8449e018 -
84a03fd05c979d084a8d1e890a67e4a60ca10584961422b31443e87c8449e018 - 810e21811e2749596905149f4b9c91d5195d7a40703182683f489ee540163bee -
810e21811e2749596905149f4b9c91d5195d7a40703182683f489ee540163bee - 3b328dd1a64534b106a3f7ecbf8eebdaddb6d56fea932a02ab918e06a48be256 -
3b328dd1a64534b106a3f7ecbf8eebdaddb6d56fea932a02ab918e06a48be256 - 0b034a19882df01571e71240c339c0fcb0b9d8adc1dd0f6108f6e4501243913c -
0b034a19882df01571e71240c339c0fcb0b9d8adc1dd0f6108f6e4501243913c
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 52.110.12.22
- 4.150.223.101
- 52.110.12.16
- 20.247.184.142
- 40.84.85.40
- 4.230.171.124
- 51.104.15.253
- 20.236.44.162
- 40.99.133.226
- 135.233.45.221
- 52.110.12.42
- 51.104.15.252
- 52.110.12.26
- 135.233.95.144
- 135.232.92.137
- 135.232.92.97
- 52.178.17.233
- 52.110.12.30
- 52.148.114.188
- 20.76.201.171
- 149.154.167.99
- 74.179.77.204
- 162.159.36.2
- 40.103.64.226
- 52.110.12.2
More Redirect samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report