MALICIOUS — 9175b09ea911110f5eb50a526be54e2b4b06e9ca4c90de205c8f934990f710f5
MALICIOUS — 9175b09ea911110f5eb50a526be54e2b4b06e9ca4c90de205c8f934990f710f5 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the 004BF035 family. 5 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
9175b09ea911110f5eb50a526be54e2b4b06e9ca4c90de205c8f934990f710f5 - SHA-1:
edb05fefb5b57e952a06ec28e2d24d3ed89cc020 - MD5:
48e7bba4949cf11c7f157e026f8753ba - imphash:
62ec3dce1eba1b68f6a4511bb09f8c2c - ssdeep:
6144:45TD4cQPEUVMuTVCGBmyDGJr/NFqpMuTVCGNg6zEH/nMuTVCGBmyDGJr/NFqpMu:45gWuhKd/NVuh1g5kuhKd/NVuh - TLSH:
T1F84A18826E00E595EFA4B20BA08DFA5DC3E6382D71676D11D61BA050582E7FFE4C035E - Submitted as: 9175b09ea911110f5eb50a526be54e2b4b06e9ca4c90de205c8f934990f710f5
- File type: pe · Size: 458752 bytes
- Verdict: malicious (96/100) · Family: 004BF035
Detections (5 of 55 engines)
- ClamAV (daily): Win.Trojan.Crypted-29
- Microsoft Defender: Backdoor:Win32/Berbew.AA!MTB
- Emsisoft (Emergency Kit): GenPack:Generic.Dacic.1.Backdoor.Hangup.A.004BF035
- Trellix Stinger (McAfee): Trojan-FUGH!48E7BBA4949C
- Kaspersky (KVRT): Trojan-Proxy.Win32.Qukart.vih
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypted-29 (rule
Win.Trojan.Crypted-29) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 3 finding(s), e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.55, confidence 0.85 - Contacted 24 external host(s) at runtime (20 HTTP) - network signal, weight 0.40, confidence 0.80
- Dropped 100 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
3129 behavior events · 1 ATT&CK techniques · 100 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Dropped files
- C:\Windows\System32\Eoheoj32.dll -
711ac6e38efa6b52bf07b6db0d9a7212179740c7d630f200737e4eed4c84e0ad - C:\Windows\System32\Gfqbbdgd.exe -
8719363ddef92c6bfb9f77e2dd26985cdd91079cbce4e0073cf1961624ea2d24 - C:\Windows\System32\Pdahoe32.exe -
6951b0a5d36e837d14547e74f3b6bbaab77fa7d3baad9f73e7ba23ab316ceed5 - C:\Windows\System32\Jhbloh32.dll -
02f5061ec4267dc52d8825684c00b8c6cadc865f51842e3fd0493fdd1df7350c - C:\Windows\System32\Mhdlak32.dll -
975c4f6239b866ebc8f30b13597135840098004ddbfef89607eb1cf654f8d906 - C:\Windows\System32\Lojjfp32.exe -
38c5d2bab5b53c3f3861e98db79e87b6045ee7ca5e820ebb9b70bb9c7816e036 - C:\Windows\System32\Cglfejih.exe -
f33c727504f4e00624ef8adc8b86e4640ee7002070871287962dcd92dd69a5b6 - C:\Windows\System32\Biqjne32.exe -
e6d778b28f8492fd3d81c4ffb086e34d9e8fa969c6e8e35077b28064c1cc2e08 - C:\Windows\System32\Pgjnle32.exe -
8e1fd42a6dfd249da420641823fe18251f8f546bf1a56a4c8d456f68400bb6c8 - C:\Windows\System32\Imbaff32.dll -
564a5fc1e944ba0569351c1aae194d74324a26d3bd9fd5da4e7c0300d7a33ca8 - C:\Windows\System32\Pkmfghbf.exe -
5ad7d1d42185a5b0acabc078f468dd7899476a69e20127583b8b3fdc54e58aba - C:\Windows\System32\Kgabpmcd.dll -
2016d6a2dc6908f25080de35531974d85b405448b76838156499ae10f84df1b0 - C:\Windows\System32\Hiojif32.exe -
5fc54389c28e16473a02ca91da94d002a763f5f585ef8881be14dd01de8eb521 - C:\Windows\System32\Hdcpedbg.dll -
a4ceaf693a7dc18911fa2f64f6bc96d96be3b741bb80ee75c8956797528ded76 - C:\Windows\System32\Faijonfb.dll -
0b6b1f25c6b1afcc3131f4fd8ed509c88af54bf22210bcfdf2a6543ef531251b
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787808676&P2=404&P3=2&P4=A3XdZRcS9CUvaTM%2f9EYwnd2cuqLLHOALNgWDeXCeCzhtk3Yu8a8kspiSqFKmZ3brJX2lSgvi0qUUHk0aEVih1g%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787808744&P2=404&P3=2&P4=GcjDh0iROdpi6d3mpUIVw0rWM2ONMgDfK3v6dwpDxQRl7GQsbIlOIGcIKTHsXAkJKKlRbGVV%2b91XU1tbd0ZquA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 52.123.252.236
- 52.168.112.66
- 4.230.171.124
- 85.210.196.11
- 20.247.184.142
- 20.165.94.63
- 74.178.240.51
- 4.207.44.72
- 20.76.201.171
- 52.123.128.14
- 52.123.129.14
- 172.178.240.163
- 172.66.2.5
- 203.26.79.13
- 52.148.114.188
- 52.123.252.195
- 135.232.92.34
- 52.123.252.222
- 125.56.205.19
- 125.56.205.51
- 40.84.97.4
- 72.154.7.109
- 52.110.12.26
- 52.110.12.51
More 004BF035 samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report