MALICIOUS — 9302af07ea59797737a7a03df81222c8578a906d0f16f9de878d913815bb8fda
MALICIOUS — 9302af07ea59797737a7a03df81222c8578a906d0f16f9de878d913815bb8fda is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Remcos family. 7 of 56 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
9302af07ea59797737a7a03df81222c8578a906d0f16f9de878d913815bb8fda - SHA-1:
367fb5fd438ad7fd18f7f21626b45c52aad8fc4b - MD5:
1a1809988ed8f631ea58e01047803c25 - imphash:
ac0eeb9445380b88a6022d3d601931ba - ssdeep:
12288:Th11Yrvt9Epl2GElIDG4arbKu44IvM3G0/e1w4OEjt/n:Th1SpM2tWMGHJvM20WJVjt/ - TLSH:
T13F509EBE3377B343CA3EC96608A59F0F0635EC8962352C4C156B443EB2E6DA7B548254 - Submitted as: 9302af07ea59797737a7a03df81222c8578a906d0f16f9de878d913815bb8fda
- File type: pe · Size: 764416 bytes
- Verdict: malicious (100/100) · Family: Remcos
Detections (7 of 56 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Dropper.Remcos-9909717-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): Trojan.Injector
- Trellix Stinger (McAfee): Fareit-FDBI!1A1809988ED8
- Kaspersky (KVRT): HEUR:Backdoor.Win32.Remcos.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 15 weighted signals:
- ClamAV (daily) flagged Win.Dropper.Remcos-9909717-0 (rule
Win.Dropper.Remcos-9909717-0) - engine signal, weight 0.90, confidence 0.95 - 2 behavioral detection(s) across 2 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.63, confidence 0.90 - Microsoft Defender flagged flagged (rule
flagged) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Injector (rule
Trojan.Injector) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Fareit-FDBI!1A1809988ED8 (rule
Fareit-FDBI!1A1809988ED8) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Backdoor.Win32.Remcos.gen (rule
HEUR:Backdoor.Win32.Remcos.gen) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 2 external host(s) and 11 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Extracted Remcos config (0 C2) - engine signal, weight 0.45, confidence 0.60
- capa (capabilities) flagged capability:collection/keylog (rule
capability:collection/keylog) - engine signal, weight 0.35, confidence 0.70 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
12649 behavior events · 3 ATT&CK techniques · 19 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- www.rgpenerji.com.tr
- yr.c.lencr.org
- yr2.c.lencr.org
- www.ubsgolds.com
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
Dropped files
- C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751 -
3dd5ea8a14eb665ba6057d424f94e5e83757ffaab456578dbf038af04053b19e - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F15827BEC5BABE89C21DCDAE77464BF1 -
108dd34232a3088b45534933d0486409616a2bbad94fd8f7ab5991c01ff179b6 - C:\Users\analyst\AppData\Roaming\ubsgolds\logs.dat -
42b4880c78774e927fc39893ff4f47a3a2f664270b3a038b6b926b63a5203e18 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F15827BEC5BABE89C21DCDAE77464BF1 -
bc4ffe5c022560e1e92ef867e95a95e37a83e8d7144427d5b1899193030c130f - C:\Users\Public\Libraries\Pvepqute\etuqpevP.url -
82f66d523c379a7c36328fc01f80c0fba06767481bf1ee863b4b31e08531625c - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\359192549888AB9224A11F5480CB68CA -
51219b73627a0ba7d39b6bc8a08ca42721004e9c9185504eb2fd2e11e90e82c1 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751 -
83677a5dd1f14f749d29cc7429a8ed13b769fe5eb41f12d34fd68bcd677e3a2b - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\359192549888AB9224A11F5480CB68CA -
688e98305360318c54cc7e6170775bee15fac92187af10079682d3ceb15e905d - e2b5172ef464c05f973ac9d6a6f269996db35eeaf818cf63ac3843e80bbb7ee0 -
e2b5172ef464c05f973ac9d6a6f269996db35eeaf818cf63ac3843e80bbb7ee0 - a2429f03811991560728e0fc4f75d071a54753303482706f75d91dde1443c631 -
a2429f03811991560728e0fc4f75d071a54753303482706f75d91dde1443c631 - 43535ae84529257d3fb334e981c83575eb7562900ea8401920bf18c3adebcb5d -
43535ae84529257d3fb334e981c83575eb7562900ea8401920bf18c3adebcb5d - 0c4b18b6d60e92eb60043d0ca1a12609ed060b67d56032695f1986fb9540a18c -
0c4b18b6d60e92eb60043d0ca1a12609ed060b67d56032695f1986fb9540a18c - c536ec64d382b601f95d8bbe74d9e18e5a18228854419cf91b87001d34ee49cb -
c536ec64d382b601f95d8bbe74d9e18e5a18228854419cf91b87001d34ee49cb - 7171ba6654340107cfb150368a31e5840499d9b2adf4f28a0ba28589a63d7d0c -
7171ba6654340107cfb150368a31e5840499d9b2adf4f28a0ba28589a63d7d0c - 75109f5f393e59eba8ffb9d4919834bb470d4bc30dd61b200b28b9c44b865edc -
75109f5f393e59eba8ffb9d4919834bb470d4bc30dd61b200b28b9c44b865edc
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://yr.c.lencr.org/
- http://yr2.c.lencr.org/123.crl
Embedded domains
- po.uk
- www.rgpenerji.com.tr
- x1.c.lencr.org
- yr.c.lencr.org
- yr2.c.lencr.org
- www.ubsgolds.com
Embedded IP addresses
- 4.150.223.106
- 52.123.252.215
- 4.230.171.124
- 40.84.97.4
- 20.247.184.197
- 135.233.95.135
- 74.179.77.204
- 52.168.112.67
- 4.150.223.104
- 20.165.94.63
- 89.252.169.15
- 104.18.21.213
- 72.153.5.138
- 52.148.114.188
- 52.110.12.21
- 52.110.12.3
File paths
- X:\:`:d:
- X:\:`:d:h:l:p:t:x:
- X:\:`:d:h:l:
- R:\:d:p:
- G:\:
- X:\:`:d:h:
- T:\:d:l:t:
More Remcos samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report