SUSPICIOUS — 93c0f50b245202f226c7e6cbc4aba07d409c20ebe84a804b4d31a437eb4f6753
SUSPICIOUS — 93c0f50b245202f226c7e6cbc4aba07d409c20ebe84a804b4d31a437eb4f6753 is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (67/100), attributed to the ASPack family. 3 of 52 detection engines flagged it.
Identification
- SHA-256:
93c0f50b245202f226c7e6cbc4aba07d409c20ebe84a804b4d31a437eb4f6753 - SHA-1:
a051dcf7e2a88c11cc98077fa3c2a194ad4b3117 - MD5:
579e44f7c05904c1cecd0cf35dc4f2de - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
3072:Z3WEUOvV9HkPsp3QkZPPI7zV9/7xtNo1El94BJTeSkqLucP:RWET9EP43QYPPGXbNoOl94BASXX - TLSH:
T1193E129C8430A7EBD5404E607BF6EDBD160C043870F1378F52A6268A74EFE63965C5A8 - Submitted as: 93c0f50b245202f226c7e6cbc4aba07d409c20ebe84a804b4d31a437eb4f6753
- File type: pe · Size: 143360 bytes
- Verdict: suspicious (67/100) · Family: ASPack
Detections (3 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:,,,
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:ASProtect 1.23-2.56
Why this verdict
The suspicious score of 67/100 is the fusion of 4 weighted signals:
- Contacted 51 external host(s) at runtime (17 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:ASProtect 1.23-2.56 (rule
DIE:ASProtect 1.23-2.56) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:,,,, ASProtect 1.23-2.56 - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
9 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- settings-win.data.microsoft.com
- officeclient.microsoft.com
- www.bing.com
- oneocsp.microsoft.com
- tas02.sls.update.microsoft.com
- v10.events.data.microsoft.com
- to-do.microsoft.com
- watson.events.data.microsoft.com
- www.microsoft.com
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 74.178.76.44
- 20.42.73.26
- 172.215.188.232
- 52.110.12.24
- 4.150.223.108
- 4.150.223.101
- 52.123.252.198
- 149.154.167.99
- 149.154.165.133
- 57.154.63.210
- 20.247.184.142
- 4.230.171.124
- 135.234.160.245
- 135.234.160.244
- 40.84.97.4
- 52.123.252.223
- 172.178.240.162
- 72.145.35.112
- 48.211.4.16
- 135.233.95.144
- 4.150.223.97
- 74.178.240.51
- 52.110.12.11
- 74.178.240.61
- 20.165.94.46
More ASPack samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report