MALICIOUS — 96b1b0b2b58388545a873089511a1416269e64346746fffe28cdffecbb90d615
MALICIOUS — 96b1b0b2b58388545a873089511a1416269e64346746fffe28cdffecbb90d615 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Fileinfector family. 5 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
96b1b0b2b58388545a873089511a1416269e64346746fffe28cdffecbb90d615 - SHA-1:
0cf43ce06602a35a2d3ae10a3de48b77f136c51f - MD5:
0b6f8bb7f6b75b1583d125b7dd6b7d08 - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
3072:0EqOnjvZtmdsgkUwGhHBk/Xw9AQtdavznn2pIyHWSH2z0tCnz21XUUu/tIZt/Hg:0v1HBk/Xw9AQtdavznn2pIyHWSH2z0t - TLSH:
T15F3CA55F522F89CFF55A8A836B38051CF25E34D337127B8A852897879C2020B9B1D75B - Submitted as: 96b1b0b2b58388545a873089511a1416269e64346746fffe28cdffecbb90d615
- File type: pe · Size: 118784 bytes
- Verdict: malicious (92/100) · Family: Fileinfector
Detections (5 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Dropper.Fileinfector-9836765-0
- Microsoft Defender: Trojan:Win32/CryptInject!pz
- Emsisoft (Emergency Kit): Trojan.GenericKD.39862403
- Kaspersky (KVRT): Virus.Win32.Lamer.ks
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Dropper.Fileinfector-9836765-0 (rule
Win.Dropper.Fileinfector-9836765-0) - engine signal, weight 0.90, confidence 0.95 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://www.pinkworld.com, http://www.youporn.com, http://www.redtube.com - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: UPX - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.pinkworld.com
- http://www.youporn.com
- http://www.redtube.com
- http://www.assparade.com/
- http://www.freeav.com/
- http://www.antispyware.com/
- http://www.antivirus.com/
- https://www.update.microsoft.com/v6/ClientWebService/client.asmx
- http://download.windowsupdate.com/d/msdownload/update/others/2019/10/30042061_1ee4f09953a673002064735ca01fff41e7174a91.cab
- http://download.windowsupdate.com/d/msdownload/update/others/2019/10/30042029_2d8b593d0f60520899411405c636b24290e77602.cab
- http://download.windowsupdate.com/d/msdownload/update/software/defu/2019/07/mpsigstub_ffb7e023a6e562d4012165c1f97ead869770441e.exe
- http://download.windowsupdate.com/d/msdownload/update/software/defu/2019/09/as_engine_543ce9895ebdb7c2ed2b493ef6733f9d0082b297.exe
- http://download.windowsupdate.com/d/msdownload/update/software/defu/2019/09/as_base_f9d23c867f448b33ac248dd76ed5a0c44515f03c.exe
- http://download.windowsupdate.com/c/msdownload/update/software/defu/2019/10/as_delta_31d3ec8562d6332ca7ddd8a6d5de4c4df676225d.exe
Embedded domains
- www.pinkworld.com
- www.youporn.com
- www.redtube.com
- www.assparade.com
- www.freeav.com
- www.antispyware.com
- www.antivirus.com
- www.update.microsoft.com
- download.windowsupdate.com
Embedded IP addresses
- 6.1.1.1
File paths
- C:\Windows\system32\svchost.exe
- c:\windows\system32\wuaueng.dll
- C:\Windows\SoftwareDistribution
- c:\program
- C:\Windows\system32\wuapi.dll
- C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab:
- C:\Windows\SoftwareDistribution\Download\b290a7b165666faba8078c785af7cc48\ffb7e023a6e562d4012165c1f97ead869770441e
- C:\Windows\SoftwareDistribution\Download\59a4232c5c2633ebdcc62778481d6cf1\543ce9895ebdb7c2ed2b493ef6733f9d0082b297
- C:\Windows\SoftwareDistribution\Download\484aaf207c92e9262ef15b093b5590a0\f9d23c867f448b33ac248dd76ed5a0c44515f03c
- C:\Windows\SoftwareDistribution\Download\5b625ca0a52d55d33797db18d668a6ca\31d3ec8562d6332ca7ddd8a6d5de4c4df676225d
- C:\Windows\SoftwareDistribution\Download\b290a7b165666faba8078c785af7cc48\ffb7e023a6e562d4012165c1f97ead869770441e:
- C:\Windows\SoftwareDistribution\Download\59a4232c5c2633ebdcc62778481d6cf1\543ce9895ebdb7c2ed2b493ef6733f9d0082b297:
- C:\Windows\SoftwareDistribution\Download\5b625ca0a52d55d33797db18d668a6ca\31d3ec8562d6332ca7ddd8a6d5de4c4df676225d:
- C:\Windows\SoftwareDistribution\Download\484aaf207c92e9262ef15b093b5590a0\f9d23c867f448b33ac248dd76ed5a0c44515f03c:
- C:\Windows\system32\wuauclt.exe
- C:\Windows\system32\wuaueng.dll
- C:\Windows\system32\wusa.exe
- C:\bc8aeeebe623911bc51e28b970\wsusscan.cab
- C:\Windows\SoftwareDistribution\ScanFile\b5572015-ee42-40d0-a6db-fe7e47754898\Source.cab:
- C:\Windows\SoftwareDistribution\Download\3113c6d599a3a2b1ecafecbe68cc9745_ctc
- C:\Windows\SoftwareDistribution\Download\3113c6d599a3a2b1ecafecbe68cc9745_ctc\Windows6.1-KB3118401-x86.cab:
- C:\Windows\SoftwareDistribution\Download\3113c6d599a3a2b1ecafecbe68cc9745\Windows6.1-KB3118401-x86.cab,
- C:\Windows\SoftwareDistribution\Download\3113c6d599a3a2b1ecafecbe68cc9745\inst
More Fileinfector samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report