MALICIOUS — 97f03565f485af62998dfaa5283f8f61118c3a6315cb3112a2bd0f41c1f07222
MALICIOUS — 97f03565f485af62998dfaa5283f8f61118c3a6315cb3112a2bd0f41c1f07222 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100). 5 of 55 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
97f03565f485af62998dfaa5283f8f61118c3a6315cb3112a2bd0f41c1f07222 - SHA-1:
94f80a0ed5708e7e7b3466fc3786bb0781468e6d - MD5:
efa26eb9bb7a7246763c07f1616b144f - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
98304:SK6jEmm+9h3VnWDSE5DOq52UTdOFJJ1HeRAdUQ5OVEHoDPxF:S7Imm+ZxebMOkJJ1HeAxgEHcPX - TLSH:
T17A67ADCC035B677ED8F5A13214845DAD6A9971A36D35381E1A90DF31003A273EEBE06E - Submitted as: 97f03565f485af62998dfaa5283f8f61118c3a6315cb3112a2bd0f41c1f07222
- File type: pe · Size: 6957056 bytes
- Verdict: malicious (100/100)
Detections (5 of 55 engines)
- YARA: MalwareAnalyser built-in: Suspicious_PowerShell_Download_Exec
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- Microsoft Defender: Trojan:Win32/Wacatac.B!ml
- Kaspersky (KVRT): VHO:Trojan-PSW.MSIL.Agensla.gen
MITRE ATT&CK
YARA
- Suspicious_PowerShell_Download_Exec
Why this verdict
The malicious score of 100/100 is the fusion of 16 weighted signals:
- Encoded/hidden PowerShell download-and-exec (rule
Suspicious_PowerShell_Download_Exec) - yara signal, weight 0.70, confidence 0.90 - Microsoft Defender flagged Trojan:Win32/Wacatac.B!ml (rule
Trojan:Win32/Wacatac.B!ml) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged VHO:Trojan-PSW.MSIL.Agensla.gen (rule
VHO:Trojan-PSW.MSIL.Agensla.gen) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s) across 1 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Contacted 4 external host(s) and 17 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082, T1622, T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- YARA: MalwareAnalyser built-in flagged Suspicious_PowerShell_Download_Exec (rule
Suspicious_PowerShell_Download_Exec) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-sections:.text (rule
high-entropy-sections:.text) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://www.facebook.com/8591PostBot, http://www.newtonsoft.com/jsonschema, https://www.nuget.org/packages/Newtonsoft.Json.Bson - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60 - Extracted generic config (3 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
39386 behavior events · 2 ATT&CK techniques · 5 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- www.8591.com.tw
- 8591postbot.azurewebsites.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
Dropped files
- c25f34f368801ee52a3c7d747d8952c5f9e38280781291538b870636b9e032e2 -
c25f34f368801ee52a3c7d747d8952c5f9e38280781291538b870636b9e032e2 - 0256690c9678547f1826e3ec46cab70cdf18bd27d0b1b2b509d914aec328d196 -
0256690c9678547f1826e3ec46cab70cdf18bd27d0b1b2b509d914aec328d196 - a1f733debd0cf65a6aa3298e6adbf1ab62eb820e3301a57f0d47067a36a371b0 -
a1f733debd0cf65a6aa3298e6adbf1ab62eb820e3301a57f0d47067a36a371b0 - 7dbf2371ef664f6e5517523620e7bb15ff1d057be2ed425cd1f345189a38cf1a -
7dbf2371ef664f6e5517523620e7bb15ff1d057be2ed425cd1f345189a38cf1a - ac2f2c5eb34bcde7cf102cc7ca733f76a5b5cfbaa32c0b37eb8ec769e5dfab63 -
ac2f2c5eb34bcde7cf102cc7ca733f76a5b5cfbaa32c0b37eb8ec769e5dfab63
Embedded URLs
- https://www.facebook.com/8591PostBot
- http://www.newtonsoft.com/jsonschema
- https://www.nuget.org/packages/Newtonsoft.Json.Bson
- https://addcn.blob.core.windows.net/static/js/ued/ui/xheditor/xheditor_skin/default/ui.css
- https://addcn.blob.core.windows.net/static/js/ued/ui/xheditor/xheditor_skin/default/iframe.css
- https://addcn.blob.core.windows.net/static/js/ued/vendor/jquery-1.8.2.min.js
- https://addcn.blob.core.windows.net/static/js/ued/ui/xheditor/xheditor-1.2.1.tw.min.js?v=12241
- https://addcn.blob.core.windows.net/static/js/ued/ui/xheditor/xheditor_plugins/ubb.js
- https://www.google.com.twhttps://www.8591.com.tw
- https://8591postbot.blob.core.windows.net/public/EstimateSumOfBusinessWav.mp3
- http://www.8591.com.tw/index.php?module=deal&action=buy
- http://www.8591.com.tw/userCenter-myWare.html
- https://8591postbot.azurewebsites.net/api/verifyV3
- http://8591postbot.azurewebsites.net/api/verifyV3
- http://blackpanther.pixnet.net
- http://www.8591.com.tw/index.php
- http://www.8591.com.tw/
- http://www.8591.com.tw/index.php?module=orders&action=orderList
- http://www.8591.com.tw/index.php?module=wareCar&action=index
- http://www.8591.com.tw/index.php?module=userCenter&action=myBuy
- http://www.8591.com.tw/index.php?module=userCenter&action=deal&do=sell&type=1&exValue=exclusive
- http://www.8591.com.tw/index.php?module=wareQuestion&action=newSellQuestion&type=noAnswer
- http://www.8591.com.tw/publish-publish.html
- http://www.8591.com.tw/ware-postSell.html
- http://www.8591.com.tw/index.php?module=userCenter&action=deal&do=sell&type=4
Embedded domains
- www.facebook.com
- www.newtonsoft.com
- www.nuget.org
- u.fr
- at.cc
- v.kr
- cs.tw
- addcn.blob.core.windows.net
- paint.net
- blackpanther.pixnet.net
- 463032408591postbot.azurewebsites.net
- www.8591.com.tw
- 8591postbot.blob.core.windows.net
- 8591postbot.azurewebsites.net
- 8591.com.tw
- maxcdn.bootstrapcdn.com
- vnd.net
- x-script.sh
- www.w3.org
- james.newtonking.com
- chat.8591.com.tw
- im.8591.com.tw
- m.8591.com.tw
- upload.8591.com.tw
- schemas.openxmlformats.org
Embedded IP addresses
- 3.6.4.6
- 3.7.3.3
- 21.1.30.2
- 51.116.253.170
- 4.144.132.114
- 4.230.171.124
- 168.62.20.37
- 3.175.115.13
- 20.209.103.4
- 20.60.131.4
- 20.42.179.204
- 4.150.223.98
- 20.42.65.94
- 172.178.240.162
- 20.42.179.192
- 72.154.7.100
- 52.148.114.188
- 52.110.12.25
- 52.110.12.14
File paths
- C:\Users\Panther\AppData\Local\Microsoft\VisualStudio\SSDT\T1db.mdf;Integrated
- C:\Users\GoodJob\Desktop\
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report