MALICIOUS — 97f36ab0a4ff9453413a38a118c000c659008125fe8fc31c2b79027e580f4a8d
MALICIOUS — 97f36ab0a4ff9453413a38a118c000c659008125fe8fc31c2b79027e580f4a8d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the DLAgent14 family. 6 of 56 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
97f36ab0a4ff9453413a38a118c000c659008125fe8fc31c2b79027e580f4a8d - SHA-1:
b16166a04ec4cf30d12b32bb25b37a0af9a906aa - MD5:
42e05cf5b8ffbb276499451adf337bcc - imphash:
fc9dbb16a3b4e2cc8d0db4a2164aacd8 - ssdeep:
49152:4l7bUqEA3ra1WAUCrYeXcoxPEqtLl085gadW6v2qqWh:4l7bfEs8pY4RdE0R0kxpeqz - TLSH:
T17F5D3377208E568EC5A8AA257F87145CD02632D2F04B5675E63AC5E3DC3A23BF977200 - Submitted as: 97f36ab0a4ff9453413a38a118c000c659008125fe8fc31c2b79027e580f4a8d
- File type: pe · Size: 2770944 bytes
- Verdict: malicious (100/100) · Family: DLAgent14
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): Themida/VMProtect
- ClamAV (daily): Win.Trojan.Generic-9908699-0
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:Win32/Fimal!rfn
- Emsisoft (Emergency Kit): Gen:Trojan.Heur.D.PMW@deqsXkpi
- Kaspersky (KVRT): HEUR:Trojan.Win32.AntiVM.pef
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 15 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Generic-9908699-0 (rule
Win.Trojan.Generic-9908699-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Fimal!rfn (rule
Trojan:Win32/Fimal!rfn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Trojan.Heur.D.PMW@deqsXkpi (rule
Gen:Trojan.Heur.D.PMW@deqsXkpi) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win32.AntiVM.pef (rule
HEUR:Trojan.Win32.AntiVM.pef) - engine signal, weight 0.55, confidence 0.85 - 2 behavioral detection(s) across 2 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.43, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 3 external host(s) and 22 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082, T1497, T1497.001, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Extracted DLAgent14 config (0 C2) - engine signal, weight 0.45, confidence 0.60
- Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged Themida/VMProtect (rule
Themida/VMProtect) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: Themida/VMProtect, high-entropy-sections: , , , ,.boot, Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Dropped 2 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
20320 behavior events · 2 ATT&CK techniques · 14 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ip-api.com
- 2no.co
- c.pki.goog
- topasmanualle.com
- iplogger.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\pxcsilf.vbs -
c6790dcaa8dcc9783e0f6e9a16b3634ad5e6bf53e027e13c114c201531ba5cd5 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12 -
63b14543360f5e89942ea8d5113526e64fbc71c1207328f0136b3a495d921dd0 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9B0AD8EAA999C25450DA773B462914D6 -
ac5cae7e888d1db3082675e980bcd771aa5f1d07a39c6c0e149d7a2ec677598d - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12 -
4eaf9b33d29d872a9397b6ab6484dcd9b6627113e193d61f15da276c2904b8b4 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9B0AD8EAA999C25450DA773B462914D6 -
1ad5729e7d10de6273e02452f1a2717e24f7a1dfa0d88c4d69e8107ff66636a4 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8 -
d2bb091268ade68ad8121d2184d0fbce128070156304bd4de312e6fbd267409c - C:\Users\analyst\AppData\Local\Temp\jypdxgmvy.vbs -
14b3f43b19af69a388f92508df7759595c5d67486ae86c2927667249a3efa906 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\95524AED30610DA431A82DA18F814069 -
4deb23c9dad40c8f5a0a80f61c20a5c69433baf49206cebeaf85189fd78416fa - C:\Users\analyst\AppData\Local\Microsoft\Windows\INetCache\IE\XRUA1FHR\json[1].json -
35aabe095c49e170f4d984bdc12bbf350958fa30391d0333b5fafa573167237c - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8 -
d2b0e843662bf69dcec4d281ef4ba571e5d60c4f30574e87cb1ca5514cb5198c - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\95524AED30610DA431A82DA18F814069 -
3bbb16081725c8a2f68b1ac162fe040a69102158a6ec226e9a7469b077331ccf - 14b13b8630847389919cc381c76b82c2a2aa75cd52467e36fe4ad2e5774b8c32 -
14b13b8630847389919cc381c76b82c2a2aa75cd52467e36fe4ad2e5774b8c32 - 62c0904f045184e329970b06d4d85a274b91640e5963769897ef34161965b361 -
62c0904f045184e329970b06d4d85a274b91640e5963769897ef34161965b361 - 48df6d81b4e7117f152aa4a08659778c8ce2ab6fca9e73ced266b3aac48ff8de -
48df6d81b4e7117f152aa4a08659778c8ce2ab6fca9e73ced266b3aac48ff8de
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://ip-api.com/json
- http://c.pki.goog/r/gsr1.crl
- http://c.pki.goog/r/r4.crl
- http://c.pki.goog/we1/v1q7FffOpC4.crl
- http://c.pki.goog/we1/btvd66Z9uQY.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- gw.tk
- ip-api.com
- 2no.co
- topasmanualle.com
- iplogger.org
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 20.42.65.93
- 4.230.171.124
- 40.84.97.4
- 85.210.193.152
- 52.253.84.76
- 172.64.154.167
- 74.178.240.51
- 20.165.94.63
- 52.182.143.212
- 40.79.141.155
- 135.232.92.137
- 45.125.247.123
- 104.21.79.229
- 104.26.3.46
- 20.184.175.4
- 172.178.240.162
- 72.153.5.139
- 52.148.114.188
- 52.110.12.53
- 52.110.12.11
More DLAgent14 samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report