MALICIOUS — 9bd17c884ce8f2ccfa085bf2bcb50850daeb36451d70df928da8ed1e83229bac
MALICIOUS — 9bd17c884ce8f2ccfa085bf2bcb50850daeb36451d70df928da8ed1e83229bac is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the Padodor family. 5 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
9bd17c884ce8f2ccfa085bf2bcb50850daeb36451d70df928da8ed1e83229bac - SHA-1:
80bb3a9e3c3997507e4bb1344537d30722c0a285 - MD5:
3aaf42880ae73da6d38def198597677f - imphash:
26babd76bbb7f9c516a338b0601b4c9f - ssdeep:
1536:XbYwsFr3xKb3NlCpo97sMBezT3FsqKjy06oGT16+fJfriteW:XbYwiK3Nqo97MzTVsq5HLrwe - TLSH:
T19F387B1E246188DFFE8112D1A2587E2EBC92D4557C3EBBA0E60DE55EB3C411B44A3C1B - Submitted as: 9bd17c884ce8f2ccfa085bf2bcb50850daeb36451d70df928da8ed1e83229bac
- File type: pe · Size: 77824 bytes
- Verdict: malicious (96/100) · Family: Padodor
Detections (5 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): Win.Trojan.Crypted-30
- Microsoft Defender: Backdoor:Win32/Padodor.SK!MTB
- Emsisoft (Emergency Kit): Trojan.Peed.Gen
- Kaspersky (KVRT): Backdoor.Win32.Padodor.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypted-30 (rule
Win.Trojan.Crypted-30) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - Contacted 24 external host(s) at runtime (17 HTTP) - network signal, weight 0.40, confidence 0.80
- Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
- Dropped 74 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
2354 behavior events · 1 ATT&CK techniques · 74 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Dropped files
- C:\Windows\System32\Okbjan32.dll -
8a7e8d21beb7ec0168d61d4c2ca0c4303d3450811d5112ecdf6d3020679a2781 - C:\Windows\System32\Iacnml32.dll -
a3cc78858ae47d1332be9562cc6ad96a9aea86d2258312a8a4d087fd51ee357b - C:\Windows\System32\Bechbmli.exe -
4aea12f54b1b9599387bbc294eb2d0f69c2ba5135c11694073b5e28caf850e6d - C:\Windows\System32\Lhgcmjob.dll -
cfbb1de154ce0f82b645ced9f7786cc52f1c2855f4cf24477403816cf34bda74 - C:\Windows\System32\Ljalhemd.exe -
378406f2edcbbd686fab75d2ad39920045d4e5cb5be5fcf2af94f4008f3394dc - C:\Windows\System32\Demdoi32.exe -
fa782a2332d860b80c8388d7966ead331015dadd455aff6e95f6ac7aa71e3bf2 - C:\Windows\System32\Lqkifd32.dll -
9c3f27dd342bc4c1a51aed66fc56888ac7e8cfabedb6ef31e21b3427d19d8f02 - C:\Windows\System32\Idikme32.dll -
7c4fcbd456f21a7505dafa78f1059c0a077f7f994bfef7cc955e9448621bfadf - C:\Windows\System32\Feolfjno.exe -
a814bea9cd2de0de22c3a534823ce45b9cfd731301ed6ade97641af525f7e046 - C:\Windows\System32\Fhqbdgfp.dll -
18c5e6618ab9851946e54452fe2d13c8cd2640eed463b1f3918c68988ab0ffc7 - C:\Windows\System32\Qkgphnng.exe -
dcf7ba4e2261d06d9ffb9ebc0eb8010b7877415d7c95c4c407540a5fa33a32fe - C:\Windows\System32\Pknmaofa.exe -
f4f0a6f0b0062df9cb165b464f42b01020f38f3d984e1e7b56ecef4419d82b05 - C:\Windows\System32\Odcfda32.exe -
32ecf8a175a8f76d08185943d4b49949d2ede796be75564c9f19980be77cbce9 - C:\Windows\System32\Cahjnd32.dll -
153e4ad3b6ba7e86bb6be2cf43c97ae47979cd4b32d1411b5e86cae53ea57eea - C:\Windows\System32\Aflpie32.dll -
62754733c0ed8e8db91913162100877c51c7d252acd025f7de4b194af8babfec
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787806287&P2=404&P3=2&P4=CTjminZTpvddOE7j4NEKyD5t%2bWxPlV1zsEwfN9jtppQnmJDzKNpq8meiVUe93SluRZ3KUxY9ph93kB3r%2bbwC%2bQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 20.184.175.20
- 4.144.132.223
- 4.230.171.124
- 40.84.97.4
- 135.232.92.137
- 13.89.179.15
- 135.233.95.135
- 20.165.94.63
- 20.112.250.133
- 40.104.4.2
- 52.123.128.14
- 52.123.129.14
- 172.66.2.5
- 135.234.160.245
- 203.26.79.13
- 135.233.45.223
- 52.148.114.188
- 48.211.4.16
- 125.56.205.57
- 125.56.205.51
- 72.153.5.140
- 52.110.12.38
- 74.178.232.29
- 52.110.12.18
More Padodor samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report