MALICIOUS — 9e46b4e6014b6cea35b1f724687e5ee65f1a73198784b4eeb7a7dc8ef33125c7
MALICIOUS — 9e46b4e6014b6cea35b1f724687e5ee65f1a73198784b4eeb7a7dc8ef33125c7 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Picsys family. 6 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
9e46b4e6014b6cea35b1f724687e5ee65f1a73198784b4eeb7a7dc8ef33125c7 - SHA-1:
e147bcded2056f29c2326d6dae5779ebd4cecfe0 - MD5:
5f8a0449a21906fa8ca3ddd66ade6a5b - imphash:
359d89624a26d1e756c3e9d6782d6eb0 - ssdeep:
1536:y4QQ6NSyM61l19piO+LV8YEoI/EU9RUe4mVOORaTf0N2pJSN:y4X6NSyfnpijeYEoIcq48ekig - TLSH:
T1D33702DA7D417C28ED9EECD55CF78D7D18E2420C22EB2649168C6039641E08FEC227AC - Submitted as: 9e46b4e6014b6cea35b1f724687e5ee65f1a73198784b4eeb7a7dc8ef33125c7
- File type: pe · Size: 69704 bytes
- Verdict: malicious (98/100) · Family: Picsys
Detections (6 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Worm.Picsys-6804101-0
- Detect It Easy (packer/type): DIE:Turbo Linker
- Microsoft Defender: Worm:Win32/Yoof!pz
- Trellix Stinger (McAfee): W32/Picsys.worm!EDF1F2AFBA70
- Kaspersky (KVRT): P2P-Worm.Win32.Picsys.b
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Worm.Picsys-6804101-0 (rule
Win.Worm.Picsys-6804101-0) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 29 external host(s) at runtime (27 HTTP) - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 a#¤, Turbo Linker - static signal, weight 0.25, confidence 0.55
- Dropped 24 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
128 behavior events · 1 ATT&CK techniques · 27 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- v7x3a5l9.hypermart.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Dropped files
- C:\Windows\System32\macromd\cute girl giving head.exe -
118ec7ccf0efa70026f9ad5840401358c02ea7f0d73ec6544f2a2e17e308a844 - C:\Windows\System32\macromd\chubby girl bukkake gang banged sucking cock.mpg.pif -
f72318b98cc3e1ad37512961009410f2250488fdb6abc4637ded2c7e8199a069 - C:\Windows\System32\macromd\Jenna Jamison Dildo Humping.exe -
0b09b3de3173d11793d86f9ee548f2ba89e2b6d56d8fa6e5f5e03a59b644b98f - C:\Windows\System32\macromd\Pamela Anderson And Tommy Lee Home Video (Part 1).mpg.exe -
3397bff3e1c5ad77b04c91178d1d9e4bcbcf2f01e25cfd5dea49b121687b1990 - C:\Windows\System32\macromd\Want to see a massive horse cock in a tight little teen's pussy.mpg.pif -
3306dfd0d3ff61d6dccd72bb75c141e13ff4713b447e4589956349779bcf0cdb - C:\Windows\System32\macromd\fetish bondage preteen porno.mpg.pif -
2d8f520025895785ba824ea553fe03ecf981bc9cc037ff2e654044a7a153c937 - C:\Windows\System32\macromd\Teen Violent Forced Gangbang.exe -
b8899fbb8c29cca70032b931f48ef1dd60bdc9fe3a069dc8f1d9f228bddaec60 - C:\Windows\System32\macromd\yahoo cracker.exe -
a9796d595f38b27f601814bf97a89f905e3a9c3c3860e0c7998e8ca62a379ed6 - C:\Windows\System32\macromd\msncracker.exe -
9309f36d2ad713995654d5be2ff38dd512db176c338ca6f0f633470f8ba21af8 - C:\Windows\System32\macromd\jenna jameson - shower scene.exe -
621198003386b015fa515d7e4d5cdc50096317ce3062ac79c043cf39a5cc1540 - C:\Windows\System32\macromd\15 year old on beach.mpg.exe -
daca4c84ba4df4f5a55f903096163d034ecda786f9e74792b27e4d250495d126 - C:\Windows\System32\macromd\preteen sucking huge cock illegal.mpg.exe -
3f82722d62ba0d070f25b627b2ea98dca1a0c0c5b101f78c776dc606241c0b15 - C:\Windows\System32\macromd\Harry Potter and the sorcerors stone.divx.exe -
76ac961c45c726a07274c396d086d46bddd14ece6bbbdf62e7fa866d411ddcc2 - C:\Windows\System32\macromd\AIM Account Hacker.exe -
f458f30ccf893b37ce7317b8628aa5c4c185bbab4baab5f9d500a33dd541a9b9 - C:\Windows\System32\macromd\nikki nova sex scene huge dick blowjob.mpg.exe -
898931e987f5f3f630decd9791fde6202bd96ab4f8b350075569e3600422ccb4
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787928971&P2=404&P3=2&P4=Ij2OX0iu6vVtpPpYYC%2fwNC05v3TvsP2npJo3KXdXFj5Ufi80VP%2bFI383XwdW5Ea%2bSymvQGM9iAVJDec%2f8LC17Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787929027&P2=404&P3=2&P4=MVKteCiUaZ3Sw30oKrYod9zPfODDAkAjZoiLHKYINpKrQxme0IUq1kSidebm95Jyix6jdMBIGCP3zHYl99BgbA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://v7x3a5l9.hypermart.net/cgi-bin/w.cgi?192.168.122.115A5578B8894C8919D50257750E3F0
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787325777&P2=404&P3=2&P4=Q61lmbEhkcWBecxxyvPy35JfCvrQC10HM3aM5FFkmGAU1rjBGubkrf4am9YHQaSv%2ft4ojlCrEGBTSRCmWjtktw%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/b56480f9-8215-4de7-ba7e-8e690088d21d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/b56480f9-8215-4de7-ba7e-8e690088d21d?P1=1787325294&P2=404&P3=2&P4=jYtYvMUCG3lDWU3Fvaw1P1lH6Kcj%2fqC7ck8xgNYU8cB79606959M%2b2hO387b7Un4XBIaJbqqzE%2bSKvrFEKbIBg%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- v7x3a5l9.hypermart.net
Embedded IP addresses
- 20.184.175.19
- 52.123.252.203
- 4.247.188.233
- 52.230.60.54
- 4.230.171.124
- 74.179.77.204
- 74.179.77.164
- 4.150.223.99
- 20.236.44.162
- 52.123.129.14
- 40.104.4.2
- 52.123.128.14
- 20.42.65.94
- 52.123.252.238
- 135.234.160.245
- 203.26.79.13
- 74.178.76.44
- 52.110.12.15
- 52.110.12.31
- 52.148.114.188
- 51.116.246.106
- 51.116.246.105
- 38.113.1.151
- 72.154.7.17
- 4.209.250.170
More Picsys samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report