MALICIOUS — a345f0880f4d95e6c2ddbd9e7431641a528969036453ffe69b4642cd02d9f647
MALICIOUS — a345f0880f4d95e6c2ddbd9e7431641a528969036453ffe69b4642cd02d9f647 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100). 6 of 56 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a345f0880f4d95e6c2ddbd9e7431641a528969036453ffe69b4642cd02d9f647 - SHA-1:
11d00bb70d872684d822895cec375e20321a349e - MD5:
2ed12a8e521c871181693e9c9b5e15f8 - imphash:
3e4757b6c44f364955a909104e3b2b4d - ssdeep:
6144:sxL0Sh8SCQriMixTmAcThAkZThMTMyEOlH/yMEj8ixTmAcThAkZThMTMEEX:8L00frrix1c60yllfyMHix1c60y5EX - TLSH:
T192479E17621AC46EC2658E263984C60D6C92E04C50F5957583CEEA6E483C93FFE7E1B3 - Submitted as: a345f0880f4d95e6c2ddbd9e7431641a528969036453ffe69b4642cd02d9f647
- File type: pe · Size: 343929 bytes
- Verdict: malicious (100/100)
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Genpack-9875154-0
- Detect It Easy (packer/type): DIE:VMProtect
- Microsoft Defender: Trojan:Win32/Ausiv
- Emsisoft (Emergency Kit): GenPack:Trojan.Agent.EXMP
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Malware.Genpack-9875154-0 (rule
Win.Malware.Genpack-9875154-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Ausiv (rule
Trojan:Win32/Ausiv) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged GenPack:Trojan.Agent.EXMP (rule
GenPack:Trojan.Agent.EXMP) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win32.Generic (rule
HEUR:Trojan.Win32.Generic) - engine signal, weight 0.55, confidence 0.85 - Contacted 1 external host(s) and 17 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:VMProtect (rule
DIE:VMProtect) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-sections:.lol
1 (rule
high-entropy-sections:.lol 1) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://creativecommons.org/publicdomain/zero/1.0/, https://www.gnu.org/software/automake/manual/automake.html, http://fsmsh.com/2753 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-sections:.lol 1, VMProtect - static signal, weight 0.25, confidence 0.55
- Dropped 10 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Extracted generic config (4 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
18907 behavior events · 0 ATT&CK techniques · 98 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
Dropped files
- C:\Program Files\7-Zip\Lang\ne.txt -
5e9097e7b26c5e9f74ebdb2ef9c8bd701c83a80fa0b6e541b00dcc344c0d1b7e - C:\Program Files\7-Zip\Lang\pa-in.txt -
de4c5450f4a10882c19448f52f4273f2476f6d4dd0802a5411a8e919d14f7a65 - C:\Program Files\7-Zip\Lang\it.txt -
30ff80d832ae527d1cd2893db8ceadb5f8d099d8ae64696fceaf35d140802c9f - C:\Program Files\7-Zip\Lang\br.txt -
4fd898ba660915967c6154852568fddd44214583967a8195f5d240346840928f - C:\Program Files\7-Zip\Lang\az.txt -
0c6eb221613630c941b0a1ae3668a0000d75179c0e751bc50cb161e283142276 - C:\Program Files\7-Zip\Lang\el.txt -
744d6739c20f3a468779edb31b1f3c44f69ea29813e66f1ca5cd00142a44b6fb - C:\Program Files\7-Zip\Lang\gl.txt -
88b890e3507fcc04f1d456a7b1e5f32481a4dbd764c7fa987d7da75fb6595896 - C:\Program Files\7-Zip\Lang\eu.txt -
e154a67dde95bf7e3a2fb4bcd1a1fe003eefb8b75e1d80431a83b7d665d547eb - C:\Program Files\7-Zip\Lang\ext.txt -
d4f2b5619ac18789c9758af8fbe308d0b9260d162688ecdf071d9d91daecb6e3 - C:\Program Files\7-Zip\Lang\hy.txt -
367dadc9140d68c71125a8444b73c9a7dd077443e28991cd1527825c6c1d073d - C:\Program Files\7-Zip\Lang\ga.txt -
0f3a9e57811853b06dfcb9aafb4011ac7628747763469da2a0516297a3a43112 - C:\Program Files\7-Zip\Lang\ka.txt -
2a5abdc6b76a774bb0bd4853b5fa327455555cdc30433a45cf94b7caa5161b10 - C:\Program Files\7-Zip\Lang\nl.txt -
46d11ecccdcddbd484f78549db383456cb174bbac89c91776d1999c3add19483 - C:\Program Files\7-Zip\Lang\ko.txt -
8d2d6dc1bb4b11db946c3519766402aed9e1ee779600d257a3b6908dfc65ed25 - C:\Program Files\7-Zip\7zCon.sfx -
e4653a99ac66726f7c3b26c2fd21e4a906adc94924777e8f17f4373b8c7a7fb2
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- https://www.gnu.org/software/automake/manual/automake.html
- http://fsmsh.com/2753
- https://autotools.io/index.html
- http://miller.emu.id.au/pmiller/books/rmch/
- http://fsf.org/
- http://www.gnu.org/licenses/
- http://www.gnu.org/philosophy/why-not-lgpl.html
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-cs-g1.crl05
- http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
- http://www.digicert.com/ssl-cps-repository.htm0
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- creativecommons.org
- geocities.com
- www.gnu.org
- fsmsh.com
- autotools.io
- miller.emu.id.au
- fsf.org
- cacerts.digicert.com
- crl4.digicert.com
- crl3.digicert.com
- www.digicert.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 104.46.162.231
- 4.230.171.124
- 85.210.193.152
- 135.233.95.144
- 20.247.184.197
- 135.232.92.97
- 20.184.175.8
- 74.179.77.204
- 172.64.154.167
- 135.233.45.221
- 20.184.175.12
- 4.150.223.112
- 52.110.12.48
- 92.223.78.30
- 52.110.12.31
- 52.110.12.1
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report