MALICIOUS — a6d2d8fe2c728c0ff3105dc287107544c7b6c2e7f88a8b60b4421cf85951e9c1
MALICIOUS — a6d2d8fe2c728c0ff3105dc287107544c7b6c2e7f88a8b60b4421cf85951e9c1 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Wacatac family. 3 of 56 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
a6d2d8fe2c728c0ff3105dc287107544c7b6c2e7f88a8b60b4421cf85951e9c1 - SHA-1:
cb8cb30289b09bd653932a59e3bd5124d4e8f3d0 - MD5:
98f84086523cd807a9d9ef488e6ba292 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
12288:PFrIu+hpWWa8KGgwCziXVqF9XPQAsuxISIhWE2Ri6+7S6:9Iu+L/iwCziXUF9XZVKWLi3S6 - TLSH:
T18F502ACA074A6215C6B409174CA0EDDF56D75CFD39B9388853C796B2D089A3F20392BB - Submitted as: a6d2d8fe2c728c0ff3105dc287107544c7b6c2e7f88a8b60b4421cf85951e9c1
- File type: pe · Size: 825760 bytes
- Verdict: malicious (98/100) · Family: Wacatac
Detections (3 of 56 engines)
- capa (capabilities): capability:execution/powershell
- Microsoft Defender: Trojan:Win32/Wacatac.B!ml
- Emsisoft (Emergency Kit): Gen:Variant.Cerbu.159488
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 11 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Wacatac.B!ml (rule
Trojan:Win32/Wacatac.B!ml) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Cerbu.159488 (rule
Gen:Variant.Cerbu.159488) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s) across 1 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Contacted 3 external host(s) and 4 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082, T1497, T1497.001, T1622 - dynamic signal, weight 0.40, confidence 0.75
- capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - Dropped 9 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 4 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
25010 behavior events · 2 ATT&CK techniques · 11 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- iamryuzaki.github.io
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- crt.usertrust.com
- edge.microsoft.com
- watson.events.data.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\Newtonsoft.Json.dll -
185a21c220bd690a2c58a3eef2695482602c208f5644057b4ff91b06810ed6ec - C:\Users\analyst\AppData\Local\Temp\discord_game_sdk.dll -
39e9856223135c5b8eb8f7fdf780f1625d6dac2ca75efa6f66aa90399d817b67 - C:\Users\analyst\AppData\Local\Temp\websocket-sharp.dll -
e36d2cef17156e376790d109ffd840df1498fd69221e0f4c170ab13163f4e140 - C:\Users\analyst\AppData\Local\Temp\Alkad.exe -
e970401f0b25799b200f083290fc52f8b67463c0899deccb2de021ba0c9656e6 - C:\Users\analyst\AppData\Local\Temp\steam_api64.dll -
1c0b8ea2894ab7e644253146f5c1e656518a52a10564a342b16024d30cbbc0e2 - C:\Users\analyst\AppData\Local\Temp\GameWer.SDK.dll -
7874540097f583ea483e19955633a184df8bf384ecceecabeb830d41bea81948 - C:\Users\analyst\AppData\Local\Temp\Facepunch.Steamworks.Win64.dll -
16c0dacf6c8f3ec520d6b73351e4f539fb28d9f9d71240b0e17b14a1c90a04e9 - C:\Users\analyst\AppData\Local\Temp\GameWer.Module.dll -
23487cc64837ed38c7ae183e3b20ce3504f21eb4be89ddc2e72927d7e78cdfdf - C:\Users\analyst\AppData\Local\Temp\GameWer.UI.Default.dll -
503cb09435f69097e5660e7a2e17c8cf4791759bb07dc92c88318055758b35af - 88d7f6325675760ea33e6c5dabb8605f3bea2112f5dbabfd49b1930d67982bd7 -
88d7f6325675760ea33e6c5dabb8605f3bea2112f5dbabfd49b1930d67982bd7 - fe863f0834534a94fd154171b66a57810531edd6b98f7d9ddc57716657daf73b -
fe863f0834534a94fd154171b66a57810531edd6b98f7d9ddc57716657daf73b
Embedded URLs
- http://schemas.microsoft.com/winfx/2006/xaml
- http://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
- https://www.digicert.com/CPS0
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- schemas.microsoft.com
- www.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- cacerts.digicert.com
- iamryuzaki.github.io
Embedded IP addresses
- 4.150.223.108
- 4.144.132.114
- 52.123.252.194
- 4.230.171.124
- 185.199.109.153
- 52.110.12.10
- 172.64.149.23
- 172.178.240.162
- 85.210.196.11
- 72.153.5.133
- 52.148.114.188
- 52.110.12.56
- 52.110.12.49
File paths
- C:\Users\TheRyuzaki\RiderProjects\GameWer
More Wacatac samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report