MALICIOUS — aab2237b23204242d9c884e2c5a49b24b919cd43bc25d8a1abb458cde05de45c
MALICIOUS — aab2237b23204242d9c884e2c5a49b24b919cd43bc25d8a1abb458cde05de45c is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Brontok family. 6 of 56 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
aab2237b23204242d9c884e2c5a49b24b919cd43bc25d8a1abb458cde05de45c - SHA-1:
7adb2c79c74cdadb98ad49e981344ff2544c6a0b - MD5:
4baac18c11e8432ec8e0732749115a10 - imphash:
1b675db9a912fecbf83526e2fd37cf23 - ssdeep:
1536:IFAutcCNS1mgnd2y1nrPlGiCcCBEulwVFAutcCNS1mgnd2y1nrPlGiCcCBEulwO:IpWC4YgBPlGiyllMpWC4YgBPlGiyllF - TLSH:
T14C3AE1C365393616DED7B0FA2084150F67A9C4801C7BECD44E6B81587B2872B68FD867 - Submitted as: aab2237b23204242d9c884e2c5a49b24b919cd43bc25d8a1abb458cde05de45c
- File type: pe · Size: 93547 bytes
- Verdict: malicious (100/100) · Family: Brontok
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): Petite
- ClamAV (daily): Win.Malware.Brontok-10037995-0
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Worm:Win32/Rahiwi!pz
- Emsisoft (Emergency Kit): Gen:Variant.Worm.VB.75
- Kaspersky (KVRT): Email-Worm.Win32.Brontok.am
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 14 weighted signals:
- ClamAV (daily) flagged Win.Malware.Brontok-10037995-0 (rule
Win.Malware.Brontok-10037995-0) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s) across 1 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged Worm:Win32/Rahiwi!pz (rule
Worm:Win32/Rahiwi!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Worm.VB.75 (rule
Gen:Variant.Worm.VB.75) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Email-Worm.Win32.Brontok.am (rule
Email-Worm.Win32.Brontok.am) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Dropped a suspicious payload (HUILoader): msvbvm60.dll - dynamic signal, weight 0.40, confidence 0.90
- Contacted 6 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged Petite (rule
Petite) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Petite, high-entropy-sections:.petite, Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
13539 behavior events · 2 ATT&CK techniques · 27 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- windows.msn.com
- www.msn.com
- settings-win.data.microsoft.com
- assets.msn.com
- www.bing.com
- th.bing.com
- fe3cr.delivery.mp.microsoft.com
- licensing.mp.microsoft.com
Dropped files
- C:\Windows\System32\tiwi.scr -
5b55973b4018cc626763f1efdc727ce5c47f6776bc6749dc0414140b438b0ad5 - C:\present.txt -
574a3a546332854d82e4f5b54cc5e8731fe9828e14e89a728be7e53ed21f6bad - C:\Users\analyst\AppData\Local\Temp\~DF526070F405EF5A24.TMP -
d003ea214e68fe721c6179a09cb6f8f4548b8454280a9c3c76c325181242d157 - C:\Users\analyst\Local Settings\Application Data\WINDOWS\lsass.exe -
87b84f0a504f2f449d7b8be6ba3db3a5ee3a740a4ad6510dc1749824eee13a06 - C:\Users\All Users\Start Menu\Programs\Startup\Empty.pif -
20d899646b74de41a36759f5ae30afe89ca7cb81e1bfa3769157cf733f38fa59 - C:\Users\analyst\AppData\Local\Temp\~DFD21404DA3E00BA8D.TMP -
88df27ce1a29b87befb27ac04832cb233b3fbeb564a49eed9acfe402287300a7 - C:\Windows\msvbvm60.dll -
898288bd3b21d0e7d5f406df2e0b69a5bbfa4f241baf29a2cdf8a3cf4d4619f2 - C:\Users\analyst\AppData\Local\Temp\~DFD9399165DBFAAED3.TMP -
a4dc62d30fb37a81c7755ea2423be215255e2af5d2d8bb147f68ca1a065e1483 - C:\Users\analyst\AppData\Local\Temp\~DF0B7BF9455E19B0D4.TMP -
7382e49c83ca56a9a4afb9b531dccff4641fc51ad5e0681867e9b056fcf590a3 - C:\Users\analyst\Local Settings\Application Data\WINDOWS\cute.exe -
96634abe290eb61656f88e089949de019335728c0dbb7582b343f0c11dd9104b - C:\Users\analyst\AppData\Local\Temp\~DF7747FBC2169B2F66.TMP -
3edb46c4610fba42f12d8d13583731287fb7166627c3ac9dbcbf42d93b0cbc76 - C:\Users\analyst\AppData\Local\Temp\~DF6E2BAB4EC2381C01.TMP -
ef4ab0cc8673e48f514fab788054354c74504b3ec9bcd4a54e5bc3fa7618263b - C:\Users\analyst\AppData\Local\Temp\~DF7D7BC3C829C780C6.TMP -
66776264930bf8b46899e2acf2cae7fa73e464f1d0af21ac35937e11c93f8816 - C:\Users\analyst\AppData\Local\Temp\~DFEC7F3DD6B9180C41.TMP -
d3a835c1fd3898b9f5209f26a86bb6ff06ad053a336047b63c5023ab482576f5 - C:\Windows\tiwi.exe -
ca2faff7023e87040b290042f5a9b8293f8e7a875bf43b293a04f0d0c05936f9
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 40.79.141.155
- 4.230.171.124
- 172.215.188.232
- 20.247.184.142
- 135.232.92.97
- 20.42.73.30
- 74.178.240.61
- 20.165.94.63
- 104.18.33.89
- 4.150.223.96
- 40.84.85.40
- 40.79.163.155
- 4.150.223.102
- 72.154.7.96
- 52.148.114.188
- 52.110.12.45
- 52.110.12.32
More Brontok samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report