MALICIOUS — ab2b6b74103c0a2b2c02271f1e3e7ba24a1fe21d4bd724d32b6323703107f11d
MALICIOUS — ab2b6b74103c0a2b2c02271f1e3e7ba24a1fe21d4bd724d32b6323703107f11d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the BlackMoon family. 8 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ab2b6b74103c0a2b2c02271f1e3e7ba24a1fe21d4bd724d32b6323703107f11d - SHA-1:
381a5d6b3daaaba304ae219b83d582a030212c73 - MD5:
b2bcb8dd89c2e14d133822ae2b6037d0 - imphash:
9dacd5fc505421be83fd9ef325d44b59 - ssdeep:
1536:mAocdpeVoBDulhzHMb7xNAa04Mcg5IKvlNJiRXDKFjI+pZm5E:0cdpeeBSHHMHLf9RyIEQ5KXZP - TLSH:
T1F53B1B6796A3A4C9C93470AF3F4E73917400BDF00653798625ACE28FBDA758B46834C6 - Submitted as: ab2b6b74103c0a2b2c02271f1e3e7ba24a1fe21d4bd724d32b6323703107f11d
- File type: pe · Size: 102284 bytes
- Verdict: malicious (98/100) · Family: BlackMoon
Detections (8 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.MPRESS1
- ClamAV (daily): Win.Trojan.BlackMoon-4255490-1
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:MPRESS 2.01-2.12
- Kaspersky (KVRT): Trojan-Dropper.Win32.Dinwod.acqn
- Microsoft Defender: Trojan:Win32/Blackmoon!rfn
- Emsisoft (Emergency Kit): Adware.GenericKD.61151796
- Trellix Stinger (McAfee): Trojan-FPCQ!BA60F51D4D97
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Trojan.BlackMoon-4255490-1 (rule
Win.Trojan.BlackMoon-4255490-1) - engine signal, weight 0.90, confidence 0.95 - Kaspersky (KVRT) flagged Trojan-Dropper.Win32.Dinwod.acqn (rule
Trojan-Dropper.Win32.Dinwod.acqn) - engine signal, weight 0.55, confidence 0.85 - Contacted 40 external host(s) at runtime (18 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:MPRESS 2.01-2.12 (rule
DIE:MPRESS 2.01-2.12) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.MPRESS1, MPRESS 2.01-2.12 - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
709 behavior events · 1 ATT&CK techniques · 22 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- settings-win.data.microsoft.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- licensing.mp.microsoft.com
- assets.msn.com
- www.bing.com
- tas02.sls.update.microsoft.com
- v10.events.data.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- slscr.update.microsoft.com
- watson.events.data.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/10142/files/5ef9af8b7d8ffde6a9d817e63950d781939f6c2bdbcbe49754179c4bdd969bff -
5ef9af8b7d8ffde6a9d817e63950d781939f6c2bdbcbe49754179c4bdd969bff - /opt/CAPEv2/storage/analyses/10142/files/a3e639d195df9185f1c7dc78cb5960f9dfd82fb3d9627a8cfc2d5a8b24b1acda -
a3e639d195df9185f1c7dc78cb5960f9dfd82fb3d9627a8cfc2d5a8b24b1acda - /opt/CAPEv2/storage/analyses/10142/files/30ca911cc8f5ed65d00b04e345660825a0787ad3cff21a5d08e3cd1a4e4fefca -
30ca911cc8f5ed65d00b04e345660825a0787ad3cff21a5d08e3cd1a4e4fefca - /opt/CAPEv2/storage/analyses/10142/files/c0a598ae9373930906d594cc827f0b94d5d08953189cd3fb4889e2087b15ff68 -
c0a598ae9373930906d594cc827f0b94d5d08953189cd3fb4889e2087b15ff68 - /opt/CAPEv2/storage/analyses/10142/files/a5040db3bedf998ba56396c269f686d7f8b9e3bb3668b0ab6787c26ff13cc05f -
a5040db3bedf998ba56396c269f686d7f8b9e3bb3668b0ab6787c26ff13cc05f - /opt/CAPEv2/storage/analyses/10142/files/a87069b3754aa92a16198374dbe519911dd0fe797f398f3397e7a07b698ea781 -
a87069b3754aa92a16198374dbe519911dd0fe797f398f3397e7a07b698ea781 - /opt/CAPEv2/storage/analyses/10142/files/4ab1c7da0c26a8b1ea25e25a410f0faa7678440c8c9bef7c38db3c13f62ee68f -
4ab1c7da0c26a8b1ea25e25a410f0faa7678440c8c9bef7c38db3c13f62ee68f - /opt/CAPEv2/storage/analyses/10142/files/71440e44ca44179d8d88b3d739259580b79ac9995c1b3403a9f47e0bef7ab53a -
71440e44ca44179d8d88b3d739259580b79ac9995c1b3403a9f47e0bef7ab53a - /opt/CAPEv2/storage/analyses/10142/files/e5df071a02f3428dcad80af16b2f64657f6f9898dfddbe86fe3bc85d5d1fcf52 -
e5df071a02f3428dcad80af16b2f64657f6f9898dfddbe86fe3bc85d5d1fcf52 - /opt/CAPEv2/storage/analyses/10142/files/d17bd9ffeab28d33240becff857c00d0faaa4574b0ea7986d765cbcbe22d91a7 -
d17bd9ffeab28d33240becff857c00d0faaa4574b0ea7986d765cbcbe22d91a7 - /opt/CAPEv2/storage/analyses/10142/files/7dee643926facb326257d27541ba08cac94edbb4cf45700acb800634d13d1dc3 -
7dee643926facb326257d27541ba08cac94edbb4cf45700acb800634d13d1dc3 - /opt/CAPEv2/storage/analyses/10142/files/0fd84dc7383dbeecb3e5d66813a4e4a84f9c6ea00d0852a26348f7a6dc629400 -
0fd84dc7383dbeecb3e5d66813a4e4a84f9c6ea00d0852a26348f7a6dc629400 - /opt/CAPEv2/storage/analyses/10142/files/c1e8dc7b0c4287116b32a41b65f1bff4b84053490a383e56694211093ab634f2 -
c1e8dc7b0c4287116b32a41b65f1bff4b84053490a383e56694211093ab634f2 - /opt/CAPEv2/storage/analyses/10142/files/f6211351e2f01282756eb4cad6d4a4a2c26ca90501c29f6e04558e322223d611 -
f6211351e2f01282756eb4cad6d4a4a2c26ca90501c29f6e04558e322223d611 - /opt/CAPEv2/storage/analyses/10142/files/9123c1f9d4d1d3941956eaf2853b97f32112abb1a70df7bc9297b740834fbda8 -
9123c1f9d4d1d3941956eaf2853b97f32112abb1a70df7bc9297b740834fbda8
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786443615&P2=404&P3=2&P4=hENOruxH%2fVCrZ5sTmYSPSahyDQwctGgK%2bcKT%2fDpy8UFhuGUDfMtfFeg%2bQ%2fZY84sC9ElQ3lKzZd5Oq70zBluk0A%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786443735&P2=404&P3=2&P4=kSLwbrC9rZzGAdmu%2f96Sl%2bGHY5CLzHvBpQzXGr%2fH1KMqMTL4%2bC1vkVjsqhSqZImS%2fIltzlO4YbMta7K8IjmhFg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 4.150.223.112
- 52.123.252.229
- 57.155.101.212
- 4.230.171.124
- 4.144.132.114
- 74.178.240.61
- 4.150.223.105
- 20.165.94.54
- 52.110.12.31
- 52.168.112.66
- 135.234.160.245
- 92.223.78.30
- 203.26.79.13
- 20.42.179.192
- 52.123.252.194
- 20.165.94.46
- 72.145.35.102
- 52.148.114.188
- 20.184.175.5
- 20.184.175.10
- 74.178.232.29
- 52.110.12.44
- 52.110.12.26
More BlackMoon samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report