MALICIOUS — ab4ff5e7070268876a1e0dc4a4459711ab282bf1adc7c26fadf6d2d4dc74f328
MALICIOUS — ab4ff5e7070268876a1e0dc4a4459711ab282bf1adc7c26fadf6d2d4dc74f328 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Qwidcl family. 4 of 56 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
ab4ff5e7070268876a1e0dc4a4459711ab282bf1adc7c26fadf6d2d4dc74f328 - SHA-1:
a380b717890d4ff45753c637d18e2751f0db67e1 - MD5:
944c22c8ed241a13e2cda6050bbeb662 - imphash:
c5723a7c7f3ee77135900804381861ec - ssdeep:
3072:n8CQ96FPCQYIfCCaMYeV6PhLN8gRVIb6RSEZwsPFAP7dL54hcRKGgYmzM9:yYFPzfC7q0PRCb6PRP6tRKy - TLSH:
T17B494843CB272115F0B2D65C188DC84C9E66DAA9344F5D01EFC3626DA4DB5E723A0E2B - Submitted as: ab4ff5e7070268876a1e0dc4a4459711ab282bf1adc7c26fadf6d2d4dc74f328
- File type: pe · Size: 393216 bytes
- Verdict: malicious (99/100) · Family: Qwidcl
Detections (4 of 56 engines)
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: flagged
- Trellix Stinger (McAfee): Trojan-FPZA!944C22C8ED24
- Kaspersky (KVRT): Trojan.Win32.Agent.qwidcl
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 11 weighted signals:
- Microsoft Defender flagged flagged (rule
flagged) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Trojan-FPZA!944C22C8ED24 (rule
Trojan-FPZA!944C22C8ED24) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Agent.qwidcl (rule
Trojan.Win32.Agent.qwidcl) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s) across 1 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 4 external host(s) and 9 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082, T1497, T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
18513 behavior events · 2 ATT&CK techniques · 23 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- www.360.cn
- icanhazip.com
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
- www.bing.com
- licensing.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\~BB43\20260823071204_6.a -
279428396d3f9aece74dc497abceb01fc78f1be10a280c41dcddec08de966bf1 - C:\Users\analyst\AppData\Local\Temp\~BB43\20260823071201_5.a -
d843c88b22f6d873c384f03a27febfa441d914dcbd655a168523e5647f7fc5e7 - C:\Users\analyst\AppData\Local\Temp\~31C6\20260823071141_1.a -
535330d798549c020f9caf5daada5fc5425c1a84e83fdc7187ded4822b068124 - C:\Users\analyst\AppData\Local\Temp\~BB43\20260823001307_10.a -
6b2fbcd8a29d5e84d7db7b66ef1ffc8c9304ec1e543f0ed38c24d7433f14139b - C:\Users\analyst\AppData\Local\Temp\~31C6\20260823071142_2.a -
a1994119b25bb02121b51f6fdaae0b0c4bbeae38b3e4fcbbdf5442de15b39a87 - C:\Users\analyst\AppData\Local\Temp\~31C6\20260823001316_13.a -
bad466635772e745b15623a85f47a95ef9db47140df3fa92de889e17710e0c00 - C:\Users\analyst\AppData\Local\Temp\1787494306.jpg -
3c1cf1d108e3c830767de28af00e86135acd6afd7307b847e73e78a862126d52 - C:\Users\analyst\AppData\Local\Temp\~BB43\20260823001322_15.a -
24b92beac336a06bca167df41a565f9e14f16513f1444487f53d456802a8b8b3 - C:\Users\analyst\AppData\Local\Temp\~BB43\20260823001303_9.a -
e923fd90d7084facf83bef1110354d3b1a479635900debaf0a82eb74f54a382a - c:\users\analyst\appdata\local\temp\~b4d8\20260823001307_00004823.s -
5984ca3c3e08b15891bcb17137216cf6ae87a7bd53bf03c75d7c37e575dc07a9 - C:\Users\analyst\AppData\Local\Temp\~BB43\20260823071211_8.a -
693511cf1f72fb268838940ddbd6741949837d416d7e861ebdd2a0d5016d8a39 - C:\ProgramData\Destro -
c2cb291f6bf259e9ec649d7c256ca4890cf672a8e6568bdf2fb422517334535e - C:\Users\analyst\AppData\Local\Temp\~BB16\C -
d243188293e7a39dc3198e90c2b5f2a3b8725997eee3ab6734fd551aab45aad2 - C:\Users\analyst\AppData\Local\Temp\~BB43\20260823001313_12.a -
21582556075e82cca50e3c05b4920bb5c68072cce232fcd0bec47c3c1eb12516 - C:\Users\analyst\AppData\Local\Temp\~31C6\20260823071142_3.a -
63773bf5ed666f2954ecc499a127e997ec50087f907548bbe72f8a76e6867f30
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://www.360.cn/status/getsign.asp
- http://icanhazip.com/
Embedded domains
- www.360.cn
- icanhazip.com
Embedded IP addresses
- 20.42.72.131
- 4.230.171.124
- 57.154.63.210
- 20.247.185.124
- 20.165.94.54
- 52.168.117.169
- 74.178.76.128
- 47.89.195.194
- 72.145.35.99
- 210.55.220.106
- 52.148.114.188
- 206.26.56.43
- 104.16.185.241
- 52.110.12.15
- 52.110.12.45
More Qwidcl samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report