MALICIOUS — ab873b5a29f6a0cc34a06adee720c63084ed98630602c8e885d781b249438c2d
MALICIOUS — ab873b5a29f6a0cc34a06adee720c63084ed98630602c8e885d781b249438c2d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Cryptinject family. 3 of 56 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
ab873b5a29f6a0cc34a06adee720c63084ed98630602c8e885d781b249438c2d - SHA-1:
01915b26e9df465f97e0a6e6b73f71be78f47994 - MD5:
7a104f1be20dfeba47cdc514e013094d - imphash:
a9192bab5c7c795c7488b69a1853f9c2 - ssdeep:
192:G49HsxwSUFx+UEqzerwdIpJNY8uMp7QPJVNMxUPAUBlxPVGcm:GBXUFh1yvN/uMmxDMm - TLSH:
T1072D83C9635A2720DCF0F854ED046D2C31D39AA462763BDC6406D43FB4EAAF305798A9 - Submitted as: ab873b5a29f6a0cc34a06adee720c63084ed98630602c8e885d781b249438c2d
- File type: pe · Size: 28672 bytes
- Verdict: malicious (99/100) · Family: Cryptinject
Detections (3 of 56 engines)
- ClamAV (daily): Win.Malware.Cryptinject-9890994-0
- Microsoft Defender: Trojan:Win32/CryptInject!pz
- Kaspersky (KVRT): Virus.Win32.Lamer.ks
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Win.Malware.Cryptinject-9890994-0 (rule
Win.Malware.Cryptinject-9890994-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/CryptInject!pz (rule
Trojan:Win32/CryptInject!pz) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.Lamer.ks (rule
Virus.Win32.Lamer.ks) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 2 external host(s) and 17 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497, T1497.001, T1622, T1082 - dynamic signal, weight 0.40, confidence 0.75
- persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://www.pinkworld.com, http://www.youporn.com, http://www.redtube.com - static signal, weight 0.35, confidence 0.60
- Dropped 23 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
55196 behavior events · 2 ATT&CK techniques · 37 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
Dropped files
- C:\Windows\System32\msvcp140_codecvt_ids.dll -
2fa408c77f2aedf193fa9b7dd6565dcdbf0614fc927198c73a6822250eda9912 - C:\Windows\win.ini -
a9b120e47438955e9beff354ebba0203d23f04ead2cf2658d839b529b37b91f2 - C:\Windows\System32\PrintConfig.dll -
9016dbf8f2a9b3c1f9642a92063f156feca479e2848b466d748c556dcc7f4fba - C:\Windows\PFRO.log -
f8d5804a939b36af5b08b07c449eda49bc7144db99d0f96351a245496af4686b - C:\Windows\lsasetup.log -
5881a5b3fdd53cfa3f4455668112dd4a92d4b860b37418c0c0ff0be5ff816779 - C:\Windows\System32\vulkan-1.dll -
87c076b8b97117e60ee5c04820fbea3400fb83271c907352b558b6832ee0ea79 - C:\Windows\DtcInstall.log -
0ea23aa66a5a737934508a19738917ad1e6395bc9f6834a535828d724d6373d2 - C:\Windows\System32\msvcp140.dll -
0627cd76dbeb331e1ec88827903b84709c5c034968a82d75ecd4199b26f4dab2 - C:\Windows\System32\concrt140.dll -
4f465190f9348d19dcc809a65df75eb6ad1a0a0ca896cec17343a4ed8bbd0a42 - C:\Windows\System32\NOISE.DAT -
5a4f72e33ecfb57eef263ce4291327cd3be98f8db122f3bc6563e095b5a089a5 - C:\Windows\System32\mfcm140.dll -
402c822dc2ffe1db9aefe5216873bf2283ec6eb5d86d33fd26a6e4a292c0d187 - C:\Windows\WindowsUpdate.log -
6f23cd7d8cda4e41cd564467bf52028dd8e2e84f6db07a7c625a04c143fdc3fe - C:\Windows\Professional.xml -
4ba1499690d9a85ccca6500e5a719b1ff4402fc4d40c51b576c5e557af7d398e - C:\Windows\System32\msvcp140_atomic_wait.dll -
2e5f197f724c20651720e89cd0ec7e08719622ed05bac8593a273063cf27d832 - C:\Windows\SysmonDrv.sys -
a18fec94b41a5fadeae9dac908da7642840dd25bcb645f46e0f4fcc1548c0853
Embedded URLs
- http://www.pinkworld.com
- http://www.youporn.com
- http://www.redtube.com
- http://www.assparade.com/
- http://www.freeav.com/
- http://www.antispyware.com/
- http://www.antivirus.com/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- www.pinkworld.com
- www.youporn.com
- www.redtube.com
- www.assparade.com
- www.freeav.com
- www.antispyware.com
- www.antivirus.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 20.184.175.6
- 52.123.252.231
- 4.247.188.233
- 4.230.171.124
- 135.232.92.97
- 52.230.60.54
- 4.207.44.72
- 74.178.240.61
- 51.132.193.104
- 104.18.33.89
- 74.178.76.128
- 52.110.12.38
- 52.110.12.48
- 4.150.223.103
- 51.132.193.105
- 135.233.45.221
- 52.148.114.188
- 72.145.35.108
- 52.110.12.30
- 52.110.12.20
File paths
- C:\!
More Cryptinject samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report