MALICIOUS — ad486bc3fc5eaa40fe5d246a0a3e8c335b7cad78ad7f8ebf6319d5719c47b6c3
MALICIOUS — ad486bc3fc5eaa40fe5d246a0a3e8c335b7cad78ad7f8ebf6319d5719c47b6c3 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the VMProtect family. 5 of 56 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
ad486bc3fc5eaa40fe5d246a0a3e8c335b7cad78ad7f8ebf6319d5719c47b6c3 - SHA-1:
93e5b421cba25bb6ba14e8bdbdcaee1e12fdfaf8 - MD5:
ed12fcdbb49c936ce536dc4548953b26 - imphash:
8d3e79136a42d187b8f3af71ce5c2684 - ssdeep:
98304:VZ8ge4Q2M9G7NKEcJiUXSoYL8N1K3E9FUIIs5m+dwOGyk3/5ap6u:A12M9GhKEEhX+L8nK3OmDsQgG9a8u - TLSH:
T1016523E0F041EF50EF26B9A41422C4BD5523A64B675E51EFF1C4E33B9AD18A798103E8 - Submitted as: ad486bc3fc5eaa40fe5d246a0a3e8c335b7cad78ad7f8ebf6319d5719c47b6c3
- File type: pe · Size: 5690192 bytes
- Verdict: malicious (97/100) · Family: VMProtect
Detections (5 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): Themida/VMProtect
- YARA: Yara-Rules community: YR_Packer_VMProtect
- Detect It Easy (packer/type): DIE:Windows Authenticode
- LIEF (executable format parser): lief:invalid-authenticode
- Kaspersky (KVRT): UDS:Trojan-Spy.Win32.Stealer.ahxd
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 11 weighted signals:
- Kaspersky (KVRT) flagged UDS:Trojan-Spy.Win32.Stealer.ahxd (rule
UDS:Trojan-Spy.Win32.Stealer.ahxd) - engine signal, weight 0.55, confidence 0.85 - 2 behavioral detection(s) across 2 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.43, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 2 external host(s) and 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Extracted RedLine config (0 C2) - engine signal, weight 0.45, confidence 0.60
- YARA: Yara-Rules community flagged YR_Packer_VMProtect (rule
YR_Packer_VMProtect) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Windows Authenticode (rule
DIE:Windows Authenticode) - engine signal, weight 0.35, confidence 0.70 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged Themida/VMProtect (rule
Themida/VMProtect) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Themida/VMProtect, high-entropy-sections:.vmp1, Windows Authenticode - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
10364 behavior events · 2 ATT&CK techniques · 7 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- desktop-hsgcbep
- login.live.com
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- v10.events.data.microsoft.com
- edge.microsoft.com
- ctldl.windowsupdate.com
- time.windows.com
Dropped files
- b7352abff4baf3122ef768299854ffe131ad65b55d63316d762b5c1bbceff297 -
b7352abff4baf3122ef768299854ffe131ad65b55d63316d762b5c1bbceff297 - 5027e276c11061181bc4944126e65c1d10a155e8af07eb47f68eb47f8793d11d -
5027e276c11061181bc4944126e65c1d10a155e8af07eb47f68eb47f8793d11d - c0212b6e29ab2aad055e3544ec038e77edb3f6a96f706e6769b4726076f783f3 -
c0212b6e29ab2aad055e3544ec038e77edb3f6a96f706e6769b4726076f783f3 - 9604d93d0d276b7bc4895412671f7431aec1a9a6405f65af68b21e65917314ef -
9604d93d0d276b7bc4895412671f7431aec1a9a6405f65af68b21e65917314ef - 7a6d427ebd47019da0fec5fa67e54170998631380e1a35655e2fac0a9afeb627 -
7a6d427ebd47019da0fec5fa67e54170998631380e1a35655e2fac0a9afeb627 - e37d072bef9d5dbd2747dce930521c37ccd2348ee19ee92e6a5ec9a12197d065 -
e37d072bef9d5dbd2747dce930521c37ccd2348ee19ee92e6a5ec9a12197d065 - 7bc5699dffb913182c45cc8cc7ce4d742175ae8df22f379f285a553287f78eff -
7bc5699dffb913182c45cc8cc7ce4d742175ae8df22f379f285a553287f78eff
Embedded URLs
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- 2.mx
- k.br
- crl.microsoft.com
- www.microsoft.com
Embedded IP addresses
- 4.150.223.101
- 4.144.132.223
- 52.123.252.231
- 4.230.171.124
- 4.150.223.113
- 4.150.223.102
- 185.51.121.233
- 52.110.12.25
- 52.110.12.52
- 162.159.142.9
- 4.247.188.224
- 184.84.165.136
- 72.145.35.100
- 52.148.114.188
- 52.110.12.20
- 52.110.12.50
File paths
- F:\oK]
- y:\xV:
More VMProtect samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report