MALICIOUS — b1289b7f569292147932ffd30935c59d8b6c1ef54830f3edc95d4bbc74e11781
MALICIOUS — b1289b7f569292147932ffd30935c59d8b6c1ef54830f3edc95d4bbc74e11781 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Vtflooder family. 5 of 55 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
b1289b7f569292147932ffd30935c59d8b6c1ef54830f3edc95d4bbc74e11781 - SHA-1:
174ef08cda382b54315d70abc86e91ebf192d300 - MD5:
1578aac6410f99664a97ba529dbcea16 - imphash:
26f24a4a2c8304d187950ea494d88d67 - ssdeep:
3072:r8Q0Vs7gZPp3gXdqHiIyyLl8/BLkcUiRADmhoLITBfT2:rkfXGQHi0ufdRUxsTBb2 - TLSH:
T12F3E0230764A14E9CF96C5B98D457C9F10D2BC0E343AA0C95612725D36E839B2A329FF - Submitted as: b1289b7f569292147932ffd30935c59d8b6c1ef54830f3edc95d4bbc74e11781
- File type: pe · Size: 137320 bytes
- Verdict: malicious (98/100) · Family: Vtflooder
Detections (5 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.
- ClamAV (daily): Win.Malware.Vtflooder-6804274-1
- Microsoft Defender: Trojan:Win32/Vflooder!pz
- Emsisoft (Emergency Kit): Trojan.Agent.EZTB
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Win.Malware.Vtflooder-6804274-1 (rule
Win.Malware.Vtflooder-6804274-1) - engine signal, weight 0.90, confidence 0.95 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 27 external host(s) at runtime (29 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: high-entropy-sections:. - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
101432 behavior events · 2 ATT&CK techniques · 10 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- google.com
- c.pki.goog
- www.virustotal.com
- a6281279.yolox.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
Dropped files
- C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05DDC6AA91765AACACDB0A5F96DF8199 -
a6f8f5d4ffd1e825ffce9a55861f16aa4dbe67871b1696b976194dd8be1fdf29 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA -
a7615a2cebb2230ed93782c502bf25809205c7f2c639cf166a3fbbc4c57a3eea - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75A092F4522006A97542D6AC4F4E69D2 -
8db14f7aaacbd54a841bff84cebde0a6e335eb4ca6781389820a967b333a5ab1 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75A092F4522006A97542D6AC4F4E69D2 -
33badd3794c0d5d02e18e88f818cf71444cba34ce75037bc4112d7f080f42f7d - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05DDC6AA91765AACACDB0A5F96DF8199 -
9e9229e50d18601d7d61d2c9313d1d25b465837bd59686f22652cbe60ae2e6d8 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA -
21dd2513fa7c4380d41c0e87c8099bd27d5d64aaa2d8d9113972e302e6ceaadc - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\71D3A36027B1506445FB345FD67207AC -
a95fc9304e6b6a815cdade01c53e4a0f40c847e126d0d97d4e20b9808d4a4a3d - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\71D3A36027B1506445FB345FD67207AC -
8bf97b6e6e4b51c899af0897814e04423d308ff4613b915c0857c8ba01788c4c - 33e51adfa115cd58a1ddf2b9850e4693b7a246e662a8518794a9061156603473 -
33e51adfa115cd58a1ddf2b9850e4693b7a246e662a8518794a9061156603473 - 2a7b9535da3c66062188cbdd8b8663cfe22f41578f583c450bd51eac5d63eef9 -
2a7b9535da3c66062188cbdd8b8663cfe22f41578f583c450bd51eac5d63eef9
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://google.com/
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787793047&P2=404&P3=2&P4=nh4muA84CEvVKU1Um5XWodDAHqOou4QRU7CTGOs4HCLLOJRdGH1UVM97gFrDUC%2bSDoE3OKPow7o9jhk9EFrfHA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://c.pki.goog/r/r1.crl
- http://c.pki.goog/wr2/oBFYYahzgVI.crl
- http://www.virustotal.com/vtapi/v2/file/scan
- http://c.pki.goog/wr3/MbJBMFoQ-sk.crl
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787793126&P2=404&P3=2&P4=NjN%2bCtnl5iA3y1kyd5uOimuaqbAyMBRr0NX9DeypesdmFt9RWLJp07lSd%2ft8G9Q07xLcP38XCU544S2VwtDX0A%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- www.virustotal.com
- a6281279.yolox.net
Embedded IP addresses
- 13.89.179.12
- 52.230.60.54
- 4.230.171.124
- 85.210.193.152
- 20.165.94.63
- 40.79.197.34
- 135.232.92.97
- 135.233.95.144
- 52.123.252.197
- 20.236.44.162
- 52.123.128.14
- 52.123.129.14
- 20.42.65.94
- 172.178.240.161
- 203.26.79.13
- 34.54.88.138
- 52.123.252.230
- 20.165.94.46
- 52.148.114.188
- 52.110.12.33
- 52.110.12.37
- 92.223.78.30
- 52.110.12.31
- 52.110.12.53
- 142.250.195.174
More Vtflooder samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report