MALICIOUS — b4c8fb1ab05b573867b082b2d9620177d2753091bbfd28ebe4fed6c8dd5d00d7
MALICIOUS — b4c8fb1ab05b573867b082b2d9620177d2753091bbfd28ebe4fed6c8dd5d00d7 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the RedLine family. 3 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b4c8fb1ab05b573867b082b2d9620177d2753091bbfd28ebe4fed6c8dd5d00d7 - SHA-1:
eda08e9995bf9a4a466d3041b0cd85a7fdc09327 - MD5:
78cd43eeea1d45de7d9c02bd938dfa74 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
12288:WGxwL6hD2x/HAWbR2zS4sisO1A83u2BSDoCqKc:WaW6uHAW92zt/sWu2BSMCqD - TLSH:
T16A4B231E4265191FDEC5FFB31A065ACC6087F29A5BB3316C0B9404781365BEB389C6B2 - Submitted as: b4c8fb1ab05b573867b082b2d9620177d2753091bbfd28ebe4fed6c8dd5d00d7
- File type: pe · Size: 504832 bytes
- Verdict: malicious (97/100) · Family: RedLine
Detections (3 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- Microsoft Defender: Trojan:Win32/Wacatac.B!ml
- Kaspersky (KVRT): UDS:Trojan-Spy.MSIL.Stealer.gen
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 6 weighted signals:
- Extracted RedLine config (1 C2) - engine signal, weight 0.80, confidence 0.90
- Memory forensics: 3 finding(s), e.g. RWX/private injected region in tsk_dd01d46013 (pid 3556) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 32 external host(s) at runtime (27 HTTP) - network signal, weight 0.40, confidence 0.80
- Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
585 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- settings-win.data.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\extract.zip -
118a63b631cd767753cf17fd7af9e1059dd9ce6bde30ed883a2c836e2a72f3a0 - 698e4beeba26363e632cbbb833fc8000cf85ab5449627bf0edc8203f05a64fa1 -
698e4beeba26363e632cbbb833fc8000cf85ab5449627bf0edc8203f05a64fa1 - dd95dd42a5dc9212db72ef97b4f891ac31ff21b2e52536392395cf760a08c067 -
dd95dd42a5dc9212db72ef97b4f891ac31ff21b2e52536392395cf760a08c067
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787884854&P2=404&P3=2&P4=nP9QK5bx1W8EJyGxtQmTdxA0JoQojco6S%2bHu7kfgMavUc5g2sOu7b14FrhgJJdupefRpAQ3%2btsD9l9V6mWwyKQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787884904&P2=404&P3=2&P4=h1wHEok1Zfqu4o1a7B8c14dIARjapaVKjvOfX7VGJAyoKfx%2bieWe0%2bS7kbYHrcwWQrI9WHiNWPGkYlMmobf0Hg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787281630&P2=404&P3=2&P4=NR0BTjMz9qNZvE5GK9aDm16dtT4E0MjrVE9mvb1dOdBKFJklIsdRW1sNBkSb66CPlzCAjQ%2fjqwV3Le7v6Dsavg%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/b56480f9-8215-4de7-ba7e-8e690088d21d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/b56480f9-8215-4de7-ba7e-8e690088d21d?P1=1787281195&P2=404&P3=2&P4=aa2EtP7RexJx%2fP8GOLwpJyhum9mz%2bgPAWVkD%2fdkqpe4tmMof7zmK1RE28vV8RlaMJCf84fkGZI1WIMg006%2fQmw%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 20.184.175.11
- 52.123.252.234
- 52.253.84.76
- 40.84.97.4
- 4.230.171.124
- 52.123.252.229
- 74.178.240.61
- 135.232.92.97
- 51.11.192.51
- 20.184.175.22
- 20.236.44.162
- 52.123.128.14
- 52.123.129.14
- 172.66.2.5
- 203.26.79.13
- 135.234.160.244
- 46.3.197.109
- 74.178.232.29
- 52.168.117.175
- 20.42.73.31
- 52.110.12.48
- 52.123.252.238
- 52.110.12.3
- 52.148.114.188
- 52.123.252.242
File paths
- C:\Users\Game\source\repos\OnlyScanTime\OnlyScanTime\obj\Release\OnlyScanTime.pdb
More RedLine samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report