MALICIOUS — b6975d193d79999a2b0eabf68ea5968d48418e990ed75897485d4ad81e08dc79
MALICIOUS — b6975d193d79999a2b0eabf68ea5968d48418e990ed75897485d4ad81e08dc79 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (70/100), attributed to the Wacatac family. 2 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b6975d193d79999a2b0eabf68ea5968d48418e990ed75897485d4ad81e08dc79 - SHA-1:
53f08a9751eecb9b400591ea74eb72a240195085 - MD5:
e7323906476c822e1166d61533c0eb76 - imphash:
062f1243054ea14659c1af0fb9d25695 - ssdeep:
768:lSyyL0Wm4WUHI9Jdic+JLGpzoJcNrUsCX/mNBTs315Yn:gXHm4WUo9JdgJLiGUUsCvmNFs315Y - TLSH:
T1FA397ECEC7BA3185FEFAD750A8C6953F94229839406C09CDE20B952F05F923B4125F61 - Submitted as: b6975d193d79999a2b0eabf68ea5968d48418e990ed75897485d4ad81e08dc79
- File type: pe · Size: 86528 bytes
- Verdict: malicious (70/100) · Family: Wacatac
Detections (2 of 55 engines)
- Microsoft Defender: Trojan:Win32/Wacatac.B!ml
- Emsisoft (Emergency Kit): Gen:Variant.Bulz.931310
MITRE ATT&CK
Why this verdict
The malicious score of 70/100 is the fusion of 3 weighted signals:
- Memory forensics: 3 finding(s), e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.55, confidence 0.85 - Contacted 16 external host(s) at runtime (14 HTTP) - network signal, weight 0.40, confidence 0.80
- 1 behavioral detection(s): Discovery: enumerates installed security software [low] (rule
tl-security-software-discovery) - dynamic signal, weight 0.20, confidence 0.90
Dynamic analysis (windows)
811 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 52.168.117.170
- 52.123.252.240
- 4.230.171.124
- 85.210.196.11
- 20.247.184.197
- 74.178.76.128
- 51.132.193.105
- 135.232.92.97
- 52.123.128.14
- 20.112.250.133
- 52.123.129.14
- 40.79.150.121
- 135.233.45.222
- 52.148.114.188
- 52.110.12.16
- 52.110.12.20
File paths
- C:\Users\Snow\Desktop\UnmanagedCLR_V2\x64\Release\UnmanagedCLR_V2.pdb
- C:\Users\Snow\source\repos\WindowsFormsApp1\obj\Debug\WindowsFormsApp1.pdb
More Wacatac samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report