MALICIOUS — b8d6bb68f70a5d4357d02d86f5d6703835a2015321d68946451307583eaff7c7
MALICIOUS — b8d6bb68f70a5d4357d02d86f5d6703835a2015321d68946451307583eaff7c7 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the BlackMoon family. 8 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b8d6bb68f70a5d4357d02d86f5d6703835a2015321d68946451307583eaff7c7 - SHA-1:
9c1486f14612375f3a9e34db3995bd5a5638b641 - MD5:
b4c14d3ecdccd0313d4508b2858548de - imphash:
9dacd5fc505421be83fd9ef325d44b59 - ssdeep:
1536:mAocdpeVoBDulhzHMb7xNAa04Mcg5IKvlNJiRXDKFjI+pZm5Q:0cdpeeBSHHMHLf9RyIEQ5KXZj - TLSH:
T1C13B1B6796A3A4C9C93470AF3F4E73917400BDF00653798625ACE28FBDA758B46834C6 - Submitted as: b8d6bb68f70a5d4357d02d86f5d6703835a2015321d68946451307583eaff7c7
- File type: pe · Size: 102096 bytes
- Verdict: malicious (99/100) · Family: BlackMoon
Detections (8 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.MPRESS1
- ClamAV (daily): Win.Trojan.BlackMoon-4255490-1
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:MPRESS 2.01-2.12
- Microsoft Defender: Trojan:Win32/Blackmoon!rfn
- Emsisoft (Emergency Kit): Adware.GenericKD.61151796
- Trellix Stinger (McAfee): Trojan-FPCQ!BA60F51D4D97
- Kaspersky (KVRT): Trojan-Dropper.Win32.Dinwod.acqn
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Win.Trojan.BlackMoon-4255490-1 (rule
Win.Trojan.BlackMoon-4255490-1) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Blackmoon!rfn (rule
Trojan:Win32/Blackmoon!rfn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Adware.GenericKD.61151796 (rule
Adware.GenericKD.61151796) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Trojan-FPCQ!BA60F51D4D97 (rule
Trojan-FPCQ!BA60F51D4D97) - engine signal, weight 0.55, confidence 0.85 - Contacted 36 external host(s) at runtime (15 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:MPRESS 2.01-2.12 (rule
DIE:MPRESS 2.01-2.12) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.MPRESS1, MPRESS 2.01-2.12 - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
673 behavior events · 1 ATT&CK techniques · 22 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
- licensing.mp.microsoft.com
- www.bing.com
- tas02.sls.update.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- v10.events.data.microsoft.com
- slscr.update.microsoft.com
- watson.events.data.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/10210/files/4ad01efb86867494980c16ae5531d12b4b815c9e4c734e4e78a4ff2a7684d929 -
4ad01efb86867494980c16ae5531d12b4b815c9e4c734e4e78a4ff2a7684d929 - /opt/CAPEv2/storage/analyses/10210/files/9c0185af54b913caeb5fffd18c89689b104a4716754615e1d962b47b18b6375e -
9c0185af54b913caeb5fffd18c89689b104a4716754615e1d962b47b18b6375e - /opt/CAPEv2/storage/analyses/10210/files/afb300c55acbcd01a001244a11bebf322b3a75af4b52a8d38006be03b7a57418 -
afb300c55acbcd01a001244a11bebf322b3a75af4b52a8d38006be03b7a57418 - /opt/CAPEv2/storage/analyses/10210/files/003fadc7b9a4d9f420ce5c7c7a72fb040cd13b0e2d5b2ef357493723b8516b5e -
003fadc7b9a4d9f420ce5c7c7a72fb040cd13b0e2d5b2ef357493723b8516b5e - /opt/CAPEv2/storage/analyses/10210/files/7300de14236b32e253bd3729a044d7a3226963be6a5943248cccc35710d31530 -
7300de14236b32e253bd3729a044d7a3226963be6a5943248cccc35710d31530 - /opt/CAPEv2/storage/analyses/10210/files/7ae0d7d4c75923f96b33ba489ceb73ae41231279221f28b926f9b6434a54ab4d -
7ae0d7d4c75923f96b33ba489ceb73ae41231279221f28b926f9b6434a54ab4d - /opt/CAPEv2/storage/analyses/10210/files/27bb5139eba0dc5509a2d06b366a5d538c54a3271ba98b18bab62c95cafdb63d -
27bb5139eba0dc5509a2d06b366a5d538c54a3271ba98b18bab62c95cafdb63d - /opt/CAPEv2/storage/analyses/10210/files/e6847bfcc0f8bf577a7252269509ecf57057ea6c4bcce7f6c6742b05017cc110 -
e6847bfcc0f8bf577a7252269509ecf57057ea6c4bcce7f6c6742b05017cc110 - /opt/CAPEv2/storage/analyses/10210/files/a4d8a2b867ec4e54a05b62d09c1500b8c35d876e5390cdb062dc1e79b736b9ed -
a4d8a2b867ec4e54a05b62d09c1500b8c35d876e5390cdb062dc1e79b736b9ed - /opt/CAPEv2/storage/analyses/10210/files/8814e29e4080cc72aafefe342f7ce5ef800de589e61dda75c2b29f8b5e9239f8 -
8814e29e4080cc72aafefe342f7ce5ef800de589e61dda75c2b29f8b5e9239f8 - /opt/CAPEv2/storage/analyses/10210/files/2bbf5ff05e98a3207b786f31dc4fa9e5025ea60cc842b139383661bc392e056e -
2bbf5ff05e98a3207b786f31dc4fa9e5025ea60cc842b139383661bc392e056e - /opt/CAPEv2/storage/analyses/10210/files/0f7b8ce3c84ba271a17025b255c881044616ca89c46c60731e78f76986d3960e -
0f7b8ce3c84ba271a17025b255c881044616ca89c46c60731e78f76986d3960e - /opt/CAPEv2/storage/analyses/10210/files/9d26278e2bc27411bb8a61264a71864e7ce1cb9f893aa9c495bc89627c5b7bc5 -
9d26278e2bc27411bb8a61264a71864e7ce1cb9f893aa9c495bc89627c5b7bc5 - /opt/CAPEv2/storage/analyses/10210/files/2fa3702717d2a643d3bb0149bcc114c61101cf43251db0c74ded9f2fcd6521ed -
2fa3702717d2a643d3bb0149bcc114c61101cf43251db0c74ded9f2fcd6521ed - /opt/CAPEv2/storage/analyses/10210/files/b978178195ffa04dbf879f02684dcf5b42d6b0286858adf19fe90ffc6eb9416b -
b978178195ffa04dbf879f02684dcf5b42d6b0286858adf19fe90ffc6eb9416b
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786446181&P2=404&P3=2&P4=I5YwhoggTDK3CpXXdUxV9ICY4U6Hfwt5RRMkAaqh8uzyS87bmIrPGmIKI5dQVYJrnE4ADX%2btqVUyyG%2f9NpvAgA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786446291&P2=404&P3=2&P4=XFXDkBs3g58CR2rELnBn6xGo3O%2fi%2bq5WmHDne3bZ4yrz4jDDsOd9p%2fqMV6F62bsdloFB4cx6su5jVmhQH7SrLA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 20.42.73.25
- 20.42.179.204
- 4.230.171.124
- 20.247.184.197
- 135.233.95.144
- 74.179.77.164
- 4.150.223.103
- 135.234.160.245
- 92.223.78.30
- 20.184.175.15
- 4.150.223.105
- 203.26.79.13
- 20.165.94.46
- 72.153.5.63
- 52.148.114.188
- 57.155.101.212
- 135.233.95.80
- 52.110.12.38
- 52.110.12.22
More BlackMoon samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report