MALICIOUS — bd053aa86c8f569eeaa24de70728c6c6fbad913fa46baf91c74db640c63dd5e2
MALICIOUS — bd053aa86c8f569eeaa24de70728c6c6fbad913fa46baf91c74db640c63dd5e2 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Brontok family. 6 of 56 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
bd053aa86c8f569eeaa24de70728c6c6fbad913fa46baf91c74db640c63dd5e2 - SHA-1:
77605271f189ea261c868481ae3b04a91cf945d4 - MD5:
316f331daa8eab0f8819c0b4a9ca3388 - imphash:
1b675db9a912fecbf83526e2fd37cf23 - ssdeep:
1536:IFAutcCNS1mgnd2y1nrPlGiCcCBEulwP4:IpWC4YgBPlGiyllP - TLSH:
T1FC35C1C629AB6DA1EAE3775A2480500E2B6ECD510C7FDD941B13485C3B7233328B5DA7 - Submitted as: bd053aa86c8f569eeaa24de70728c6c6fbad913fa46baf91c74db640c63dd5e2
- File type: pe · Size: 61580 bytes
- Verdict: malicious (100/100) · Family: Brontok
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): Petite
- ClamAV (daily): Win.Malware.Brontok-10037995-0
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Worm:Win32/Rahiwi!pz
- Emsisoft (Emergency Kit): Gen:Variant.Worm.VB.89
- Kaspersky (KVRT): Email-Worm.Win32.Brontok.am
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 14 weighted signals:
- ClamAV (daily) flagged Win.Malware.Brontok-10037995-0 (rule
Win.Malware.Brontok-10037995-0) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s) across 1 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged Worm:Win32/Rahiwi!pz (rule
Worm:Win32/Rahiwi!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Worm.VB.89 (rule
Gen:Variant.Worm.VB.89) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Email-Worm.Win32.Brontok.am (rule
Email-Worm.Win32.Brontok.am) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Dropped a suspicious payload (HUILoader): msvbvm60.dll - dynamic signal, weight 0.40, confidence 0.90
- Contacted 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged Petite (rule
Petite) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Petite, high-entropy-sections:.petite, Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
6268 behavior events · 2 ATT&CK techniques · 23 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- licensing.mp.microsoft.com
- www.bing.com
- th.bing.com
- assets.msn.com
- edge.microsoft.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Dropped files
- C:\Users\analyst\Local Settings\Application Data\WINDOWS\cute.exe -
3e80d85df09186899fcfa98004a379c36fa71dbc96f1168f960ed93c280e01ab - C:\Users\analyst\AppData\Local\Temp\~DF8D363CEBD4A634DB.TMP -
097e3c2f38394ff3ddf9b9024bcfc1eed6d05b6463d569a93220808a0494a18f - C:\Users\analyst\AppData\Local\Temp\~DF5A61622128A321B6.TMP -
efa1df4f685844b1f84251deefebd09b29fa686f6cdbdea72dff7ec1f636d3d7 - C:\present.txt -
574a3a546332854d82e4f5b54cc5e8731fe9828e14e89a728be7e53ed21f6bad - C:\Windows\System32\tiwi.scr -
7f2c46de4beb52d09d5214c21e03d8e2529904bf171948246f751fe5af00f086 - C:\Users\analyst\AppData\Local\Temp\~DF7FCA98FED87751F1.TMP -
18cb191b10028c7acaae51db1aade7448e617ecff37c11d8b0e7598dd7b9ad5a - C:\Users\analyst\Local Settings\Application Data\WINDOWS\winlogon.exe -
f8b3e7a929e1d0e3a996243c92d663600db19cecccc64d4542829bfb12151dc2 - C:\Users\analyst\Local Settings\Application Data\WINDOWS\lsass.exe -
c2f0be53519a68eb6305a9556a37e5092d20bd7675773fd993bd8258d29daf36 - C:\Windows\msvbvm60.dll -
898288bd3b21d0e7d5f406df2e0b69a5bbfa4f241baf29a2cdf8a3cf4d4619f2 - C:\Users\analyst\AppData\Local\Temp\~DF8D8B6FCC1F46B8F6.TMP -
4a755742a641028b4ebbf2abb3373ff5fcaad107c67e2674068ad082145f1889 - C:\Windows\System32\IExplorer.exe -
2e8c329715515ab4c392b282e8f330c17fc1bc312075f0c1b210b08a5ae93456 - C:\Users\analyst\AppData\Local\Temp\~DF0C1741F19B23CEF2.TMP -
30c3ce481c774b1dbc5f1d7f23886ad24e33cc1b44a4473fcf67ec3f392e11de - C:\Users\analyst\AppData\Local\Temp\~DF910ADE2168BB7291.TMP -
fda3e3b23685a4a1b1104fb7c52171dafc009b53183a6580207fb1a3f5a7ec96 - C:\Users\analyst\AppData\Local\Temp\~DF13ECD5605034FE21.TMP -
d73aec9696aef5ca3025ffe7a0234d5fea72f7780ae5e38a0da79d05d193ab95 - C:\Users\analyst\Local Settings\Application Data\WINDOWS\imoet.exe -
0170a157541a20718d5c60f41574bda7e7b42290bd3125fc2c68422fcf31f40c
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 20.42.65.85
- 20.247.185.124
- 172.64.154.167
- 4.230.171.124
- 52.110.12.54
- 52.110.12.18
More Brontok samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report