MALICIOUS — c2032c8f3c3864e67052df1bdccf984df2cdd5311df82ba580e8fac467210be5
MALICIOUS — c2032c8f3c3864e67052df1bdccf984df2cdd5311df82ba580e8fac467210be5 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the Donut family. 6 of 55 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
c2032c8f3c3864e67052df1bdccf984df2cdd5311df82ba580e8fac467210be5 - SHA-1:
1474051b65bdf978771f8c29790aeecc5c0ce96a - MD5:
3ac4e7d501c1a53207de28e043c74aaf - imphash:
9bfd2dac39af50555ae9789117b36b66 - ssdeep:
49152:+3BtqV+4rOd1gGYgi2T5h41DTUXjMgGhg+X2ti1m+twyZ/wLu1RH1Rafb7jRr7w: - TLSH:
T10E652380BCD095CBEDC0E595C2925CAD212D59919D60C88EBADB6DD0EBEFDF1821C9C0 - Submitted as: c2032c8f3c3864e67052df1bdccf984df2cdd5311df82ba580e8fac467210be5
- File type: pe · Size: 5633024 bytes
- Verdict: malicious (93/100) · Family: Donut
Detections (6 of 55 engines)
- YARA: MalwareAnalyser community pack: TL_UPX_Packed
- YARA: Yara-Rules community: YR_AntiVM_Sandbox
- Microsoft Defender: Trojan:Win64/Donut!pz
- Emsisoft (Emergency Kit): Trojan.Agent
- Trellix Stinger (McAfee): Packed-GEJ!3AC4E7D501C1
- Kaspersky (KVRT): HEUR:Trojan.Win64.Donut.pef
MITRE ATT&CK
Why this verdict
The malicious score of 93/100 is the fusion of 8 weighted signals:
- Memory forensics: 3 finding(s), e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 30 external host(s) at runtime (28 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- YARA: MalwareAnalyser community pack flagged TL_UPX_Packed (rule
TL_UPX_Packed) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiVM_Sandbox (rule
YR_AntiVM_Sandbox) - engine signal, weight 0.35, confidence 0.70 - 1 behavioral detection(s): Discovery: enumerates installed security software [low] (rule
tl-security-software-discovery) - dynamic signal, weight 0.20, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
28584 behavior events · 2 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\__PSScriptPolicyTest_ngbr1kmx.41g.psm1 -
96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7 - cba1517f404846822334ef57b3f70c5aac02c95db78c6681c976f44c52ba31be -
cba1517f404846822334ef57b3f70c5aac02c95db78c6681c976f44c52ba31be - 0585d1a08c141e83368074eef355c1ab20c7607c13881be487e11e6a242065d6 -
0585d1a08c141e83368074eef355c1ab20c7607c13881be487e11e6a242065d6
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787930494&P2=404&P3=2&P4=RI2LKLvLo4xNRhF3v%2fpAD%2fQSVzrju2bqRFbuakSXI1I2Jp38kZJifZ4JVj%2fE%2bhVjBsah%2ffUjht0TzkjUcMXSaQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787930570&P2=404&P3=2&P4=IKQ8h8MXnPA5%2bzNS2uv6cfb%2flgfc8w5tJDzCtf7SijnaOnq4rE0mrA06krdTyOyNeTfPIlp8V8oYSbogRx2P2A%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/b56480f9-8215-4de7-ba7e-8e690088d21d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787327251&P2=404&P3=2&P4=EOFvQW9vGBV0NoI6byNRVDGpZ037i6QtJnpzKWb43nHJGov56aleF7Ium9VYt%2fbNCkR1Q0L9FvUMD8wCWDoU%2fg%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/b56480f9-8215-4de7-ba7e-8e690088d21d?P1=1787326868&P2=404&P3=2&P4=iS%2fitLqJcOEaFTdr%2f0sopTn3Ti%2fmSf4i9zkosADnSFS0LqipGsFmxqHNqPtox54YRGcaWZ589LXIX2XEugbAiw%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/6c2dbffa-872a-4f74-b39c-0ab782eea5bf/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/6c2dbffa-872a-4f74-b39c-0ab782eea5bf?P1=1787332452&P2=404&P3=2&P4=cqlsP5ERFaM23m5vJI1BrlBs2DddBeqiBb1BrDubWDPF4ZORnN4IDp44Z%2f8ohD%2b5KbYWUuOXjavHszAanyNtrA%3d%3d&cacheHostOrigin=tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 52.168.117.169
- 4.247.188.224
- 4.230.171.124
- 52.253.84.76
- 135.232.92.137
- 135.233.95.135
- 52.168.117.170
- 20.76.201.171
- 52.123.129.14
- 4.150.223.107
- 52.123.252.204
- 172.178.240.163
- 203.26.79.13
- 40.84.85.40
- 52.123.252.220
- 20.165.94.46
- 52.110.12.44
- 52.110.12.2
- 52.123.252.241
- 52.148.114.188
- 52.123.252.243
- 72.153.5.130
- 104.46.162.229
- 172.170.180.133
- 20.184.175.3
More Donut samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report