MALICIOUS — c270db65418c45204b151f743ef8b423da7210ac2497599cf3d1868f8a05bd6f
MALICIOUS — c270db65418c45204b151f743ef8b423da7210ac2497599cf3d1868f8a05bd6f is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the Crypted family. 4 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
c270db65418c45204b151f743ef8b423da7210ac2497599cf3d1868f8a05bd6f - SHA-1:
54a620d11f9103644bc8de090052844df0c8275f - MD5:
46373c197a187a218993efd9c158c48e - imphash:
95e6f8741083e0c7d9a63d45e2472360 - ssdeep:
3072:BO9yuCQzK7DrFDHZtOg5BOFyxZZhgyv3wDrFDHZtOgB:BOIugB5tT5CABgkI5tTB - TLSH:
T1D64127F2E2486C4CDA689126AC39943F1F1776D112267603CB87D347E63A2B7E4E016C - Submitted as: c270db65418c45204b151f743ef8b423da7210ac2497599cf3d1868f8a05bd6f
- File type: pe · Size: 185640 bytes
- Verdict: malicious (96/100) · Family: Crypted
Detections (4 of 55 engines)
- ClamAV (daily): Win.Trojan.Crypted-30
- Microsoft Defender: Backdoor:Win32/Berbew!pz
- Emsisoft (Emergency Kit): Backdoor.Hangup.B
- Kaspersky (KVRT): Trojan-Spy.Win32.Qukart.af
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypted-30 (rule
Win.Trojan.Crypted-30) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - Contacted 29 external host(s) at runtime (26 HTTP) - network signal, weight 0.40, confidence 0.80
- Dropped 100 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
3143 behavior events · 1 ATT&CK techniques · 100 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- settings-win.data.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Dropped files
- C:\Windows\System32\Onjgeiag.dll -
328f226032d774776981572d54a74508cd747d919895b41ad62a174fac371ec9 - C:\Windows\System32\Nllmbc32.exe -
57625e10f5ecdb2b54bd6befef1a78648d5e9628d3eeadaa6050b92624c13ec5 - C:\Windows\System32\Gipbfc32.dll -
07d2a6f82fc4db660afbd2da63de4953c9a5eb260b741160a5ab6f83b6764d8b - C:\Windows\System32\Kogipi32.dll -
ff76e59b2a83521064227542fc5925d35bc5cc641d578a9c1e8b64a66303445e - C:\Windows\System32\Iobbge32.exe -
f9e204a973c2e55da7c56e7871c3290ce354bd10c4c7824e81b77fbddf707051 - C:\Windows\System32\Hpcdnjop.dll -
b34bf67138d790c66bbd3925956a2d1746f13d9a14ff15e26d167c9dbcc16a87 - C:\Windows\System32\Dggofblo.exe -
82778b6837b213ff7c20e2512c9cf7d6e8759b952bce3fb7bac5425b2ef28ac6 - C:\Windows\System32\Eflemh32.exe -
eaa3ec8cf5f2436e003ebc383801d215ec7784ebfb478344a1e7acd951950b2f - C:\Windows\System32\Pnimco32.dll -
1b76fdddb9538c4b9955b3dddaf39c1dd64992c15ad1fa6a30417ec755a86d51 - C:\Windows\System32\Gfcnjj32.dll -
994920c2411852fd879d0edb7dfac9053bb84dc2eca4abe834a7e041051ce305 - C:\Windows\System32\Knaqknql.dll -
06bc67719bce426db4faff67e83b941446b8ef18819d5e337959898f325ff115 - C:\Windows\System32\Mkhffmga.dll -
0cea80cb44cb4b288e792e3172dab0a08f387c222f20f1aeb4d98b223b719117 - C:\Windows\System32\Kjhibfeo.exe -
76cda388e93c27def45c2d4456cc4e2a3796db5237b89744c60d8c9fef82de32 - C:\Windows\System32\Ofjmkd32.exe -
ce0a7d4ee7a88d2b4f402f244fd09801787fd9f939d8a8dd091097a8ff375c3f - C:\Windows\System32\Opionk32.exe -
9222fb08c3fbd7103c450b2e08edd2faf491300747a3748f971816e55c8fd699
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787795956&P2=404&P3=2&P4=lHm1thhx7E7YE0V9jriKBhM%2fFGR7u5SkLAczogO8DTNZDIBJGSGqSDJY1vBr6ye7eQBJMuJvF8ozLtsxlqW9Eg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787795988&P2=404&P3=2&P4=ax%2fCEzf%2fdfQQpMuqh3X7jMIqfmEWdlYBBChrlfArOy2NdSF8kZp1m9h6UzDHboLBFWxOR%2fBagrvGXviPd7p1Aw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- oneclient.sfx.ms
Embedded IP addresses
- 20.184.175.10
- 20.42.179.192
- 4.230.171.124
- 20.247.184.197
- 57.155.101.212
- 74.179.77.204
- 74.178.76.54
- 51.105.71.137
- 20.236.44.162
- 40.99.133.210
- 52.123.129.14
- 52.123.128.14
- 20.42.73.26
- 20.165.94.63
- 135.233.45.221
- 203.26.79.13
- 135.232.92.34
- 52.148.114.188
- 20.42.65.94
- 20.42.65.89
- 72.153.5.132
- 52.182.143.212
- 48.211.4.16
- 20.50.201.205
- 20.42.65.90
More Crypted samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report