MALICIOUS — DED6.tmp
MALICIOUS — DED6.tmp is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Cuegoe family. 4 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c2daa60621754ef490408c33e69fd0dcecd9e90f3935767ece1701a221b4ca00 - SHA-1:
679829a3e487fbeea35cc4dcd5a0bdaf7971fc68 - MD5:
6240831a19f881bbcb19529d0ff8cd86 - imphash:
6dca3e9fb3928bbdb54dbce669943ec8 - ssdeep:
12288:wU5rCOTeiDXuvzd4AgsX/sgH0iuTs51oNZ+3/v+I9hUG2VA:wUQOJDevZ4DsPNH+Tu2NGEA - TLSH:
T16F4ED1CE9100E741D9739F123554ADCE24A2B8D2A4763E8C0B82F03F17F5D27B85A5A9 - Submitted as: DED6.tmp
- File type: pe · Size: 667648 bytes
- Verdict: malicious (97/100) · Family: Cuegoe
Detections (4 of 55 engines)
- ClamAV (daily): Win.Trojan.Cuegoe-6336261-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: TrojanDownloader:Win32/Upatre
- Kaspersky (KVRT): HEUR:Backdoor.Win32.Salgorea.gen
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Cuegoe-6336261-0 (rule
Win.Trojan.Cuegoe-6336261-0) - engine signal, weight 0.90, confidence 0.95 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 23 external host(s) at runtime (21 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis (windows)
2644 behavior events · 1 ATT&CK techniques · 29 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- officeclient.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\3851.tmp -
038485840e32e6acc0711c73ae4b43e9684687dd62bf1467f2a5b442dd88c3d7 - C:\Users\analyst\AppData\Local\Temp\2E8D.tmp -
f9e6cd758d6040a076fd99584fbf402526d16aacb5a68d0255509f50f442d93a - C:\Users\analyst\AppData\Local\Temp\8E7F.tmp -
5623f4a3fa7004e4665ff73af1714bbf43def36cde08b14620bfb61c56ce4845 - C:\Users\analyst\AppData\Local\Temp\4FFF.tmp -
0f862d77e3a7fa59e6c51ca6560a48bd6dccceb6bbf9a1d3abd5754c2274363e - C:\Users\analyst\AppData\Local\Temp\E7DA.tmp -
0185f7d6f896725db20d405a773c48a442526f8f28ea07cd798c8e0f4407710a - C:\Users\analyst\AppData\Local\Temp\1F0C.tmp -
6bd3ddb0c44988184d3d977e66968e0d17c4e56aaf32bf779114c39aed579491 - C:\Users\analyst\AppData\Local\Temp\47DC.tmp -
9e2a31ffd982cd7bb97a0debf0f764d76d59c8af770415fe1fb7ed2b9e6c3e2d - C:\Users\analyst\AppData\Local\Temp\10D3.tmp -
0fe60b31298059aa13df88c0ce4be6eaf9c5f8fa1842022d946125c52eea9755 - C:\Users\analyst\AppData\Local\Temp\CAC8.tmp -
c9fb6b2d2d3f2cd6289a28aa67bfe65f668d65b5f2dfe5d7699b43025b47f82e - C:\Users\analyst\AppData\Local\Temp\6905.tmp -
3bd1b012a9960fc2d19b49be92d6f8fa0d52b4bd7ebcd9940150e6f5315f9087 - C:\Users\analyst\AppData\Local\Temp\47C2.tmp -
9d4da8d28230af5918ba3aa853353d84d0aaf57ce64be2cad51ebc4f712b4859 - C:\Users\analyst\AppData\Local\Temp\A761.tmp -
8995994c6d30c93259536849388c7603ee95c3e8d4650df7533797851cbd804e - C:\Users\analyst\AppData\Local\Temp\1488.tmp -
f4a05cffd552312bdfec7a2779bbd2cba642da0ae69de1ea48dcbea958a1a31a - C:\Users\analyst\AppData\Local\Temp\FBD4.tmp -
1910ad571e68300e455e604ba79959036620be93fc59353603e39af1264ad2ee - C:\Users\analyst\AppData\Local\Temp\6B14.tmp -
1f0c63a96e7e31b529faa7f8eb1021d1f991dfca278f109f2acba69307375e21
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://schemas.microsoft.com/ado/2007/08/dataservices/metadata
- http://schemas.microsoft.com/ado/2007/06/edmx
- http://schemas.microsoft.com/ado/2006/04/edm
- http://schemas.microsoft.com/ado/2007/05/edm
- http://schemas.microsoft.com/ado/2008/01/edm
- http://www.w3.org/2001/XMLSchema-instance
- http://schemas.microsoft.com/ado/2008/01/edm:OpenType
- http://schemas.microsoft.com/ado/2008/09/edm
- http://schemas.microsoft.com/ado/2006/04/edm/ssdl
- http://schemas.microsoft.com/ado/2009/02/edm/annotation
- http://schemas.microsoft.com/ado/2007/08/dataservices/scheme
- http://www.w3.org/2005/Atom
- http://www.w3.org/2000/xmlns/
- http://schemas.microsoft.com/ado/2006/04/edm/ssdl:StoreGeneratedPattern
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787696030&P2=404&P3=2&P4=dPNL4jeG6kOLTOnXcR9bVKGFEPyCb%2bKb%2bANOW4ik9vF79EF9re95TefJF0RW%2buWMtr7fwzsSVUOfBT0552%2bryg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787696123&P2=404&P3=2&P4=d3YirqQJ9IK1a1KdghhOAxDCtoMF0Cqte2jAMAf3MAWFhUsQsAIllmvwG1L5%2bd0YumbnT6NCpiiMnOXiWyqNfA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- schemas.microsoft.com
- www.w3.org
Embedded IP addresses
- 20.184.175.11
- 48.211.4.16
- 4.144.132.114
- 4.230.171.124
- 20.165.94.63
- 135.233.95.135
- 20.42.65.93
- 20.231.239.246
- 52.123.129.14
- 40.103.64.242
- 203.26.79.13
- 4.150.223.103
- 74.179.71.159
- 135.234.160.246
- 92.223.78.30
- 52.148.114.188
- 20.42.65.90
- 52.123.252.239
- 135.233.95.80
- 52.123.252.194
- 72.145.35.108
- 52.110.12.44
- 52.110.12.15
File paths
- D:\:p:
- f:\dd\tools\devdiv\EcmaPublicKey.snk
- U:\:c:j:q:x:
- P:\:d:
More Cuegoe samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report