MALICIOUS — c3f972c29455988064dda1f4412c386c41c5283bc405f689a84609310ab25608
MALICIOUS — c3f972c29455988064dda1f4412c386c41c5283bc405f689a84609310ab25608 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (70/100), attributed to the ASPack family. 7 of 25 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c3f972c29455988064dda1f4412c386c41c5283bc405f689a84609310ab25608 - SHA-1:
ba71dea5d7d90abd164ed0a9f60454d10c5990c5 - MD5:
53199b2b0cecf8fe45f839801195efc9 - imphash:
ac99a5a6590e07f40380584be971cd01 - ssdeep:
12288:RIbnq5ORFftIiB6gBFvST9kFO14SFoktWEY+ucXz+J6nJELcUmQ+7B:RIbq0ft8gLvoko1hmkQ5cXzyvL/o - TLSH:
T1AD4B239A153A015BD145B09C36029B3FC3A873A593F99BCC3A632D832253963C97E563 - Submitted as: c3f972c29455988064dda1f4412c386c41c5283bc405f689a84609310ab25608
- File type: pe · Size: 480357 bytes
- Verdict: malicious (70/100) · Family: ASPack
Detections (7 of 25 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.MPRESS1
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:MPRESS 2.01-2.12
- Microsoft Defender: Trojan:Win32/Urelas.HNS!MTB
- Emsisoft (Emergency Kit): Gen:Trojan.Heur.Dmrar9EqNypGy
- Trellix Stinger (McAfee): Obfuscated-FQZ!hb
- Kaspersky (KVRT): HEUR:Trojan.Win32.Urelas.a
MITRE ATT&CK
Why this verdict
The malicious score of 70/100 is the fusion of 5 weighted signals:
- Contacted 46 external host(s) at runtime (29 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:MPRESS 2.01-2.12 (rule
DIE:MPRESS 2.01-2.12) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.MPRESS1, MPRESS 2.01-2.12 - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
8873 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/2cbcf400-ac8d-4d86-9d69-c7f0dff56d2e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/2cbcf400-ac8d-4d86-9d69-c7f0dff56d2e?P1=1786748269&P2=404&P3=2&P4=FyrqtlkTDMhnEclzEPavype3yDz2gtSQgnh9OIViZHfOOqZ7nC38VbP%2bQuc8B7JBiv7xjsXefbQF0%2fJ8vj2BRw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/1d8d0488-0a3b-440b-b2a9-36df2b9d4ebd/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/1d8d0488-0a3b-440b-b2a9-36df2b9d4ebd?P1=1786748288&P2=404&P3=2&P4=FdlQo4xGrfVGE0cFNWa46uPhCQWPJZxVcVjUop4u5qmF92S1lOFZjWz%2bjyH9o2UdtMUxsE6Y8pQkGZxxCUoCWQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- s.ai
Embedded IP addresses
- 4.150.223.97
- 52.123.252.194
- 4.230.171.124
- 48.211.4.16
- 52.230.59.222
- 135.232.92.137
- 135.232.92.97
- 20.52.64.200
- 52.123.129.14
- 20.231.239.246
- 52.123.128.14
- 52.123.252.229
- 135.234.160.245
- 74.178.76.44
- 203.26.79.13
- 162.159.142.9
- 40.84.97.4
- 135.233.95.144
- 184.84.165.136
- 172.170.180.133
- 20.42.73.31
- 52.123.252.242
- 72.153.5.62
- 20.50.201.201
- 52.148.114.188
More ASPack samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report