MALICIOUS — c4d62957293602368a51c0a2aaa1e6aca9c6505830ddeafece8303cde8213721
MALICIOUS — c4d62957293602368a51c0a2aaa1e6aca9c6505830ddeafece8303cde8213721 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (82/100), attributed to the ASPack family. 3 of 55 detection engines flagged it.
Identification
- SHA-256:
c4d62957293602368a51c0a2aaa1e6aca9c6505830ddeafece8303cde8213721 - SHA-1:
f4f2f8e0c554bd68b0167f1177a9d5ee6a4dbfb5 - MD5:
5759323d362341a0bd78fbc00fb78e5d - imphash:
2d164de8123f006744f6ff354b0cb948 - ssdeep:
12288:ZeRsqm5gkhgoiMG+IFO6ee1Lb26pwQD0cKAh8:ZAFrB1Lb2QW+8 - TLSH:
T1104B23CF9E6F4A74F7F2F30299257EAE12A7176ED05E54E2218224F4208A043BC74756 - Submitted as: c4d62957293602368a51c0a2aaa1e6aca9c6505830ddeafece8303cde8213721
- File type: pe · Size: 514865 bytes
- Verdict: malicious (82/100) · Family: ASPack
Detections (3 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.MPRESS1
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:Microsoft Visual Basic
Why this verdict
The malicious score of 82/100 is the fusion of 5 weighted signals:
- Memory forensics: 4 finding(s), e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.55, confidence 0.85 - Contacted 25 external host(s) at runtime (25 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Visual Basic (rule
DIE:Microsoft Visual Basic) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.MPRESS1, Microsoft Visual Basic - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
647 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- c.pki.goog
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\TMP133.ico -
70859de6a01a06c43f1a887e0a130e7e3af20aa9e3417038fae71a880a5f0c8f - C:\Users\analyst\AppData\Local\Temp\~DFD0057258AAA46713.TMP -
a72a5530136e57028e30cda5929251061dc98444218b49472eeabceb8aa68585
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787759862&P2=404&P3=2&P4=nKtTNHzwZ4wf%2f8hMsOMW%2fyanJTue5muRTGHlGKZqdgx33jIRf%2fRtB4TY9cSGNmA7uirUoevCoxXIgGtH8%2fsIRg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787759936&P2=404&P3=2&P4=EuUk0m1Tfq41Ald07TpEYCGsLh4ZSeXAkc4sxFqJ19pslAtWXRpfdrL%2f%2fH1YcG4SyNchw3Q9HHOAQGxWwIN2dA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://c.pki.goog/r/gsr1.crl
- http://c.pki.goog/r/r4.crl
Embedded IP addresses
- 203.26.79.13
- 4.207.44.73
- 52.123.252.229
- 52.230.60.54
- 4.247.188.224
- 4.230.171.124
- 135.233.95.144
- 135.233.95.135
- 20.184.175.3
- 52.123.252.203
- 20.231.239.246
- 52.123.128.14
- 52.123.129.14
- 135.234.160.244
- 20.165.94.46
- 52.148.114.188
- 52.110.12.56
- 52.110.12.2
- 72.153.5.129
- 172.217.25.195
- 51.105.71.136
- 92.223.78.30
- 74.178.76.44
- 52.110.12.10
- 52.110.12.28
File paths
- t:\bz
More ASPack samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report