MALICIOUS — c69b9433f8d09671099d736b593d8a1f7430f8c8325a95255e22c28a3e331a77
MALICIOUS — c69b9433f8d09671099d736b593d8a1f7430f8c8325a95255e22c28a3e331a77 is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 5 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c69b9433f8d09671099d736b593d8a1f7430f8c8325a95255e22c28a3e331a77 - SHA-1:
28038022412801fa27024b4720d458258d0da13a - MD5:
3d6fc032cca29fe6ea9548985c2677f8 - ssdeep:
96:n5zI1DIfNxoDfLiDoeduQfAGfaqQ9fk6KMvYVaAVlYMaVnJmt9yTYVocnXmuz:aI1yDji0cuQWD9M6WVnVlYMaVnJmt9y8 - TLSH:
T1F11A61B84BB024808251646205516964BE9DBC72A5337BCE19FE4A333C7F39265F42FB - Submitted as: c69b9433f8d09671099d736b593d8a1f7430f8c8325a95255e22c28a3e331a77
- File type: script · Size: 4432 bytes
- Verdict: malicious (99/100)
Detections (5 of 54 engines)
- YARA: MalwareAnalyser built-in: Suspicious_PowerShell_Download_Exec
- capa (capabilities): capability:execution/powershell
- YARA: MalwareAnalyser community pack: TL_Suspicious_PowerShell_Download
- Emsisoft (Emergency Kit): Trojan.GenericKDZ.86459
- Kaspersky (KVRT): HEUR:Exploit.Java.CVE-2019-2725.gen
MITRE ATT&CK
YARA
- Suspicious_PowerShell_Download_Exec
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- Encoded/hidden PowerShell download-and-exec (rule
Suspicious_PowerShell_Download_Exec) - yara signal, weight 0.70, confidence 0.90 - Emsisoft (Emergency Kit) flagged Trojan.GenericKDZ.86459 (rule
Trojan.GenericKDZ.86459) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Exploit.Java.CVE-2019-2725.gen (rule
HEUR:Exploit.Java.CVE-2019-2725.gen) - engine signal, weight 0.55, confidence 0.85 - Obfuscated powershell script: download, dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - YARA: MalwareAnalyser community pack flagged TL_Suspicious_PowerShell_Download (rule
TL_Suspicious_PowerShell_Download) - engine signal, weight 0.50, confidence 0.70 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: MalwareAnalyser built-in flagged Suspicious_PowerShell_Download_Exec (rule
Suspicious_PowerShell_Download_Exec) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.bea.com/async/AsyncResponseService, http://194.38.20.31/xms.ps1, 194.38.20.31 - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1152 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- _dosvc._tcp.local
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.85
- 23.11.37.157
- 40.126.14.160
- 52.110.12.55 AU · Sydney · AS8075 Microsoft Corporation
- 23.33.238.135
- 4.247.188.224 IN · Pune · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.207
Embedded URLs
- http://schemas.xmlsoap.org/soap/envelope/
- http://www.w3.org/2005/08/addressing
- http://www.bea.com/async/AsyncResponseService
- http://bea.com/2004/06/soap/workarea/
- http://194.38.20.31/xms.ps1
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- schemas.xmlsoap.org
- www.w3.org
- www.bea.com
- bea.com
Embedded IP addresses
- 194.38.20.31
- 74.178.240.61
- 57.154.63.210
- 203.26.79.13
- 72.154.7.113
- 4.150.223.114
- 85.210.196.11
- 52.110.12.55
- 4.247.188.224
- 4.230.171.124
- 51.11.192.50
- 135.233.95.144
- 72.154.7.111
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report