SUSPICIOUS — c6a598722f0da67eae7a2d89c231ecab1fd79dfbe1cab2686083f1e407eed554
SUSPICIOUS — c6a598722f0da67eae7a2d89c231ecab1fd79dfbe1cab2686083f1e407eed554 is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (45/100). 0 of 56 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c6a598722f0da67eae7a2d89c231ecab1fd79dfbe1cab2686083f1e407eed554 - SHA-1:
297c80203eccbc13bd02c34427b6ae0083a493f8 - MD5:
ce720e893810a32a75156bb575916f39 - imphash:
5e6955ab958f0427686406bc5d4d6248 - ssdeep:
24576:5JUw4jqUUKBUvd8JyYuLImwC9TKa5DVY8zcsnRTZ:gw4jwKBUvd8JzttyVY8r - TLSH:
T1D1589ECD061D9B12D3F2CE261E44998DD527F19A227E272C6B83863F58730A7AC6503D - Submitted as: c6a598722f0da67eae7a2d89c231ecab1fd79dfbe1cab2686083f1e407eed554
- File type: pe · Size: 1647848 bytes
- Verdict: suspicious (45/100)
Detections (0 of 56 engines)
No engine flagged this sample.
MITRE ATT&CK
Why this verdict
The suspicious score of 45/100 is the fusion of 3 weighted signals:
- Contacted 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Memory forensics: 4 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
- licensing.mp.microsoft.com
- www.bing.com
- th.bing.com
- fe3cr.delivery.mp.microsoft.com
Embedded URLs
- http://shop.microsoft.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- shop.microsoft.com
- r.office.microsoft.com
Embedded IP addresses
- 20.42.73.31
- 4.230.171.124
- 40.84.97.4
- 4.144.132.114
- 20.42.179.204
- 74.178.240.51
- 74.178.76.128
- 172.64.154.167
- 4.207.44.77
- 52.253.84.76
- 104.46.162.224
- 51.104.15.252
- 92.223.78.30
- 52.110.12.44
- 52.110.12.24
Registry keys
- HKLM\%s.
- HKCU\%s.
- HKLM\%s:
File paths
- d:\office\source\otools\inc\util\ocfx\optr.h
- d:\office\source\otools\inc\util\ocfx\ocomutility.h
- d:\office\source\setupexe\setupexe\selectculture.cpp
- d:\office\source\setupexe\setupexe\selectculturedata.cpp
- d:\office\source\setupexe\catalyst\catcore\option.cpp
- d:\office\source\otools\inc\util\ocfx\oxmlattribute.h
- d:\office\source\otools\inc\util\ocfx\oproductid.h
- d:\office\source\setupexe\catalyst\catcore\job.cpp
- d:\office\source\setupexe\lis\logic\lis.h
- d:\office\source\setupexe\catalyst\catcore\catconfig.cpp
- d:\office\source\setupexe\catalyst\catcore\catcore.cpp
- d:\office\source\setupexe\catalyst\catcore\msipackage.cpp
- d:\office\source\setupexe\catalyst\catcore\patch.cpp
- d:\office\source\setupexe\catalyst\catcore\catpatch.cpp
- d:\office\source\setupexe\catalyst\catcore\skucomponentbase.cpp
- d:\office\source\setupexe\catalyst\catcore\product.cpp
- d:\office\source\setupexe\catalyst\catcore\addon.cpp
- d:\office\source\setupexe\catalyst\catcore\msifeature.cpp
- d:\office\source\setupexe\lis\logic\lismanager.cpp
- d:\office\source\otools\inc\util\ocfx\oxmlelement.h
- d:\office\source\setupexe\lis\logic\lis.cpp
- d:\office\source\otools\inc\util\ocfx\oalloc.h
- d:\office\source\setupexe\lis\olis\olis.cpp
- d:\office\source\setupexe\watson\catwatson.cpp
- d:\office\source\util\ocfx\ostring.cpp
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report