MALICIOUS — c760fb2a7249448811c1af6495705c365596149ae393696340fa943cd1db49ef
MALICIOUS — c760fb2a7249448811c1af6495705c365596149ae393696340fa943cd1db49ef is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Genome family. 7 of 56 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
c760fb2a7249448811c1af6495705c365596149ae393696340fa943cd1db49ef - SHA-1:
6b7a3d7cbea9fb868c1b9b341aa628411d1f6f23 - MD5:
df70b93118ce35b90a5927acd6df15d6 - imphash:
a2d15c16f6fabfe6d7dfbc495f06e242 - ssdeep:
12288:DtyJr4HHfgzLRXH+WjIknWRBe3l12E3qq:oJMH4/R3FFnWKDXaq - TLSH:
T15C4A9FBE17277703DA3BCA284844BF4E0476F85E10BD248D4657657CA3E9CA72A00B9D - Submitted as: c760fb2a7249448811c1af6495705c365596149ae393696340fa943cd1db49ef
- File type: pe · Size: 458752 bytes
- Verdict: malicious (100/100) · Family: Genome
Detections (7 of 56 engines)
- capa (capabilities): capability:collection/keylog
- MalwareAnalyser heuristics (entropy/packer): UPX
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:Turbo Linker
- Emsisoft (Emergency Kit): Gen:Variant.Downloader.665
- Kaspersky (KVRT): Trojan-Downloader.Win32.Genome.ajdq
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 17 weighted signals:
- YARA: delivr.to detections flagged DLV_Maldoc_VBA_AutoExec (rule
DLV_Maldoc_VBA_AutoExec) - engine signal, weight 0.70, confidence 0.70 - Emsisoft (Emergency Kit) flagged Gen:Variant.Downloader.665 (rule
Gen:Variant.Downloader.665) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-Downloader.Win32.Genome.ajdq (rule
Trojan-Downloader.Win32.Genome.ajdq) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s) across 1 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 5 external host(s) and 15 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:collection/keylog (rule
capability:collection/keylog) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.rdscanada.ca/images/winns.exe, http://www.treewhispers.com/stories/winns.exe, http://www.koja-lindlar.de//bilder/2008_05_18/winns.exe - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: UPX, Turbo Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
6779 behavior events · 2 ATT&CK techniques · 10 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- www.rdscanada.ca
- www.treewhispers.com
- c.pki.goog
- treewhispers.com
- www.koja-lindlar.de
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- licensing.mp.microsoft.com
- assets.msn.com
Dropped files
- C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA -
a99b0491f4bdd8b44cf8073b5b827a6b81a2b0c9cbf04692cfa037e1cd74531b - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05DDC6AA91765AACACDB0A5F96DF8199 -
a6f8f5d4ffd1e825ffce9a55861f16aa4dbe67871b1696b976194dd8be1fdf29 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2FE8C49700FF8424764C56660092EBD4 -
331d95de9926c5af9678afe4c31bc25592e6f9324071c9c8bdad55ba6216184c - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2FE8C49700FF8424764C56660092EBD4 -
9de49d9b8a537927d5d8b35ab6c8f641e435e548ff78e4f8c55dbadd8158f657 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F23ABF92C22B6AEF874EEB91DFCBB6A1 -
b971df79b68ddd1eb4151da0d49127c29a142d8aadfebc7b58844da30892503d - C:\Users\analyst\AppData\Local\Microsoft\Windows\INetCache\IE\H9BOFF51\winns[1].htm -
9e17cb15dd75bbbd5dbb984eda674863c3b10ab72613cf8a39a00c3e11a8492a - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA -
d74acc2bcb5544795848ef326cd91104c3df25dabf2f40db18465116a89c926b - C:\Users\analyst\AppData\Local\Microsoft\Windows\INetCache\IE\9G746KYB\winns[1].htm -
7e8b90211a289f88bfdd5e7b10794981d7b806a0697d116555977d0c3c1ef95a - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05DDC6AA91765AACACDB0A5F96DF8199 -
0d1cc2792df5c9c5a233b962cc84253a6e77a58ecb7e51ea8a4e8c33201f63a8 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F23ABF92C22B6AEF874EEB91DFCBB6A1 -
75c8a5e41f2a8a0e47bf03280ca5864c88c978b6b00d91f888669c13e6bd6c77
Embedded URLs
- http://www.rdscanada.ca/images/winns.exe
- http://www.treewhispers.com/stories/winns.exe
- http://www.koja-lindlar.de//bilder/2008_05_18/winns.exe
- http://www.ueltschi.org/teaching/2009-MA131/winns.exe
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://c.pki.goog/wr1/QHNqq_7Jb2g.crl
- http://c.pki.goog/wr1/ehmxk4X0Mqk.crl
Embedded domains
- www.rdscanada.ca
- www.treewhispers.com
- www.koja-lindlar.de
- www.ueltschi.org
- treewhispers.com
Embedded IP addresses
- 4.150.223.98
- 52.123.252.203
- 20.247.184.142
- 4.230.171.124
- 57.155.101.212
- 192.0.78.168
- 66.96.149.1
- 157.90.33.73
- 135.234.160.244
- 20.42.179.192
- 52.110.12.10
- 52.110.12.32
- 184.84.165.136
- 72.145.35.98
- 52.148.114.188
- 52.110.12.24
- 52.110.12.49
More Genome samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report