MALICIOUS — ca5f4806b481c58175f0175d2c1c4e883efe464f93aee3ec978a74001598fdf6
MALICIOUS — ca5f4806b481c58175f0175d2c1c4e883efe464f93aee3ec978a74001598fdf6 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the RedLine family. 4 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
ca5f4806b481c58175f0175d2c1c4e883efe464f93aee3ec978a74001598fdf6 - SHA-1:
4a09a14c217024e268cd9c69bee08dd965426a30 - MD5:
6975c4025d6b66d9f27becc3ef860011 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
6144:oQIidCjrlBtKw3hBUkt9h03tJuVsK+6UQXnNVD3Mhbf:Ai0fym9hHsK+6fj3Mhr - TLSH:
T1FA471E46829C5D90C4DC56BE0E7E0D9FDBEF142A90B3331F2369483A4AA8573C5217B6 - Submitted as: ca5f4806b481c58175f0175d2c1c4e883efe464f93aee3ec978a74001598fdf6
- File type: pe · Size: 341400 bytes
- Verdict: malicious (100/100) · Family: RedLine
Detections (4 of 56 engines)
- LIEF (executable format parser): lief:invalid-authenticode
- Emsisoft (Emergency Kit): IL:Trojan.MSILZilla.9531
- Trellix Stinger (McAfee): AgentTesla-FDDZ!6975C4025D6B
- Kaspersky (KVRT): UDS:Trojan-Spy.MSIL.Stealer.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- Extracted RedLine config (1 C2) - engine signal, weight 0.80, confidence 0.90
- Memory forensics: 1 finding(s) attributed to the sample across 1 technique(s), e.g. process hollowing in tsk_eee98d534b (pid 2224) (rule
windows.hollowprocesses.HollowProcesses) - memory signal, weight 0.70, confidence 0.85 - Emsisoft (Emergency Kit) flagged IL:Trojan.MSILZilla.9531 (rule
IL:Trojan.MSILZilla.9531) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged AgentTesla-FDDZ!6975C4025D6B (rule
AgentTesla-FDDZ!6975C4025D6B) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:Trojan-Spy.MSIL.Stealer.gen (rule
UDS:Trojan-Spy.MSIL.Stealer.gen) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 1 external host(s) and 17 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 1.0.97.57 - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
5936 behavior events · 2 ATT&CK techniques · 12 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
Dropped files
- c6b274ae2f66d717ef3f33fd4f292c429025c855b780d9d356b8637b0eea0273 -
c6b274ae2f66d717ef3f33fd4f292c429025c855b780d9d356b8637b0eea0273 - 38421cb676a2757ea564fe975d66c6a36011c5fc1a9cf278acd05ca195e428f8 -
38421cb676a2757ea564fe975d66c6a36011c5fc1a9cf278acd05ca195e428f8 - e02925897b4aa06a852ab636859a5232955208047793d11cf99e0c080523a843 -
e02925897b4aa06a852ab636859a5232955208047793d11cf99e0c080523a843 - fae338ca23411cbed003c181cf4d314a414172df6af194937f6a37de9ed9dd24 -
fae338ca23411cbed003c181cf4d314a414172df6af194937f6a37de9ed9dd24 - 485d33cfa9f1a98af2e587d8e17306d6ba7cadeb9cfbee63bff9e3c6a0808d35 -
485d33cfa9f1a98af2e587d8e17306d6ba7cadeb9cfbee63bff9e3c6a0808d35 - 8eb9143a0c6f35ccdf7a945546ee686acf62aca217594c20c84bd5bcf0e1ce28 -
8eb9143a0c6f35ccdf7a945546ee686acf62aca217594c20c84bd5bcf0e1ce28 - 788d04e32b466c049843325d2afbed14efe93f0bdef1cc4a7acfbea4824fc292 -
788d04e32b466c049843325d2afbed14efe93f0bdef1cc4a7acfbea4824fc292 - 774965e45a5a5de31399197f3efc5014ccf911030548810c443f396e5957790d -
774965e45a5a5de31399197f3efc5014ccf911030548810c443f396e5957790d - 988fc09d7e54a1a3d0d15641c77d7bc77ee64faf4a07dd058f7a08a7757d8ac9 -
988fc09d7e54a1a3d0d15641c77d7bc77ee64faf4a07dd058f7a08a7757d8ac9 - 9fab150b5a719d5fe9b438439bba9b4fb323a9482b2b1818b449545272875496 -
9fab150b5a719d5fe9b438439bba9b4fb323a9482b2b1818b449545272875496 - 9c3ede83f4e1affebdc80dfa21372de76baf972c13ed13b97524517141f16e3d -
9c3ede83f4e1affebdc80dfa21372de76baf972c13ed13b97524517141f16e3d - 8735e5b067eeb6603e57b498e3bce1c1a01cac0156dd54e3edc1433b38add743 -
8735e5b067eeb6603e57b498e3bce1c1a01cac0156dd54e3edc1433b38add743
Embedded URLs
- http://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
- https://www.digicert.com/CPS0
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- www.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- cacerts.digicert.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 1.0.97.57
- 20.50.73.14
- 20.247.184.142
- 4.230.171.124
- 85.210.193.152
- 104.18.33.89
- 135.232.92.97
- 74.179.77.204
- 4.150.223.103
- 74.178.240.61
- 92.223.78.30
- 185.215.113.57
- 52.168.117.170
- 20.42.73.31
- 172.178.240.163
- 52.148.114.188
- 72.153.5.137
- 52.110.12.40
- 52.110.12.42
More RedLine samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report