MALICIOUS — caab9bffb4f64ba498dabe03ddd9196f610b398f02f75d2dc87d15f80cd124bd
MALICIOUS — caab9bffb4f64ba498dabe03ddd9196f610b398f02f75d2dc87d15f80cd124bd is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the RedLine family. 7 of 56 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
caab9bffb4f64ba498dabe03ddd9196f610b398f02f75d2dc87d15f80cd124bd - SHA-1:
109fcb73f551e14411af06c5ab358eb03ae0fca2 - MD5:
966435a94ae36680749c810b1569a0d5 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
3072:nU7dmhTEnyklIRZ92bzJzN+1ow5QjYgB3iI9mgcO2+aaWAw:U7dmhTEnyIIRZ92bzJzwEB3F7cfg - TLSH:
T1E73E9D46CACD8E33C6FF6D9E253F443F46CA5A1FE874290861BE25B284522C3863D525 - Submitted as: caab9bffb4f64ba498dabe03ddd9196f610b398f02f75d2dc87d15f80cd124bd
- File type: pe · Size: 148770 bytes
- Verdict: malicious (100/100) · Family: RedLine
Detections (7 of 56 engines)
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:Win32/Wacatac.B!ml
- Emsisoft (Emergency Kit): Gen:Variant.Barys.430087
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 17 weighted signals:
- Extracted RedLine config (1 C2) - engine signal, weight 0.80, confidence 0.60
- Microsoft Defender flagged Trojan:Win32/Wacatac.B!ml (rule
Trojan:Win32/Wacatac.B!ml) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Barys.430087 (rule
Gen:Variant.Barys.430087) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win32.Generic (rule
HEUR:Trojan.Win32.Generic) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s) across 1 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Contacted 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082, T1497 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged Microsoft Linker (rule
Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 6.9.0.114 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. RWX/private injected region in SppExtComObj.E (pid 5932) (rule
windows.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
51716 behavior events · 2 ATT&CK techniques · 5 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- odc.officeapps.live.com
- www.msn.com
- www.bing.com
- assets.msn.com
- watson.events.data.microsoft.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Dropped files
- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tsk_7e6fc86fb496_cb22fa3f8ab4a2617ad383e34a27d08d287b47dc_00000000_d6395b3e-776d-435b-8905-6486a94aca36\Report.wer -
0f04af9dc2c123f0689bd71dd396d78a987957e7d4929000296ce5b550a3b704 - 3da02e78a6170665a65969e9e87fa0e15e09ea61b1fdaf9fe02ae9180fad69cc -
3da02e78a6170665a65969e9e87fa0e15e09ea61b1fdaf9fe02ae9180fad69cc - 360edd511a8a05a3c892a6ed44546d94eadc82fdcfec4fee149975ddc45ef701 -
360edd511a8a05a3c892a6ed44546d94eadc82fdcfec4fee149975ddc45ef701 - b9d9e54e037ae097f24f46b21ae993c248b4c941e3a7e6c841b18e34ac085932 -
b9d9e54e037ae097f24f46b21ae993c248b4c941e3a7e6c841b18e34ac085932 - 7dd42e7cf6f416e037bd77656757164024d2d70addff6254a337a287736edb10 -
7dd42e7cf6f416e037bd77656757164024d2d70addff6254a337a287736edb10
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 6.9.0.114
- 4.150.223.113
- 52.253.84.76
- 52.123.252.222
- 4.230.171.124
- 135.233.45.223
- 162.159.142.9
- 52.110.12.46
- 52.110.12.40
More RedLine samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report