MALICIOUS — cd59adea9ff9f62d3a384585b4d68a8293b26ec9080166dcad31317803fbce5d
MALICIOUS — cd59adea9ff9f62d3a384585b4d68a8293b26ec9080166dcad31317803fbce5d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 7 of 55 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
cd59adea9ff9f62d3a384585b4d68a8293b26ec9080166dcad31317803fbce5d - SHA-1:
83a5354b68b03094b1ab707aea66895d8297381c - MD5:
694681c199884ef5faf9fd7106738102 - imphash:
87bed5a7cba00c7e1f4015f1bdae2183 - ssdeep:
3072:oFUTOgM+xqMFdxyK0hGo3hoBTobshWJtD2:lZMSFnyK0hG2hShstK - TLSH:
T1C13D1230B8AB1C32F66EE1323D4213EDC624D679CEFD1A1983408258ED7A11F765CA09 - Submitted as: cd59adea9ff9f62d3a384585b4d68a8293b26ec9080166dcad31317803fbce5d
- File type: pe · Size: 131620 bytes
- Verdict: malicious (99/100)
Detections (7 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:bero^fr
- ClamAV (daily): Win.Malware.Byfh-6912997-0
- Detect It Easy (packer/type): DIE:BeRoEXEPacker
- Microsoft Defender: Trojan:Win32/Vflooder.C
- Emsisoft (Emergency Kit): Trojan.GenericKD.34745281
- Trellix Stinger (McAfee): Trojan-FPLW!694681C19988
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Win.Malware.Byfh-6912997-0 (rule
Win.Malware.Byfh-6912997-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 4 finding(s), e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 27 external host(s) at runtime (34 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:BeRoEXEPacker (rule
DIE:BeRoEXEPacker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:bero^fr , BeRoEXEPacker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
80454 behavior events · 2 ATT&CK techniques · 9 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- google.com
- c.pki.goog
- www.virustotal.com
- a6281279.yolox.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
Dropped files
- C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05DDC6AA91765AACACDB0A5F96DF8199 -
6702b2490fb5f7a2770c2b45929c55e37199fdcd47f7f381837178abab31f31f - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05DDC6AA91765AACACDB0A5F96DF8199 -
a6f8f5d4ffd1e825ffce9a55861f16aa4dbe67871b1696b976194dd8be1fdf29 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA -
daa1b5866a93c20d1c8be015ba22faa8fb02a14e9f9f72afd2171c6f685326f2 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75A092F4522006A97542D6AC4F4E69D2 -
5b136773b0f377976e30ebdf1cdeb368227211d65bff2654e50fe461c2110bb9 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75A092F4522006A97542D6AC4F4E69D2 -
88a0656ad5407a82a003e37b35e1ea8569aa648382c2ae143bc97965b6112634 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA -
21dd2513fa7c4380d41c0e87c8099bd27d5d64aaa2d8d9113972e302e6ceaadc - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\71D3A36027B1506445FB345FD67207AC -
e8cfdb6ac7494ca88346114baa3e844607807ac5b36d602e04e88f5e57dd3919 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\71D3A36027B1506445FB345FD67207AC -
a95fc9304e6b6a815cdade01c53e4a0f40c847e126d0d97d4e20b9808d4a4a3d - 3671e6f5a73ace7d135515131bdbb295ec0bb86f197524f83298b194f7dbdc04 -
3671e6f5a73ace7d135515131bdbb295ec0bb86f197524f83298b194f7dbdc04
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787801135&P2=404&P3=2&P4=NTkIavhwEDHVZd7cm0Cdq4ErjYkCnxO6jcssyHMoavfv8CGpEyEMeenSmICIZblyqw9ZU8rxg0l7K%2fhrNdcH4w%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://google.com/
- http://c.pki.goog/r/r1.crl
- http://c.pki.goog/wr2/oBFYYahzgVI.crl
- http://www.virustotal.com/vtapi/v2/file/scan
- http://c.pki.goog/wr3/MbJBMFoQ-sk.crl
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787801185&P2=404&P3=2&P4=hNDmhfeIEmf5ArmFcnC4%2bbEqM1PWm%2bafda31CdIiBQ2x5lutA0WGD%2fYOkZLYUZD4jiq149KKV4kORNMDr%2bqO6Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787197947&P2=404&P3=2&P4=bHmid0%2bz0SHmBZfo4Rjpa%2fKfJcEHbm6wSHGcqdQrV9cO1oZbi8j9qV33CoQW0nHoW4%2bo3L15l1aDu4Hg16FyJA%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/b56480f9-8215-4de7-ba7e-8e690088d21d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/b56480f9-8215-4de7-ba7e-8e690088d21d?P1=1787197469&P2=404&P3=2&P4=TK2UjZ7rFKsN3QwHSEGLKttwUJFMMSqvZKcA945GlUyTHBADuWt8dmewKDMD%2bi3JM3q%2bAhvM4%2bzirK52ZAA3wA%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- www.virustotal.com
- a6281279.yolox.net
Embedded IP addresses
- 13.69.109.130
- 4.230.171.124
- 52.230.59.222
- 4.247.188.224
- 52.123.252.244
- 74.178.232.29
- 74.178.240.61
- 52.182.143.212
- 74.178.76.54
- 74.178.76.128
- 203.26.79.13
- 20.112.250.133
- 40.99.133.210
- 52.123.128.14
- 52.123.129.14
- 34.54.88.138
- 135.233.45.222
- 162.159.142.9
- 52.148.114.188
- 4.247.188.233
- 72.145.35.110
- 4.150.223.104
- 20.42.73.28
- 52.110.12.42
- 142.251.222.14
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report