MALICIOUS — ce77d116a074dab7a22a0fd4f2c1ab475f16eec42e1ded3c0b0aa8211fe858d6
MALICIOUS — ce77d116a074dab7a22a0fd4f2c1ab475f16eec42e1ded3c0b0aa8211fe858d6 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Sunburst family. 7 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
ce77d116a074dab7a22a0fd4f2c1ab475f16eec42e1ded3c0b0aa8211fe858d6 - SHA-1:
d130bd75645c2433f88ac03e73395fba172ef676 - MD5:
846e27a652a5e1bfbd0ddd38a16dc865 - imphash:
dae02f32a21e03ce65412f6e56942daa - ssdeep:
12288:5JKoHwfn/jz3bbO4Qag2I97PMieSLezPKT+BYvjenWHuhh9c0g8vkzK19Q:vEfDbO97P8TrK0YbenWH4c0g8vkzK19 - TLSH:
T1485339DC152FB311D339C93A2940EAEE5C58B8942ABDB76C0F454A72101197BFC7A0AD - Submitted as: ce77d116a074dab7a22a0fd4f2c1ab475f16eec42e1ded3c0b0aa8211fe858d6
- File type: pe · Size: 1028072 bytes
- Verdict: malicious (100/100) · Family: Sunburst
Detections (7 of 52 engines)
- capa (capabilities): capability:execution/powershell
- ClamAV (daily): Win.Countermeasure.Sunburst-9809152-0
- Cyble Vision: Cyble Vision: Cobalt Strike
- Microsoft Defender: Trojan:MSIL/Solorigate!atmn
- Emsisoft (Emergency Kit): Trojan.Win32.Sunburst
- Trellix Stinger (McAfee): Trojan-sunburst
- Kaspersky (KVRT): HEUR:Backdoor.MSIL.SunBurst.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Countermeasure.Sunburst-9809152-0 (rule
Win.Countermeasure.Sunburst-9809152-0) - engine signal, weight 0.90, confidence 0.95 - Cyble Vision flagged Cyble Vision: Cobalt Strike (rule
Cyble Vision: Cobalt Strike) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:MSIL/Solorigate!atmn (rule
Trojan:MSIL/Solorigate!atmn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Win32.Sunburst (rule
Trojan.Win32.Sunburst) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Trojan-sunburst (rule
Trojan-sunburst) - engine signal, weight 0.55, confidence 0.85 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Embedded network infrastructure: http://sv.symcb.com/sv.crl0a, https://d.symcb.com/rpa0, http://sv.symcb.com/sv.crt0 - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
48 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://sv.symcb.com/sv.crl0a
- https://d.symcb.com/rpa0
- http://sv.symcb.com/sv.crt0
- http://www.symauth.com/cps0
- http://www.symauth.com/rpa00
- http://s1.symcb.com/pca3-g5.crl0
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
- http://solarwinds.s3.amazonaws.com/solarwinds/Release/MIB-Database/MIBs.zip
- https://www.solarwinds.com/embedded_in_products/productLink.aspx?id=online_quote
Embedded domains
- www.solarwinds.com
- thwackfeeds.solarwinds.com
- sv.symcb.com
- d.symcb.com
- www.symauth.com
- s1.symcb.com
- www.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- cacerts.digicert.com
- solarwinds.s3.amazonaws.com
- t.name
- agents.name
- tf.name
- s.name
Embedded IP addresses
- 2.1.1.5
- 2.1.1.4
- 2.1.1.6
- 2.1.1.1
- 1.1.1.1
- 4.1.9.9
- 109.1.1.1
- 1.1.2.1
- 1.1.1.28
- 1.1.20.0
- 1.20.1.1
- 1.1.5.3
- 1.1.1.2
- 2.1.25.3
- 3.1.2.0
- 4.1.9.2
- 2.1.25.2
- 4.1.23.2
- 27.2.1.3
- 27.2.1.6
- 27.2.1.4
- 27.2.1.5
- 27.2.1.7
- 27.2.1.8
- 27.2.1.1
File paths
- C:\buildAgent\temp\buildTmp\Obj\SolarWinds.Orion.Core.BusinessLayer\Release\SolarWinds.Orion.Core.BusinessLayer.pdb
More Sunburst samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report