MALICIOUS — d2795375b060f7bfc14b5d04bde0e091245892f3ce121d47cddc810cdcf898c6
MALICIOUS — d2795375b060f7bfc14b5d04bde0e091245892f3ce121d47cddc810cdcf898c6 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Crypted family. 4 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
d2795375b060f7bfc14b5d04bde0e091245892f3ce121d47cddc810cdcf898c6 - SHA-1:
6ceefb97d22060a7f1703c1bbd85b0cdc9b44fbd - MD5:
edff9f57397a83573a6ae1e1dd737a52 - imphash:
95e6f8741083e0c7d9a63d45e2472360 - ssdeep:
1536:vhpQ05KagsmfdusoEnhM/qZ/Ev9guOgBiA5W9KjCASgvIGLy9mN076Z+EnhM/qZ:5pQPs9l0h/81B5/CARn0U0K+0h/81B5 - TLSH:
T191414ABB86FCA411D888B737E008516CB0194F74F1F46256CF3501AF9B8BE9B9A83615 - Submitted as: d2795375b060f7bfc14b5d04bde0e091245892f3ce121d47cddc810cdcf898c6
- File type: pe · Size: 186368 bytes
- Verdict: malicious (92/100) · Family: Crypted
Detections (4 of 55 engines)
- ClamAV (daily): Win.Trojan.Crypted-29
- Microsoft Defender: Backdoor:Win32/Berbew!pz
- Emsisoft (Emergency Kit): GenPack:Backdoor.Hangup.B
- Kaspersky (KVRT): Trojan-Spy.Win32.Qukart.af
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypted-29 (rule
Win.Trojan.Crypted-29) - engine signal, weight 0.90, confidence 0.95 - Contacted 22 external host(s) at runtime (20 HTTP) - network signal, weight 0.40, confidence 0.80
- Dropped 96 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
3012 behavior events · 1 ATT&CK techniques · 96 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Dropped files
- C:\Windows\System32\Ggpmli32.dll -
f87dff9870bb596bb9393fb869bb98edef9c3521a5e478dac6703df78d6c068f - C:\Windows\System32\Igafiq32.dll -
db928e323570801c5b22578c8b8e2f0964749875e605066eab9a7ac0e9f23128 - C:\Windows\System32\Lplgkl32.exe -
4a9b1e1ef41adfb0b446ffa8178acb8c4a9d6d747de5c4209d160f40eb5017b4 - C:\Windows\System32\Moghdo32.exe -
1df24a95ece417c7c82414e590c22204a75fdc6144a8e376a916d11445fa301d - C:\Windows\System32\Jqoegpkj.dll -
99136cf09ae1a1a0ee252029c0b2d30004b08516f9b73eb91da81ef1c3fcd4c0 - C:\Windows\System32\Jhbloh32.dll -
bb8be4925ced134ec67b97766e929715b286be0bfa147de60e27daf7484d1050 - C:\Windows\System32\Cgkpjaog.exe -
955ddf2f3ec0f69f12806fca88f64826e98fa0d45c6810186d9797c032afdfb2 - C:\Windows\System32\Jciddeji.dll -
5e110e7ff8fb384d140f384ae3f828da90395eb01b526a7b28441c80b06c999e - C:\Windows\System32\Fngipm32.exe -
d8a79373273f291b10532d467c2de5b7c615304a8deb99603b1625b4f922dfb5 - C:\Windows\System32\Kbkeallc.dll -
c08522102e6008b895f3d9415b503f4f8ed38706d7deb4a221af3889363e2e9b - C:\Windows\System32\Jjgaglbk.dll -
9178aa2acab132d18fb6180c62ef2cd3247d64124195cdc45470e89b28544aaa - C:\Windows\System32\Aknfhmho.exe -
dfd3a4d35287c11102e980a77de69e03907b81e024523a3542f6ff11904ccf38 - C:\Windows\System32\Ggdoqcji.dll -
9fe4fe4eab7cb8ac2b32f3353305e853c0d4c4fc49392d6250aa7a7b1cb338f2 - C:\Windows\System32\Ocpooijd.dll -
8eba656aa57e86a7f39ce2f410d366ce74cde29eae256c3134d759488f16ad98 - C:\Windows\System32\Lapjpe32.dll -
3b1bf4667b9989d9c8507083fbabbdebd03794f3ffad0d40736480676ed24ae1
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787799858&P2=404&P3=2&P4=lR5m15qi1tdBe4tPmtRiD%2bpV0H8euS55TOZj9qnyQqJFCYg%2bTgx2IxcuQ86B%2bhjNfJV74ZPw41UQwXWm%2frQLZA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787799951&P2=404&P3=2&P4=CYKXBtXB8umod6E%2fdQfbowXrb1d%2f2gYZjzqnhMrovuPOmgDOTa5%2be7WmUziYjPQjqCOYe2%2fhFQuhQ1wvvOcZ3A%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 4.150.223.108
- 52.123.252.229
- 4.230.171.124
- 20.42.179.204
- 4.144.132.223
- 135.233.95.144
- 135.232.92.97
- 13.89.179.15
- 20.76.201.171
- 52.123.128.14
- 20.42.73.24
- 135.234.160.245
- 203.26.79.13
- 52.148.114.188
- 52.123.252.227
- 135.232.92.34
- 52.123.252.193
- 52.123.252.198
- 135.233.45.222
- 72.153.5.60
- 52.110.12.53
- 52.110.12.45
More Crypted samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report