MALICIOUS — d8dd7719ea821b0ddcfec45e9fad178f6a580488784a22d952b3da8775d43404
MALICIOUS — d8dd7719ea821b0ddcfec45e9fad178f6a580488784a22d952b3da8775d43404 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100), attributed to the Glupteba family. 4 of 55 detection engines flagged it.
Identification
- SHA-256:
d8dd7719ea821b0ddcfec45e9fad178f6a580488784a22d952b3da8775d43404 - SHA-1:
2d1d3737b8ecd6775364393a4b3688cada478a32 - MD5:
6ea14aa6f47df977e3be9bb800f2f3ec - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
1536:AMNG/DiKMSdXplPRdHERkzdvB9Z9Qm6nEe3Bcw7xsBKgrKlbJvHbqz9FBlL:AJWv4/PRdHXzJB9v6R8BKmKtJvHElp - TLSH:
T13C39BEB5BE925F68FC10F0153D7AD82EA3004ABB16B6790B28CC90E0DC99517B91674B - Submitted as: d8dd7719ea821b0ddcfec45e9fad178f6a580488784a22d952b3da8775d43404
- File type: pe · Size: 84480 bytes
- Verdict: malicious (72/100) · Family: Glupteba
Detections (4 of 55 engines)
- Microsoft Defender: Trojan:Win32/Glupteba!pz
- Emsisoft (Emergency Kit): Gen:Trojan.Heur.fuW@IHo3wXi
- Trellix Stinger (McAfee): Glupteba-FTSD!6EA14AA6F47D
- Kaspersky (KVRT): HEUR:Trojan.Win32.Copak.vho
Why this verdict
The malicious score of 72/100 is the fusion of 2 weighted signals:
- Memory forensics: 5 finding(s), e.g. process hollowing in tsk_c4cee2f1b8 (pid 5416) (rule
windows.hollowprocesses.HollowProcesses) - memory signal, weight 0.70, confidence 0.85 - Contacted 19 external host(s) at runtime (14 HTTP) - network signal, weight 0.40, confidence 0.80
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 51.132.193.104
- 52.123.252.223
- 57.155.104.224
- 4.230.171.124
- 52.230.59.222
- 74.178.76.128
- 52.182.143.212
- 135.232.92.97
- 20.112.250.133
- 52.123.128.14
- 52.123.129.14
- 104.208.16.94
- 135.233.45.222
- 72.153.5.141
- 135.232.92.34
- 52.148.114.188
- 52.110.12.54
- 52.123.252.235
- 52.110.12.50
More Glupteba samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report