MALICIOUS — d8eb68b269f792a84252096db5dd7e286859edc3cb7da30d775e02fc3236f165
MALICIOUS — d8eb68b269f792a84252096db5dd7e286859edc3cb7da30d775e02fc3236f165 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Psixbot family. 6 of 56 detection engines flagged it, exhibiting 6 ATT&CK techniques.
Identification
- SHA-256:
d8eb68b269f792a84252096db5dd7e286859edc3cb7da30d775e02fc3236f165 - SHA-1:
463a7db9cff3f32c2e44bd39a7908eaaa19e5ab6 - MD5:
34d6c2a3ff2bb43cf4e3b324e33fdaaf - imphash:
8fecd48a2a2309d9acd4f1e6ab7123d1 - ssdeep:
3072:tZTz1WIXC6GESSgWNRXumi7+IF6foPCaTRMXbaev0FQcmWk6kwsNIf6cHzbQ2v0:tZHcIX9SSgMi+IFZMbQrkodzb4VF2Yd - TLSH:
T17E467CCE4119779FDA379E113850AAAEA4A2F8C6D4B53F0C0A87C43A3191C1BED7145B - Submitted as: d8eb68b269f792a84252096db5dd7e286859edc3cb7da30d775e02fc3236f165
- File type: pe · Size: 303680 bytes
- Verdict: malicious (100/100) · Family: Psixbot
Detections (6 of 56 engines)
- capa (capabilities): capability:execution/powershell
- ClamAV (daily): Win.Malware.Psixbot-9917128-0
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Trojan:Win32/PsiXBot!pz
- Emsisoft (Emergency Kit): Adware.GenericKD.61115760
- Kaspersky (KVRT): HEUR:Backdoor.Win32.PsixBot.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 16 weighted signals:
- ClamAV (daily) flagged Win.Malware.Psixbot-9917128-0 (rule
Win.Malware.Psixbot-9917128-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/PsiXBot!pz (rule
Trojan:Win32/PsiXBot!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Adware.GenericKD.61115760 (rule
Adware.GenericKD.61115760) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Backdoor.Win32.PsixBot.gen (rule
HEUR:Backdoor.Win32.PsixBot.gen) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Contacted 7 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1497, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://checkip.dyndns.org/, http://rrradiusspace.bit/, http://spinner.bit/ - static signal, weight 0.35, confidence 0.60
- 1 behavioral detection(s) across 1 rule(s): Discovery: enumerates installed security software [low] (rule
tl-security-software-discovery) - dynamic signal, weight 0.20, confidence 0.90 - Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
27396 behavior events · 2 ATT&CK techniques · 15 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- dns2.soprodns.ru
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- www.bing.com
- assets.msn.com
- licensing.mp.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- settings-win.data.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Microsoft\audiohd.exe -
fdf367b396316769b7006aeed343fe8a9ce87bc124e7e89580baddad194221a3 - C:\Users\analyst\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive -
e116e8fc07e66a65bc54c9b67bf9b073723c2cea4423f93846b38546a76ecf70 - C:\Users\analyst\AppData\Local\Temp\__PSScriptPolicyTest_glf2orbs.q10.psm1 -
96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7 - C:\Users\analyst\AppData\Local\Microsoft\local.cs -
6da3e26b268e4a6c21e192c8b9a1b89aef6880bad673b79e6a889d29641ac2cc - 9df288d7098c73a9fa5fd19c46ca81266b7c841420ea36617cd9587196703e54 -
9df288d7098c73a9fa5fd19c46ca81266b7c841420ea36617cd9587196703e54 - ce225d64589e14f8ca17792329a6c75f6c1f0b006ae3a0a193ee780e49530be3 -
ce225d64589e14f8ca17792329a6c75f6c1f0b006ae3a0a193ee780e49530be3 - 2a373a609f7f23e44b2932ff27eab92ac9abf52e92a1539adda2caf095715cc0 -
2a373a609f7f23e44b2932ff27eab92ac9abf52e92a1539adda2caf095715cc0 - ee39bc9f3b1102317e197dca7b4bdf7e0a9d19ed43635077c7a4091dbe1207f8 -
ee39bc9f3b1102317e197dca7b4bdf7e0a9d19ed43635077c7a4091dbe1207f8 - b1ae578f286f3379daf1e3c6132db706e5c58038ed8d4498c6839bea289e36f7 -
b1ae578f286f3379daf1e3c6132db706e5c58038ed8d4498c6839bea289e36f7 - 9b83c961f4a907b8eb2e53c2b9aa6efd003c52bdee8d0303c387ff64a93ea09b -
9b83c961f4a907b8eb2e53c2b9aa6efd003c52bdee8d0303c387ff64a93ea09b - 7ff22075c65ae2ca2406b99554a48bc56ba27006db08a1d7e2ab8252f9251304 -
7ff22075c65ae2ca2406b99554a48bc56ba27006db08a1d7e2ab8252f9251304 - 47d6a7cc52471e1dd317c0f2d2dc0bf127dcbc9b317242af4796402f6436e09f -
47d6a7cc52471e1dd317c0f2d2dc0bf127dcbc9b317242af4796402f6436e09f - b2aaf458904782c12be5c98b4779ae3fdacdc1e6a3dc37db589c6a3fd0c2627d -
b2aaf458904782c12be5c98b4779ae3fdacdc1e6a3dc37db589c6a3fd0c2627d - d8121a235c3e62910ff870bda6383dd565b5805138bb3d7d3e99b49b0b15dc4a -
d8121a235c3e62910ff870bda6383dd565b5805138bb3d7d3e99b49b0b15dc4a - 914373f9906967945755b1eb82901243774570fc2c586b2d40fbaf4cf8eadaba -
914373f9906967945755b1eb82901243774570fc2c586b2d40fbaf4cf8eadaba
Embedded URLs
- http://checkip.dyndns.org/
- http://rrradiusspace.bit/
- http://spinner.bit/
- http://getreserv.su/safedomain.txt
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- checkip.dyndns.org
- dns2.soprodns.ru
- dns1.soprodns.ru
- getreserv.su
- rrradiusspace.bit
- spinner.bit
Embedded IP addresses
- 5.154.191.67
- 185.121.177.177
- 169.239.202.202
- 198.251.90.143
- 111.67.20.8
- 163.53.248.170
- 139.59.17.152
- 142.4.204.111
- 142.4.205.47
- 158.69.239.167
- 192.99.85.244
- 31.3.135.232
- 31.171.251.118
- 81.2.241.148
- 62.113.203.99
- 37.58.63.27
- 130.255.78.223
- 144.76.133.38
- 82.141.39.32
- 139.59.208.246
- 172.104.136.243
- 130.255.73.90
- 195.154.226.249
- 212.47.242.157
- 87.98.175.85
File paths
- G:\WORK\MONEY\BOT\NoName\PsiX\obj\x86\Release\source2.pdb
- c:\users\user\source\repos\WindowsProject1\Release\WindowsProject1.pdb
- C:\Windows\Microsoft.NET\Framework\v4.0.30319
- C:\Program
- C:\Windows\SysWOW64\WindowsPowerShell
- C:\Windows\explorer.exe
More Psixbot samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report