MALICIOUS — d978d11cde9f39572409ddaa0c02d99883adc8906b868d45d919a87492816955
MALICIOUS — d978d11cde9f39572409ddaa0c02d99883adc8906b868d45d919a87492816955 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Vflooder family. 8 of 56 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
d978d11cde9f39572409ddaa0c02d99883adc8906b868d45d919a87492816955 - SHA-1:
9ad47d887fb60502d77457da20013aefc3a709c4 - MD5:
780f3e7028b9d65ba1abe17e4a19aa34 - imphash:
2530491d48892f2e1a2d640515c13122 - ssdeep:
1536:g1VPvh/81hTx5n2sR7GCjdp87t92tzJOxvxgidzdRtG:gnu1hT2sR7o7tIExJFdxRtG - TLSH:
T1C13CE0A332051EA9D7BBFBFA5D477F9D0003602351BC24C84527180E3A9156BDAB72B2 - Submitted as: d978d11cde9f39572409ddaa0c02d99883adc8906b868d45d919a87492816955
- File type: pe · Size: 117609 bytes
- Verdict: malicious (100/100) · Family: Vflooder
Detections (8 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): Themida/VMProtect
- ClamAV (daily): Win.Trojan.Agent-1388699
- YARA: Yara-Rules community: YR_Packer_VMProtect
- Detect It Easy (packer/type): DIE:MPRESS
- Microsoft Defender: Trojan:Win32/Vflooder!pz
- Emsisoft (Emergency Kit): Dump:Trojan.Agent.BYFH
- Trellix Stinger (McAfee): Agent-FEU!83C10D2F540B
- Kaspersky (KVRT): Trojan.Win32.Agent.iftf
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 17 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Agent-1388699 (rule
Win.Trojan.Agent-1388699) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Vflooder!pz (rule
Trojan:Win32/Vflooder!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Dump:Trojan.Agent.BYFH (rule
Dump:Trojan.Agent.BYFH) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Agent-FEU!83C10D2F540B (rule
Agent-FEU!83C10D2F540B) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Agent.iftf (rule
Trojan.Win32.Agent.iftf) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s) across 1 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 1 external host(s) and 14 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- YARA: Yara-Rules community flagged YR_Packer_VMProtect (rule
YR_Packer_VMProtect) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:MPRESS (rule
DIE:MPRESS) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged Themida/VMProtect (rule
Themida/VMProtect) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: Themida/VMProtect, MPRESS - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
84660 behavior events · 2 ATT&CK techniques · 9 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- google.com
- c.pki.goog
- www.virustotal.com
- a6281279.yolox.net
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- licensing.mp.microsoft.com
- assets.msn.com
- www.bing.com
- th.bing.com
Dropped files
- C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05DDC6AA91765AACACDB0A5F96DF8199 -
a6f8f5d4ffd1e825ffce9a55861f16aa4dbe67871b1696b976194dd8be1fdf29 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75A092F4522006A97542D6AC4F4E69D2 -
484a79505b41d51272a731d2e2db438d4f6659c93c4bfc47bea2a147f8edb3f1 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA -
9b0031e00cb94f52d01d71c62053c3e657be2f0e2ea7aff32aa56bed5c296fd4 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75A092F4522006A97542D6AC4F4E69D2 -
a159864b9bdb74dc61636bda6b8f822debc8c9eb9023f8bd1ac91db2519f6525 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA -
716f71b3eb77573f61f4557e9ca27a4ad4c153adbcbc929a86558ca73afb0d9a - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\71D3A36027B1506445FB345FD67207AC -
5378ed5d8b2008e5a542d61b163a3419b8895338f2264badc34f4888921adba2 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05DDC6AA91765AACACDB0A5F96DF8199 -
43ebcdeaf0e3cf79024702c38f9c090462f00db95a3b906e0649ba9137c3c5c4 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\71D3A36027B1506445FB345FD67207AC -
110fe0e32dd36370ff247b8b6d94fde5630db91e3f550485018525d0a9ce6113 - e1604779168c7d4d4641bea6d657f10337bdd08d35c88866b3a2083d5929dce8 -
e1604779168c7d4d4641bea6d657f10337bdd08d35c88866b3a2083d5929dce8
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://google.com/
- http://c.pki.goog/r/r1.crl
- http://c.pki.goog/wr2/oBFYYahzgVI.crl
- http://www.virustotal.com/vtapi/v2/file/scan
- http://c.pki.goog/wr3/MbJBMFoQ-sk.crl
Embedded domains
- www.virustotal.com
- a6281279.yolox.net
Embedded IP addresses
- 52.168.112.66
- 52.253.84.76
- 4.230.171.124
- 104.18.33.89
- 34.54.88.138
- 57.155.101.212
- 52.110.12.55
More Vflooder samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report