MALICIOUS — db8d92ae473e42321a225a3d99c896ef6f727d3dded063d452f2c1650808f224
MALICIOUS — db8d92ae473e42321a225a3d99c896ef6f727d3dded063d452f2c1650808f224 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Crypted family. 5 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
db8d92ae473e42321a225a3d99c896ef6f727d3dded063d452f2c1650808f224 - SHA-1:
f2aea5598da94576afbf1130d53a1a12aeb83aa7 - MD5:
c6943559a683f5cd0cd9c3f4afc04c79 - imphash:
62ec3dce1eba1b68f6a4511bb09f8c2c - ssdeep:
1536:7pyjEhkQxxuVFjXGBceInft8x2LE/DUJWiUboFkj/t/M8PtJF+OF2LP:7GEyZZRUDWwbj1rVJEP - TLSH:
T1253C4A76BAD51911DEE19699710FB84EE0E12A302EF016640B5F68A768064C7B4FC0FF - Submitted as: db8d92ae473e42321a225a3d99c896ef6f727d3dded063d452f2c1650808f224
- File type: pe · Size: 112640 bytes
- Verdict: malicious (92/100) · Family: Crypted
Detections (5 of 55 engines)
- ClamAV (daily): Win.Trojan.Crypted-31
- Microsoft Defender: Backdoor:Win32/Berbew.AA!MTB
- Emsisoft (Emergency Kit): GenPack:Generic.Dacic.1.Backdoor.Hangup.A.004BF035
- Trellix Stinger (McAfee): Trojan-FUGH!C6943559A683
- Kaspersky (KVRT): Trojan-Proxy.Win32.Qukart.vih
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypted-31 (rule
Win.Trojan.Crypted-31) - engine signal, weight 0.90, confidence 0.95 - Contacted 24 external host(s) at runtime (23 HTTP) - network signal, weight 0.40, confidence 0.80
- Dropped 90 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
2870 behavior events · 1 ATT&CK techniques · 90 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Dropped files
- C:\Windows\System32\Dieeel32.exe -
9a5f0ba5a888f20d0e254adb411d95a58f7418f3371f94bc1426c53a4d4617cf - C:\Windows\System32\Emeqcaop.dll -
3297d367710dd5c9ee358a210a15c91515fee20e613c662e2d5792e0f9c5bf71 - C:\Windows\System32\Cdgnojoo.dll -
fa5366135e7cdc9ee66ea3d37a4e14f459085f5da555af97b89f2718c27670b5 - C:\Windows\System32\Kdhmnccp.dll -
4414bda20c4f608b4267d5033d4ac9009e24333482e182603f5a50e4607aa539 - C:\Windows\System32\Jinbji32.dll -
5ba24187120f74b8b1d485668c47b2ba5db55f2a21e183039dde9a4433e3aae7 - C:\Windows\System32\Gaenen32.dll -
498933544b82ac29e3501bbd8374fa6cdebe04e8645c44629840bd82b59b185a - C:\Windows\System32\Iglnli32.dll -
a771698f26c60ec38da9e4c9768daad936b2cac8cd4db7dcb891b538b38baa3d - C:\Windows\System32\Bncakq32.exe -
564995af7e8fb9de9ccf90746f926cb60a1684c34918f575a80f1bf426739368 - C:\Windows\System32\Laigopfd.exe -
5223e0a4a5b731d7a16eda637a2d8272fa70ae2f5cd46ef087831ba808bba2ff - C:\Windows\System32\Lccgqa32.dll -
05aa48353d582c0ef0cece91ab7eb637d6b44dbee800ac848fa7e15b39b24ba3 - C:\Windows\System32\Iqaejhmm.dll -
e00c2b130bfa23bddfdd7c7c87d1b7634baa39af01790cee4b647ef50d0c86b2 - C:\Windows\System32\Ldacid32.dll -
a85f1c3b9b489fc8ec712ffa9608a29fc09cbd7c02bca2a0a6751cf1c38911b2 - C:\Windows\System32\Mpjdljan.exe -
f0b6bb0abc919c4c8a65cd4bd8f180e58424b81a4882e4b19a6e27b91c406b69 - C:\Windows\System32\Lciifd32.exe -
2c7ae7b67de005a15be0986abdceb5933bcb3b9bb4aae4dc68453fbebf854054 - C:\Windows\System32\Kajpgpfi.dll -
4215ce0ca8533a7fa5dbd91f6db8a1b4e35af72475b793268d3e256b38fe30d8
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787803558&P2=404&P3=2&P4=R5SFPpkiAw69h8CqYD4DD68xCz%2f8qZ9iyU4QkWAEbZPc1Rukl65qjDI24QFfTOYs2OIkHhnStThgUks8938KXQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787803616&P2=404&P3=2&P4=f2bDbG%2bhZP9mXD1n%2fu32rVkiDDNI9xvvcgpxy3xxEYkJh5H%2bDk18Wm8mYDE0MODNs4MshxNrMRkKN7VwpGI08A%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- 2.me
Embedded IP addresses
- 20.42.65.89
- 52.123.252.245
- 40.84.97.4
- 4.230.171.124
- 52.253.84.76
- 135.233.95.144
- 20.184.175.8
- 135.232.92.97
- 92.223.78.30
- 20.236.44.162
- 52.123.128.14
- 52.123.129.14
- 52.123.252.240
- 20.184.175.12
- 135.234.160.244
- 203.26.79.13
- 135.232.92.34
- 52.123.252.202
- 52.148.114.188
- 172.215.188.232
- 72.145.35.105
- 135.234.160.246
- 52.110.12.49
- 52.110.12.31
More Crypted samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report