MALICIOUS — dbe6eb8fa069c3edcea4a87b1193539b111da5c8c918e49ffe78a240a722682a
MALICIOUS — dbe6eb8fa069c3edcea4a87b1193539b111da5c8c918e49ffe78a240a722682a is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Mikey family. 11 of 56 detection engines flagged it, exhibiting 9 ATT&CK techniques.
Identification
- SHA-256:
dbe6eb8fa069c3edcea4a87b1193539b111da5c8c918e49ffe78a240a722682a - SHA-1:
63489e280b5aa04441a8de590b57ec7b18246035 - MD5:
f6df5f2ab7655820fabe9f5ef4dc5b0a - imphash:
2b817dc1b1849c6a436f0647be7673e0 - ssdeep:
196608:3HyHu9V2Lhixwhzav1yoX1CPwDv3uFZjeg2EeJUO9WLQETxtw3iFFrS6XOvTV73a:3SO92ixwZ6P1CPwDv3uFteg2EeJUO9WB - TLSH:
T1CD68CF981609B700DDE4DE00BD005EBEE297D8C270B50EDD6282D12FBAA6F67523645F - Submitted as: dbe6eb8fa069c3edcea4a87b1193539b111da5c8c918e49ffe78a240a722682a
- File type: pe · Size: 8151557 bytes
- Verdict: malicious (100/100) · Family: Mikey
Detections (11 of 56 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- capa (capabilities): capability:execution/powershell
- ClamAV (daily): Win.Malware.Mikey-9819889-0
- YARA: bartblaze: BB_Clipbanker
- YARA: ESET research: coruscant
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Backdoor:Win32/ParalaxRat!pz
- Emsisoft (Emergency Kit): Gen:Variant.Midie.107242
- Kaspersky (KVRT): Trojan.Win32.Agentb.jzwz
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 100/100 is the fusion of 26 weighted signals:
- ClamAV (daily) flagged Win.Malware.Mikey-9819889-0 (rule
Win.Malware.Mikey-9819889-0) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - YARA: bartblaze flagged BB_Clipbanker (rule
BB_Clipbanker) - engine signal, weight 0.70, confidence 0.70 - YARA: ESET research flagged coruscant (rule
coruscant) - engine signal, weight 0.70, confidence 0.70 - Microsoft Defender flagged Backdoor:Win32/ParalaxRat!pz (rule
Backdoor:Win32/ParalaxRat!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Midie.107242 (rule
Gen:Variant.Midie.107242) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Agentb.jzwz (rule
Trojan.Win32.Agentb.jzwz) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s) across 1 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 3 external host(s) and 17 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Extracted BitRAT config (0 C2) - engine signal, weight 0.45, confidence 0.60
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser built-in flagged Windows_Injection_Api_Combo (rule
Windows_Injection_Api_Combo) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.30, confidence 0.70 - Embedded network infrastructure: https://curl.haxx.se/docs/http-cookies.html, http://mingw-w64.sourceforge.net/, http://www.zlib.net/ - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Dropped 8 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60
Dynamic analysis (windows)
22289 behavior events · 2 ATT&CK techniques · 18 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- myexternalip.com
- yr.c.lencr.org
- yr1.c.lencr.org
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- odc.officeapps.live.com
- www.msn.com
- licensing.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\b86622ab\tor\libcrypto-1_1.dll -
0ebde7a876ee8eb1ed70872155592b2430ec8d15f26fa42e94528a4346601168 - C:\Users\analyst\AppData\Local\b86622ab\tor\torrc -
d4f01031fe4f429eb511dc849cb67e72af5c1b84a97f2cab03ae629b5c1bca95 - C:\Users\analyst\AppData\Local\b86622ab\tor\libwinpthread-1.dll -
92cfd0277c8781a15a0f17b7aee6cff69631b9606a001101631f04b3381efc4e - C:\Users\analyst\AppData\Local\b86622ab\tor\tigar.exe -
8c41b2118842ff1c03fc42daea341dde7f6a115576c9f6ae4c14a280b6153f84 - C:\Users\analyst\AppData\Local\b86622ab\tor\libssl-1_1.dll -
787291025ae5ade79a521a2bd32608cae32a3c2e8bb081b439ec42bccb8a4957 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\25E080C95D21A9ED83828D40CB493B9F -
d84345afb2dd3da699aefd0ce982098e7d57f4652e53e86f2f4195f96812b8a7 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751 -
3dd5ea8a14eb665ba6057d424f94e5e83757ffaab456578dbf038af04053b19e - C:\Users\analyst\AppData\Local\b86622ab\tor\zlib1.dll -
8688bd7ca55dcc0c23c429762776a0a43fe5b0332dfd5b79ef74e55d4bbc1183 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751 -
42dea0cc299f813ce761fc9682655e2ff5de5051c79d7934073923244dab789a - C:\Users\analyst\AppData\Local\b86622ab\tor\libssp-0.dll -
cbb5236d923d4f4baf2f0d2797c72a2cbae42ef7ac0acce786daf5fdc5b456e6 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F15827BEC5BABE89C21DCDAE77464BF1 -
108dd34232a3088b45534933d0486409616a2bbad94fd8f7ab5991c01ff179b6 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F15827BEC5BABE89C21DCDAE77464BF1 -
590e295555d0d0e6f43bd29bdc9c6eba18e3238e18d4de46f7f7dfe8c95b5ba8 - C:\Users\analyst\AppData\Local\b86622ab\tor\libgcc_s_sjlj-1.dll -
2922193133dabab5b82088d4e87484e2fac75e9e0c765dacaf22eb5f4f18b0c5 - C:\Users\analyst\AppData\Local\b86622ab\tor\libevent-2-1-6.dll -
b65f9aa0c7912af64bd9b05e9322e994339a11b0c8907e6a6166d7b814bda838 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\25E080C95D21A9ED83828D40CB493B9F -
54bfd7593f9ad45d476ed52afa1c3a5d25bc15efe035b8c95de44e0ce76d9489
Embedded URLs
- https://curl.haxx.se/docs/http-cookies.html
- https://www.openssl.org/
- http://mingw-w64.sourceforge.net/
- http://www.zlib.net/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://yr.c.lencr.org/
- http://yr1.c.lencr.org/113.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
Embedded domains
- curl.haxx.se
- example.com
- www.openssl.org
- mingw-w64.sourceforge.net
- www.zlib.net
- myexternalip.com
- x1.c.lencr.org
- yr.c.lencr.org
- yr1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
Embedded IP addresses
- 1.101.3.4
- 2.4.13.6
- 20.50.80.215
- 52.253.84.76
- 4.230.171.124
- 34.160.111.145
- 135.234.160.246
- 52.110.12.48
- 52.110.12.16
- 135.234.160.247
- 135.233.45.221
- 135.233.45.222
- 135.233.45.223
- 51.116.253.169
- 20.50.201.203
- 48.211.4.16
- 172.178.240.161
- 72.154.7.106
- 52.148.114.188
- 104.18.20.213
- 52.110.12.33
- 52.110.12.10
File paths
- A:\\X
More Mikey samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report