MALICIOUS — de1018bc56d7b25d6b06756a516bbdfe5f0f67ff412dac6e90ee3547e7e819ad
MALICIOUS — de1018bc56d7b25d6b06756a516bbdfe5f0f67ff412dac6e90ee3547e7e819ad is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the EB3081BC family. 4 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
de1018bc56d7b25d6b06756a516bbdfe5f0f67ff412dac6e90ee3547e7e819ad - SHA-1:
61cc85109dc7f973511c12b4956afdc1fce23838 - MD5:
c069d36b7dbfc2f6b2513ec2e8981030 - imphash:
62ec3dce1eba1b68f6a4511bb09f8c2c - ssdeep:
1536:kHW0m1G5rhTKyQU/Jqzku4jX94gYZ3TqCl6RF0y2LV7:omwVVxyku4jX94gYnl4e/V7 - TLSH:
T1963429E7AA261BF9DCE29305D01C7B5DC5F12031EFB41258715668C2DB0F6ABE0C6289 - Submitted as: de1018bc56d7b25d6b06756a516bbdfe5f0f67ff412dac6e90ee3547e7e819ad
- File type: pe · Size: 56320 bytes
- Verdict: malicious (99/100) · Family: EB3081BC
Detections (4 of 56 engines)
- ClamAV (daily): Win.Trojan.Crypted-29
- Microsoft Defender: Backdoor:Win32/Berbew.AA!MTB
- Emsisoft (Emergency Kit): Generic.Dacic.1.Backdoor.Hangup.A.EB3081BC
- Kaspersky (KVRT): Trojan-Proxy.Win32.Qukart.vih
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypted-29 (rule
Win.Trojan.Crypted-29) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Backdoor:Win32/Berbew.AA!MTB (rule
Backdoor:Win32/Berbew.AA!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Generic.Dacic.1.Backdoor.Hangup.A.EB3081BC (rule
Generic.Dacic.1.Backdoor.Hangup.A.EB3081BC) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-Proxy.Win32.Qukart.vih (rule
Trojan-Proxy.Win32.Qukart.vih) - engine signal, weight 0.55, confidence 0.85 - Contacted 1 external host(s) and 19 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Dropped 112 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
3645 behavior events · 1 ATT&CK techniques · 112 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- settings-win.data.microsoft.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
Dropped files
- C:\Windows\System32\Fiphmneo.exe -
f960cd3a9da76b3c7e788a1a6b3d5d2122fbe0cdfe4799a42503386ad31502c6 - C:\Windows\System32\Mepdjooe.dll -
e1486160ccc8a584ec660c89918ccc2456721f3471c29af214e7da17037c853d - C:\Windows\System32\Hhfmel32.exe -
d36f5903e352d3db4a8997b2455ab7d028f7e6ed2fa5350d5089c1e1058ff651 - C:\Windows\System32\Bfcmho32.dll -
5a3dbe3b35e066ae75d900e4f14a7738ce4da6ede8ad698c5f5796bf096a3860 - C:\Windows\System32\Pclina32.dll -
8f106be6652759109ae77eaf69283121ec25db3793fcd345a1de3939f059ee81 - C:\Windows\System32\Hoeack32.dll -
234d5be73c6ff9177ba1c35d6aa47c0768aadf8ae4f5d211a96e7c2e3a51a5e9 - C:\Windows\System32\Lfppba32.exe -
225da79c967da4c152d765f0196c851c74b66dbbce3d9418ed51e50cba2da48c - C:\Windows\System32\Cidclpno.dll -
c6afc0ac69b15b2ead3e786d1f7275adbe68ee1e198f9203568fc777b58ed220 - C:\Windows\System32\Odlqbg32.dll -
a4bee715c7fb6a71a9e0eccd3c5b1fdc01f0396d53a3b32e0f9452a641d2c838 - C:\Windows\System32\Kdpilocd.dll -
073d661132afd634f634c85389672c33c5f16c7f1fe29fe60f775969a16b756f - C:\Windows\System32\Laqdjedg.exe -
b9fdc2203585772e894668996e22b8e4f39721975750ced4446235983e1ee175 - C:\Windows\System32\Lcenpakf.exe -
411eb172c860f85a436ca1ba55ed6b942fe1b099d653ca23501f5d21d70d71b0 - C:\Windows\System32\Bphnfice.dll -
7a3ea9f867b97e699c58a08560d8e6ae1d708beed6e7bbe8de4d0ef4bbfacdb5 - C:\Windows\System32\Fagikd32.dll -
089819a54dbc8a17f8ce3516dcf1f229b077f83cb753dd371e0f3130288ef9cf - C:\Windows\System32\Ochjhgpn.dll -
2eae593e048bf2025f170622ceb8b211368d73c861c6e8881877bd3470f52cb9
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 172.215.188.232
- 20.89.1.13
- 20.247.185.124
- 4.230.171.124
- 20.42.179.204
- 74.178.76.128
- 4.150.223.112
- 135.232.92.97
- 104.18.33.89
- 125.56.205.56
- 125.56.205.42
- 125.56.205.17
- 52.148.114.188
- 172.178.240.163
- 72.153.5.141
- 52.110.12.11
- 52.110.12.19
More EB3081BC samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report