MALICIOUS — dfcf860125e34ba79237e0d226892b9cb6948315a24a9ae6dba810688ec69dfd
MALICIOUS — dfcf860125e34ba79237e0d226892b9cb6948315a24a9ae6dba810688ec69dfd is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Fileinfector family. 5 of 56 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
dfcf860125e34ba79237e0d226892b9cb6948315a24a9ae6dba810688ec69dfd - SHA-1:
f82be3c0e636e1eeb898b24a1c2b4af776545469 - MD5:
595fbafbf4668e379de60bce93c0562b - imphash:
895fbb56c02c3d2bca3125cef5da8730 - ssdeep:
384:GTe/OrHWVYbvN/uMmxDMmWrm2HB084SY+2lmg/YFgfJhFeS9+7Gx9QVmNYDkHrJ:ae2gM1ZmxDMmDwwR1fQRDl6dR - TLSH:
T1AE39EDCE561D6F21CB3DD9386A2CD8CE90A5F1E420B6732D0D119133582357BECB29A9 - Submitted as: dfcf860125e34ba79237e0d226892b9cb6948315a24a9ae6dba810688ec69dfd
- File type: pe · Size: 86016 bytes
- Verdict: malicious (100/100) · Family: Fileinfector
Detections (5 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Fileinfector-9832954-0
- Detect It Easy (packer/type): DIE:MinGW
- Microsoft Defender: Trojan:Win32/Vindor!pz
- Kaspersky (KVRT): Virus.Win32.Lamer.ks
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Win.Malware.Fileinfector-9832954-0 (rule
Win.Malware.Fileinfector-9832954-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Vindor!pz (rule
Trojan:Win32/Vindor!pz) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.Lamer.ks (rule
Virus.Win32.Lamer.ks) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 2 external host(s) and 6 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497, T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:MinGW (rule
DIE:MinGW) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1, MinGW - static signal, weight 0.25, confidence 0.55
- Dropped 23 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
44559 behavior events · 2 ATT&CK techniques · 38 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
- licensing.mp.microsoft.com
- www.bing.com
- fe3cr.delivery.mp.microsoft.com
- v10.events.data.microsoft.com
Dropped files
- C:\Windows\lsasetup.log -
f0f814ebcb3f5db5898f6adb6b225e339bedc5237f4700919bd4a4f031c0db2c - C:\Windows\System32\vulkan-1.dll -
a31e1063d6827a70f420b587d50760cdfcd2c18f44f565506f0b3b820b451bbb - C:\Windows\System32\vcomp140.dll -
b8ce2af43c02067be6334c9cefd2edd4a9f697ea09dbd6daa78b8b73562a9ced - C:\Windows\DtcInstall.log -
093cedecd08d5ccb0b4361f62d83516b28703fee4e985502c383afd41e753f13 - C:\Windows\System32\vcruntime140_threads.dll -
ffae6688df161b10ad472ad7535e3b1894d3bae09b4a81bcc2f1bb8699eeb12c - C:\Windows\System32\vccorlib140.dll -
1848830a5ba75f028e54869d272391d9d4ac34c2ab060582ad4d338183710fc6 - C:\Windows\Professional.xml -
4d35bafee23ca3fdf9df1818d8df0e902a9d2bc89a6f314480d7509cdcc33ddd - C:\Windows\setuperr.log -
6202edd873a1f5df3d7487a731001d5cdb370bb831ac920d7364ca96588a7d10 - C:\Windows\System32\vcruntime140.dll -
2bfdcefc3c171e9ddbd7a3b5e3a34cf7b10e8232a7664fe199adf79be86e3f15 - C:\Windows\System32\dssec.dat -
93969025208a983d73639a4ccf91ba5947d0449ff27939b0dbccbc4744ff63ad - C:\Windows\System32\msvcp140_2.dll -
fe671eeae257cff851a84ba16e1008b7901c55f1ffbd5417aae1f5bc426589b2 - C:\Windows\System32\msvcp140_codecvt_ids.dll -
b3fc76d63e7699dc4b8bdf6642a2f030334037ea811c4e743a3460c69695302c - C:\exc.exe -
0217a33df3ca2fe602100c2182bd67e7328840ba895cb1ea0f32562ab5e84719 - C:\Windows\System32\opencl.dll -
38a6364c3fbec503b3617cbb41669e876ee9d2553ceea38fe008c9e9bd8dd54c - C:\Windows\PFRO.log -
2af2eaf03312361ca53c0657fba1d0036c0068d0c1b2909c2aaf8d5b4b17c9cd
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 20.42.73.25
- 4.230.171.124
- 20.42.179.204
- 20.247.185.124
- 57.154.63.210
- 74.178.240.51
- 4.150.223.102
- 135.233.95.144
- 74.179.77.204
- 52.110.12.33
- 52.110.12.18
- 13.89.179.12
- 20.42.73.28
- 135.234.160.245
- 72.153.5.136
- 92.223.78.30
- 52.148.114.188
- 52.110.12.25
- 52.110.12.51
More Fileinfector samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report