MALICIOUS — e0bbaac03759d989440c660cfad14e20da3be4546a08a29039f7a7df8d04fa36
MALICIOUS — e0bbaac03759d989440c660cfad14e20da3be4546a08a29039f7a7df8d04fa36 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the DCOM family. 8 of 56 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
e0bbaac03759d989440c660cfad14e20da3be4546a08a29039f7a7df8d04fa36 - SHA-1:
c1f198e5426f52a2d7b9bdb473cef8d560fb7d1a - MD5:
25474fb0273113036b0ce80b263ded48 - imphash:
c4998075f1324ce0f644f12a548d76b1 - ssdeep:
3072:B7puEEMoTEqTY9VfrW7pbrGcMS3eNdeYEBLIDlAtUFCyfSHBW1j0tGSFtcFnip4z:ppMM8EV1Gp6FULI0PHBWN0tNcl4rTHG - TLSH:
T102455ADC5A1ABB41E5F6D6201C245E9C5063F4EE227E3A8E89C3813E76E6437983405F - Submitted as: e0bbaac03759d989440c660cfad14e20da3be4546a08a29039f7a7df8d04fa36
- File type: pe · Size: 271578 bytes
- Verdict: malicious (100/100) · Family: DCOM
Detections (8 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:ÒuÛëÔ
- ClamAV (daily): Win.Exploit.DCOM-5
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Exploit:Win32/RpcDcom!pz
- Emsisoft (Emergency Kit): Trojan.Agent.FRPG
- Trellix Stinger (McAfee): Agent-FQX!25474FB02731
- Kaspersky (KVRT): Virus.Win32.Lamer.kp
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 17 weighted signals:
- ClamAV (daily) flagged Win.Exploit.DCOM-5 (rule
Win.Exploit.DCOM-5) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Exploit:Win32/RpcDcom!pz (rule
Exploit:Win32/RpcDcom!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Agent.FRPG (rule
Trojan.Agent.FRPG) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Agent-FQX!25474FB02731 (rule
Agent-FQX!25474FB02731) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.Lamer.kp (rule
Virus.Win32.Lamer.kp) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 3 external host(s) and 10 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-sections:ÒuÛëÔ (rule
high-entropy-sections:ÒuÛëÔ) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: 212.33.237.86 - static signal, weight 0.35, confidence 0.60
- 1 behavioral detection(s) across 1 rule(s): Discovery: enumerates installed security software [low] (rule
tl-security-software-discovery) - dynamic signal, weight 0.20, confidence 0.90 - Packing/obfuscation: high-entropy-sections:ÒuÛëÔ - static signal, weight 0.25, confidence 0.55
- Dropped 30 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
37602 behavior events · 1 ATT&CK techniques · 49 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- edge-consumer-static.azureedge.net
- clients2.googleusercontent.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- th.bing.com
- go.microsoft.com
Dropped files
- bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 -
bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 - C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe- -
0740fa7f9a8a72fb31d562463da9546ec678fc3e2ef40769f87b082892382fba - C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe- -
3e6ebdbdb169ee682a5c4d5a9bc8d398609498bbce1359c7961f42801689acfd - C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe- -
59cc670a6d508998fef3f085e2249490fbcff214e048fb0466ef24b090200af1 - C:\Program Files\Adobe\Acrobat DC\Acrobat\Adobe Crash Processor.exe- -
c0cb3b71ef8d2dd339b4605fb59ba12fa4129c7de69050699da639632b88ccb1 - C:\Program Files\7-Zip\7zFM.exe- -
a4f461241b79b9df027dc1fc66042556dc9e30c3e8d4306e81b4ace2534f1f61 - C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe -
1d525ddead9a369126a96856b90d10fb43992029d2c558636c1d63fd4f38cd7c - C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe- -
a2f644123ed606fa9f816d2f60789fe255f4d1d39304189e5c35a8b26caed530 - C:\Program Files\7-Zip\Uninstall.exe -
044beb751cd38b1ab606fb1cf9cc538772c7a2734a30b77d2387cd20cf99b757 - C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe -
79671bf6759f645dfeb021e3fcece87abe20b7c6be7ee7bf9c362603056a23ee - C:\Program Files\Adobe\Acrobat DC\Acrobat- -
7075f985ed341332be2e33e2abcfe9d5c098c28b64e52c231f30a3c26211ce95 - C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe -
7ab807b2f85d1de86a4ddbdc9efffe045c74d75668f9e7428999e863a062507b - C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe -
f22787287d068bf4e09ae95e1b53dba0e06dd0290a16a421e9060bd99172db79 - C:\Program Files\7-Zip\7zG.exe- -
1cc779a133aa32cf625e09f9e09172e8dfced68349003c28db45cdacf2b19d90 - C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe -
c82577476eb3c66d0e8e4e1c57c1cb88e453d988bd7cbc41abd5faa1449b30ca
Embedded URLs
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- crl.microsoft.com
- www.microsoft.com
Embedded IP addresses
- 212.33.237.86
- 20.42.73.27
- 52.230.59.222
- 52.123.252.225
- 4.230.171.124
- 172.64.154.167
- 13.70.178.62
- 20.11.121.11
- 135.234.160.244
- 52.148.114.188
- 52.110.12.42
- 52.110.12.3
- 72.154.7.110
File paths
- C:\Program
- C:\\Program
- C:\\DLLS\CorFlags.exe
- T:\:d:l:t:
- X:\:`:d:h:l:p:t:x:
More DCOM samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report