MALICIOUS — e2b36927d6a60a0cb48ac6c6c48765d84ba857b01b4d6dadb0c8d1e3a192451a
MALICIOUS — e2b36927d6a60a0cb48ac6c6c48765d84ba857b01b4d6dadb0c8d1e3a192451a is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Conti family. 3 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
e2b36927d6a60a0cb48ac6c6c48765d84ba857b01b4d6dadb0c8d1e3a192451a - SHA-1:
d512f7974aeb053f879e734c973c16bf9535d019 - MD5:
eb930c6d291047962ef2c55e3800c8d7 - imphash:
662e16ab4544980676deddbb348b6c35 - ssdeep:
6144:4A0HKAh9NhgdfSEbKi2pPm3p/0i8qNN51PYR3Iemad5Epb61aoQtkU+DLjnE:4JKkbhgdfS+KigO3p6Y1W3BSdtk5vjE - TLSH:
T1FE5CF87E5C5B160DC1CC3813CA27A7CED6A8445314780948D24AEDBBB6CB6376F4A9C8 - Submitted as: e2b36927d6a60a0cb48ac6c6c48765d84ba857b01b4d6dadb0c8d1e3a192451a
- File type: pe · Size: 2515216 bytes
- Verdict: malicious (97/100) · Family: Conti
Detections (3 of 56 engines)
- LIEF (executable format parser): lief:invalid-authenticode
- Emsisoft (Emergency Kit): Gen:Variant.Jaik.49267
- Kaspersky (KVRT): UDS:Trojan-Ransom.Win32.SuspFile
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 9 weighted signals:
- Emsisoft (Emergency Kit) flagged Gen:Variant.Jaik.49267 (rule
Gen:Variant.Jaik.49267) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:Trojan-Ransom.Win32.SuspFile (rule
UDS:Trojan-Ransom.Win32.SuspFile) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 17 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Extracted Conti config (0 C2) - engine signal, weight 0.45, confidence 0.60
- LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://sv.symcb.com/sv.crl0a, https://d.symcb.com/rpa0, http://sv.symcb.com/sv.crt0 - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
45767 behavior events · 2 ATT&CK techniques · 33 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- officeclient.microsoft.com
- www.msn.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
Dropped files
- c:\cape\bootstrap.log.gtyeg -
7e618e346b46a4ddf0b209028c346249775cf951a024cf805be2de43d108388b - c:\program files\7-zip\7zcon.sfx.gtyeg -
47ff5d393b9e107b4b51005fa243932e79d2c5f9e3d4a8dfacd59259f23f2705 - c:\$winreagent\rollback.xml.gtyeg -
bf91d934f541e2687f1c1881312b950bba25a6db751ba1e5ffb3ab8dbc7a217b - c:\program files\7-zip\history.txt.gtyeg -
8cd1b6e4c1b6b6c3df9694b58de84018d4d287a51cc5b7530394cc5cf88a644b - c:\cape\cape-bootstrap.ps1.gtyeg -
ecca252a9722307b875a94c2d120ae1fbec7c3ef668b40064518880dec23f8fd - c:\python3\license.txt.gtyeg -
498a1c733d348de7bcc00ce57a3edb8a8d1fd7d232a613ac1c4004f4dfa63547 - C:\ProgramData\regid.1991-06.com.microsoft\readme.txt -
4e3e79bf909f48c98b87543b6166711e28207833b30f7bdb3379923a0f704656 - c:\p.ps1.gtyeg -
3a68c3663b0ef7f8ebd47d525b16cc8c95c503da8ce72584795f228b832a434e - c:\threatlens\bake.log.gtyeg -
f57144af455fd303a9138821a306deb1c2b7eaac598248165c165dff5a958dc2 - c:\program files\libreoffice\credits.fodt.gtyeg -
5407621185615e19f666aa4edf08188b90aa18b02d3a2846f62a35ee5776ef07 - c:\scoobe-fix.cmd.gtyeg -
e6a6a67979d24aed8526ca039d9e88c105c4234258c2e953a569a0378513ec92 - c:\office-config.ps1.gtyeg -
dd9c3680b86eed5cac50c21989323b56ce9b54422527d673cc163f31a834b42b - c:\cape\agent.py.gtyeg -
568f7f622edfd5f12fb56d677422b1ce0c26825df6cc77155bb67602ac6d9795 - c:\recovery\reagentold.xml.gtyeg -
e6ec509faa9e14a8b32a2e7e69e01789a2fc76a7cd392a979c672074d2ed4b42 - c:\$winreagent\backup\boot.sdi.gtyeg -
6315ebab6817e322fe94f3a1c68713fef8198367b221173d23f6ca953c6662db
Embedded URLs
- http://crl.thawte.com/ThawteTimestampingCA.crl0
- http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
- http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
- http://sv.symcb.com/sv.crl0a
- https://d.symcb.com/rpa0
- http://sv.symcb.com/sv.crt0
- http://www.symauth.com/cps0
- http://www.symauth.com/rpa00
- http://s1.symcb.com/pca3-g5.crl0
- http://s.symcb.com/universal-root.crl0
- https://d.symcb.com/rpa0@
- http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
- http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- crl.thawte.com
- ts-aia.ws.symantec.com
- ts-crl.ws.symantec.com
- sv.symcb.com
- d.symcb.com
- www.symauth.com
- s1.symcb.com
- s.symcb.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 13.69.109.130
- 52.253.84.76
- 52.123.252.244
- 4.230.171.124
- 40.84.85.40
- 162.159.142.9
- 172.178.240.161
- 40.84.97.4
- 184.84.165.171
- 52.110.12.53
- 52.110.12.46
- 72.154.7.106
- 52.148.114.188
- 172.178.240.163
- 52.110.12.21
More Conti samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report