MALICIOUS — e2d7f0197ac18d51007b47a0e97d5d31c77024effa3bc532b7f6402c153361ee
MALICIOUS — e2d7f0197ac18d51007b47a0e97d5d31c77024effa3bc532b7f6402c153361ee is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Picsys family. 6 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
e2d7f0197ac18d51007b47a0e97d5d31c77024effa3bc532b7f6402c153361ee - SHA-1:
7ab6dd3b4f8195bb384c1a79ba537efad3bfe7cc - MD5:
1a07e1505c6d138c6b08bd3e8d6414ec - imphash:
359d89624a26d1e756c3e9d6782d6eb0 - ssdeep:
1536:y4QQ6NSyM61l19piO+LV8YEoI/EU9RUe4mcY9OAvzZxjCgNkYW:y4X6NSyfnpijeYEoIcq4I9OizZlCgNo - TLSH:
T1C5370289B180786CCCAFEDC52CB6867D1492521E22FF3F8D15887039452E087ECA87D9 - Submitted as: e2d7f0197ac18d51007b47a0e97d5d31c77024effa3bc532b7f6402c153361ee
- File type: pe · Size: 74207 bytes
- Verdict: malicious (100/100) · Family: Picsys
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Worm.Picsys-6804101-0
- Detect It Easy (packer/type): DIE:Turbo Linker
- Microsoft Defender: Worm:Win32/Yoof!pz
- Trellix Stinger (McAfee): W32/Picsys.worm!B80D9CF0C706
- Kaspersky (KVRT): P2P-Worm.Win32.Picsys.b
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Worm.Picsys-6804101-0 (rule
Win.Worm.Picsys-6804101-0) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s) across 1 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged Worm:Win32/Yoof!pz (rule
Worm:Win32/Yoof!pz) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged W32/Picsys.worm!B80D9CF0C706 (rule
W32/Picsys.worm!B80D9CF0C706) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged P2P-Worm.Win32.Picsys.b (rule
P2P-Worm.Win32.Picsys.b) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 3 external host(s) and 21 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 a#¤, Turbo Linker - static signal, weight 0.25, confidence 0.55
- Dropped 24 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
134 behavior events · 1 ATT&CK techniques · 27 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- v7x3a5l9.hypermart.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- windows.msn.com
- www.msn.com
- www.bing.com
Dropped files
- C:\Windows\System32\macromd\illgal incest preteen porn cum.mpg.exe -
6ed577e9ed82fb94ca3ea76fe0c83d457099f68b03a293bd0037c7d1dd85f0da - C:\Windows\System32\macromd\Britney Spears Dance Beat.exe -
8f9fc06c240fda077d3b8463c6ea8cba3ef790a21d413a7903f0c1b227888fc2 - C:\Windows\System32\macromd\invisible IP.exe -
7ff2b91488b21a3e218f8f5840a1cc09d0d3b07ebb3578313bb541f435f42d73 - C:\Windows\System32\macromd\fetish bondage preteen porno.mpg.pif -
8cb98da8578bd7e4c74c20baf9d117c8f8b9a6936d3125301af19f1971f05750 - C:\Windows\System32\macromd\divx pro.exe -
b0e3ba72550280e4f0e2cf6d87aad03f408847e5f8446e6d95ec1cd9f87633cc - C:\Windows\System32\macromd\DivX pro key generator.exe -
72da0c4b9e8633831662bcfec0d2873666d83612287ca854f550206f287aea00 - C:\Windows\System32\macromd\16 year old webcam.mpg.exe -
17ce96218cd8fcd02410c1162c3243dea5034434d9813f00b9c56b2c0dcef1e8 - C:\Windows\System32\macromd\Counter Strike CD Keygen.exe -
74e65fb1d5888641713902bf6c2bb0298801f1da18fcb57286416027bf5fc786 - C:\Windows\System32\macromd\GTA 3 Crack.exe -
8434237e480c45953401338fb5611014ea9538f0cac75ea7c2f17005629c40e8 - C:\Windows\System32\macromd\Universal Game Crack.exe -
32271c01d48632f4a75e926a9428c555d8f943750642966878034bb4f2cce457 - C:\Windows\System32\macromd\illegal porno - 15 year old raped by two men on boat.mpg.pif -
bfea2acd75513c9df9c85c63d9e3ecc18f0b034d2d1bb6e344708267a8ee7801 - C:\Windows\System32\macromd\GTA 3 Serial.exe -
70846d81680c76a48ceecb4d6a393202845bb1e6e5cd6fca0983511f39ec771f - C:\Windows\System32\macromd\cute girl giving head.exe -
54ca7935063c2400681a0b7e8f056b8e265c423aad2668e49a906a8a8a71d663 - C:\Windows\System32\macromd\AOL, MSN, Yahoo mail password stealer.exe -
8145984a102f945ef616e505eb5465391b476d107e6f46972bb34e6d2be22d57 - C:\Windows\System32\macromd\crack.exe -
d76138fba6b9c151b84691c68942a15bcdd2134cb34aff367a6414623f8e0215
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- http://v7x3a5l9.hypermart.net/cgi-bin/w.cgi?192.168.122.109A2356B8214C8113D14007753E3F0
Embedded domains
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- v7x3a5l9.hypermart.net
Embedded IP addresses
- 52.168.112.67
- 52.123.252.229
- 74.178.76.128
- 4.150.223.114
- 135.233.95.135
- 104.18.33.89
- 52.168.112.66
- 4.230.171.124
- 20.42.179.192
- 20.247.185.124
- 52.110.12.30
- 52.110.12.15
- 20.42.65.91
- 52.178.17.235
- 38.113.1.151
- 57.154.63.210
- 172.172.255.216
- 4.150.223.98
- 72.145.35.96
- 52.148.114.188
- 52.110.12.48
- 52.110.12.46
More Picsys samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report