MALICIOUS — e44efea3c94a2b21450af9c9593b0c889f75aafca54314f5f1191b9801b61231
MALICIOUS — e44efea3c94a2b21450af9c9593b0c889f75aafca54314f5f1191b9801b61231 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the DelfInject family. 5 of 55 detection engines flagged it.
Identification
- SHA-256:
e44efea3c94a2b21450af9c9593b0c889f75aafca54314f5f1191b9801b61231 - SHA-1:
e02fe90180710b748d55cefae191d0dc672b3877 - MD5:
06a3b278dcce87aded55ebbce8bc74a6 - imphash:
0af56bf70c7b81394871a4713f3cc30b - ssdeep:
24576:0GOB1BaxiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiQ:07ByiiiiiiiiiiiiiiiiiiiiiiiiiiiQ - TLSH:
T1C4539D9E263A3646E172A91A14274A4C1C32B4D4CB3B3F494D63C23B3970C5BD8D56EA - Submitted as: e44efea3c94a2b21450af9c9593b0c889f75aafca54314f5f1191b9801b61231
- File type: pe · Size: 1048576 bytes
- Verdict: malicious (91/100) · Family: DelfInject
Detections (5 of 55 engines)
- ClamAV (daily): Win.Malware.Generic-9899488-0
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Trojan:Win32/DelfInject.SS!MTB
- Emsisoft (Emergency Kit): Trojan.GenericKDZ.78423
- Trellix Stinger (McAfee): Packed-GDT!06A3B278DCCE
Why this verdict
The malicious score of 91/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Malware.Generic-9899488-0 (rule
Win.Malware.Generic-9899488-0) - engine signal, weight 0.90, confidence 0.95 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 25.3.12.21, 25.8.20.17 - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 25.3.12.21
- 25.8.20.17
- 20.42.65.94
- 52.123.252.213
- 4.247.188.233
- 4.230.171.124
- 20.247.185.124
- 74.178.240.61
- 20.42.73.27
- 74.178.240.51
- 20.112.250.133
- 52.123.129.14
- 52.123.128.14
- 20.184.175.7
- 52.148.114.188
- 52.110.12.22
- 52.110.12.40
File paths
- f:\dd\vctools\crt_bld\self_x86\crt\src\output.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\_file.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\input.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\mbctype.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\tidtable.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\_sftbuf.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\ioinit.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\stdenvp.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\stdargv.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\w_env.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\onexit.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\mlock.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\_getbuf.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\read.c
- C:\xugaravobin\jolixakipof
- f:\dd\vctools\crt_bld\self_x86\crt\src\sprintf.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\scanf.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\strtol.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\fprintf.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\winsig.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\crt0msg.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\_flsbuf.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\vsprintf.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\isctype.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\localref.c
More DelfInject samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report