MALICIOUS — e90ebab1189bde368929f30615cfa89958263e3a96216e9ea355651ae5eb844d
MALICIOUS — e90ebab1189bde368929f30615cfa89958263e3a96216e9ea355651ae5eb844d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Mintluks family. 5 of 56 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
e90ebab1189bde368929f30615cfa89958263e3a96216e9ea355651ae5eb844d - SHA-1:
c216eeca524a5a2e93f4dd1c2723fc3bc3eac12b - MD5:
05d9c6743b357fffc95d4fdd15cb2904 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
1536:UPWV5jELT8hn2Ep7WzPdVj6Ju8B3AZ242UdIAkD4x3HT4hPVoYdVQtS6t9/31L8:UPWV5jSE2EwR4uY41HyvY19/q - TLSH:
T15638BF69FDBF9E70E97EEC6974C4D13D825270D1A9EE23081B4044212874E673CA629F - Submitted as: e90ebab1189bde368929f30615cfa89958263e3a96216e9ea355651ae5eb844d
- File type: pe · Size: 80384 bytes
- Verdict: malicious (100/100) · Family: Mintluks
Detections (5 of 56 engines)
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): Win.Malware.Avlj-9877624-0
- Microsoft Defender: PWS:MSIL/Mintluks!pz
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 16 weighted signals:
- ClamAV (daily) flagged Win.Malware.Avlj-9877624-0 (rule
Win.Malware.Avlj-9877624-0) - engine signal, weight 0.90, confidence 0.95 - 2 behavioral detection(s) across 2 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.63, confidence 0.90 - Microsoft Defender flagged PWS:MSIL/Mintluks!pz (rule
PWS:MSIL/Mintluks!pz) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win32.Generic (rule
HEUR:Trojan.Win32.Generic) - engine signal, weight 0.55, confidence 0.85 - 2 IDS alert(s): ThreatLens no-ip dynamic DNS C2 - network signal, weight 0.50, confidence 0.80
- Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Contacted 1 external host(s) and 8 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-sections:.text (rule
high-entropy-sections:.text) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
- Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
24600 behavior events · 3 ATT&CK techniques · 28 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- bejnz.com
- rwkeith.no-ip.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- officeclient.microsoft.com
- www.msn.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- assets.msn.com
- www.bing.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\7tmey8uc.0.vb -
daa1aaef1615d3d7c9f8dc572ed8f3966a725929adbaf6ab4d6246cd0b2a85c0 - C:\Users\analyst\AppData\Local\Temp\zCom.resources -
69db906941dec2a7f1748ea1d15a058751c77d851ce54ea9e2ebdf1d6c7ed4f4 - C:\Users\analyst\AppData\Local\Temp\7tmey8uc.out -
09aedafd5e72635be75e09613337cab213e5d05b3a9f072379bd373fc8c2603f - C:\Users\analyst\AppData\Local\Temp\RES120C.tmp -
3cbbb766e9965afc99fb3478c0df121051c5b6ef17e0dbcfc0c99cb891ef2c7b - C:\Users\analyst\AppData\Local\Temp\7tmey8uc.cmdline -
3ca53cd548c7c1e903df25faf043b3d7964f3a984d19c28976d01bb1795dff05 - C:\Users\analyst\AppData\Local\Temp\tmpE80E.tmp.exe -
13d24f177ddd92eeba85326a635c06fd6f47a3a12a70e4af72f7ca77f7f37688 - C:\Users\analyst\AppData\Local\Temp\vbcA8E7029D4D1E4547B0125884D3AB4C3.TMP -
858461e8ca1d309e626a1b5ce4e1d4e3a74ee960514506513300311f3e1fef76 - e098fc1971acc66b83fad3904b0b52a4ff3b4c1f7e6df743411bdd8f5f3b9433 -
e098fc1971acc66b83fad3904b0b52a4ff3b4c1f7e6df743411bdd8f5f3b9433 - baabe216e5df4a73954a117d563a8dff8b1a9a65ce68189c3be40ee9cff39e73 -
baabe216e5df4a73954a117d563a8dff8b1a9a65ce68189c3be40ee9cff39e73 - 837371e5ad93e1ca3c595434459baaea35e8d5aaf745029e22d5b59a8e8dedc4 -
837371e5ad93e1ca3c595434459baaea35e8d5aaf745029e22d5b59a8e8dedc4 - 284ec454f7c517d38f30899ecdfa3c223dfcd17f5341721c0e77829d1d682b20 -
284ec454f7c517d38f30899ecdfa3c223dfcd17f5341721c0e77829d1d682b20 - 72aa0f6e18c8d2286444a304466c11d370cfc716356e8351984fe94b5dd24cfd -
72aa0f6e18c8d2286444a304466c11d370cfc716356e8351984fe94b5dd24cfd - ad77ce0f3409b02bf8cb088de315ed07f7d866812519bae5007bfd0397b84fc8 -
ad77ce0f3409b02bf8cb088de315ed07f7d866812519bae5007bfd0397b84fc8 - e1eb1657b4086f294d9f2333514ffd7f2143b73eee5c8f2d94a5749871a81160 -
e1eb1657b4086f294d9f2333514ffd7f2143b73eee5c8f2d94a5749871a81160 - 3300e1b7dc0120bb95055fc1710a66ac2fa45f151bfdbe3734dca9f61532dc51 -
3300e1b7dc0120bb95055fc1710a66ac2fa45f151bfdbe3734dca9f61532dc51
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://bejnz.com/IP.php
Embedded domains
- bejnz.com
- rwkeith.no-ip.org
Embedded IP addresses
- 40.79.141.155
- 172.215.188.232
- 4.230.171.124
- 20.247.184.197
- 74.178.240.51
- 20.165.94.63
- 20.184.175.21
- 172.66.2.5
- 3.229.117.57
- 92.223.78.30
- 20.42.72.131
- 135.234.160.246
- 72.154.7.109
- 52.148.114.188
- 52.110.12.22
- 52.110.12.32
More Mintluks samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report