MALICIOUS — e90fc4c090ec1e6c330a769d7736c70d26a0ada8403704dd63b36c47724c7b20
MALICIOUS — e90fc4c090ec1e6c330a769d7736c70d26a0ada8403704dd63b36c47724c7b20 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Brontok family. 5 of 25 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
e90fc4c090ec1e6c330a769d7736c70d26a0ada8403704dd63b36c47724c7b20 - SHA-1:
c8df6d1478d0edbaa1fe4f7dcb1f79d7a930a573 - MD5:
dca5e13da49b0505ea5fcedf81e8f0cc - imphash:
1b675db9a912fecbf83526e2fd37cf23 - ssdeep:
6144:2WC4YgB9GiybWC4YgB9Giy8mWC4YgB9GiygWC4YgB9GiyMWC4YgB9Giy8mWC4Ygg:FtJ9GiHtJ9Gi7VtJ9GiatJ9GiKtJ9GiI - TLSH:
T1C545E1C3653A3616DED7B4FA2084150F67A9C4801C7BECD44E6B81187B2872B68FD867 - Submitted as: e90fc4c090ec1e6c330a769d7736c70d26a0ada8403704dd63b36c47724c7b20
- File type: pe · Size: 281421 bytes
- Verdict: malicious (92/100) · Family: Brontok
Detections (5 of 25 engines)
- MalwareAnalyser heuristics (entropy/packer): Petite
- Detect It Easy (packer/type): DIE:Petite 2.2
- Microsoft Defender: Worm:Win32/Rahiwi!pz
- Emsisoft (Emergency Kit): Gen:Variant.Worm.VB.75
- Kaspersky (KVRT): Email-Worm.Win32.Brontok.am
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 6 weighted signals:
- Dropped a malicious payload (Brontok): d1c8d2d7f2b28613d11cd72debdf3a91bebf7226cd7f84f57f62e4daca6bebb6 - dynamic signal, weight 0.80, confidence 0.90
- Contacted 35 external host(s) at runtime (21 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:Petite 2.2 (rule
DIE:Petite 2.2) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Petite, high-entropy-sections:.petite, Petite 2.2 - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
5906 behavior events · 1 ATT&CK techniques · 21 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Dropped files
- /opt/CAPEv2/storage/analyses/20327/files/6949695ef362522f5715309fc34cbe7ea2df8e5326e07b242bcda19969b19528 -
6949695ef362522f5715309fc34cbe7ea2df8e5326e07b242bcda19969b19528 - /opt/CAPEv2/storage/analyses/20327/files/d1c8d2d7f2b28613d11cd72debdf3a91bebf7226cd7f84f57f62e4daca6bebb6 -
d1c8d2d7f2b28613d11cd72debdf3a91bebf7226cd7f84f57f62e4daca6bebb6 - /opt/CAPEv2/storage/analyses/20327/files/73f47898e4af9077d472bfd942f40f28de5e62df5b983dea3921dafc42ed69a9 -
73f47898e4af9077d472bfd942f40f28de5e62df5b983dea3921dafc42ed69a9 - /opt/CAPEv2/storage/analyses/20327/files/574a3a546332854d82e4f5b54cc5e8731fe9828e14e89a728be7e53ed21f6bad -
574a3a546332854d82e4f5b54cc5e8731fe9828e14e89a728be7e53ed21f6bad - /opt/CAPEv2/storage/analyses/20327/files/749ee056a0b1721398144b48ca6c65bec6eb60ffce2e9b789218b5436ec0562f -
749ee056a0b1721398144b48ca6c65bec6eb60ffce2e9b789218b5436ec0562f - /opt/CAPEv2/storage/analyses/20327/files/0c4497805d1fdabbf85b77fa2ad0916e3b1a9bf15ce7b0ede2da98f22946ef24 -
0c4497805d1fdabbf85b77fa2ad0916e3b1a9bf15ce7b0ede2da98f22946ef24 - /opt/CAPEv2/storage/analyses/20327/files/898288bd3b21d0e7d5f406df2e0b69a5bbfa4f241baf29a2cdf8a3cf4d4619f2 -
898288bd3b21d0e7d5f406df2e0b69a5bbfa4f241baf29a2cdf8a3cf4d4619f2 - /opt/CAPEv2/storage/analyses/20327/files/3fc531136d8c461007be54c74f078b009c85758d4b765eff2e618b9c98093c50 -
3fc531136d8c461007be54c74f078b009c85758d4b765eff2e618b9c98093c50 - /opt/CAPEv2/storage/analyses/20327/files/179a12b20bee2e2b326b384cb300ed75629be389c0e00385b35096a9a31216a5 -
179a12b20bee2e2b326b384cb300ed75629be389c0e00385b35096a9a31216a5 - /opt/CAPEv2/storage/analyses/20327/files/c4d3cf86cf8e443b6d207e74a8a3ef88b8edc238804d2ac7ac8c856cf66974aa -
c4d3cf86cf8e443b6d207e74a8a3ef88b8edc238804d2ac7ac8c856cf66974aa - /opt/CAPEv2/storage/analyses/20327/files/885d1561946d091deac18f535ce12336a1e33a9146de5287fa4fa9f8abd247c2 -
885d1561946d091deac18f535ce12336a1e33a9146de5287fa4fa9f8abd247c2 - /opt/CAPEv2/storage/analyses/20327/files/9ba73695b503265ea7d049ed8e5c9c14c4b89e440a6253d0b443d8a37b78edc0 -
9ba73695b503265ea7d049ed8e5c9c14c4b89e440a6253d0b443d8a37b78edc0 - /opt/CAPEv2/storage/analyses/20327/files/e45ef40e947e269731dc8af79f70caac5cc5f8f34d73af4e590417bb8623651c -
e45ef40e947e269731dc8af79f70caac5cc5f8f34d73af4e590417bb8623651c - /opt/CAPEv2/storage/analyses/20327/files/daf2cea644983450be3f8c1c32321b317ccfc6fa4cf45dbc23f08b0a4d908871 -
daf2cea644983450be3f8c1c32321b317ccfc6fa4cf45dbc23f08b0a4d908871 - /opt/CAPEv2/storage/analyses/20327/files/05a56ff75296f1ec642c6229f9a4fbd32f64d56080a405eb82062f971702b5f5 -
05a56ff75296f1ec642c6229f9a4fbd32f64d56080a405eb82062f971702b5f5
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/2cbcf400-ac8d-4d86-9d69-c7f0dff56d2e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/2cbcf400-ac8d-4d86-9d69-c7f0dff56d2e?P1=1786771807&P2=404&P3=2&P4=RCYxwdhN%2bzZFQ4hNgRcGPUPmP%2fxQ23T2UFLiIWx2%2butGHKHtyjiylqV3P6I4V7H7aW%2byeq8NV%2fDiMONyo3IGNQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 20.184.175.22
- 52.123.252.239
- 52.230.60.54
- 57.155.104.224
- 4.230.171.124
- 20.165.94.63
- 74.179.77.164
- 20.42.65.85
- 135.233.45.222
- 52.123.252.247
- 20.231.239.246
- 52.123.129.14
- 40.99.133.210
- 52.123.252.242
- 203.26.79.13
- 135.232.92.34
- 72.153.5.132
- 52.110.12.37
- 52.110.12.20
More Brontok samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report