MALICIOUS — ea31985086363dc8d9dca9df7eced875ef775b1a78a138723b105e32ba7d94b3
MALICIOUS — ea31985086363dc8d9dca9df7eced875ef775b1a78a138723b105e32ba7d94b3 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the LokiBot family. 4 of 55 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
ea31985086363dc8d9dca9df7eced875ef775b1a78a138723b105e32ba7d94b3 - SHA-1:
fef001943eca05c89e8a1ab7d07d67c850048577 - MD5:
c5f93a2a2c05f231b31b4565ea365d47 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
6144:3Igi1JM3L2GhNrTvoYmtTGT8dKLJ3lE+steS+42gteVyEg6WM:RjL2iNnohTE8dKLrcUS+42gteVVg65 - TLSH:
T1AF486B3FCA65C6BFFF3B1EE3AC0246CE226A781DD45039C3112D6B01D10964B16B55AA - Submitted as: ea31985086363dc8d9dca9df7eced875ef775b1a78a138723b105e32ba7d94b3
- File type: pe · Size: 373760 bytes
- Verdict: malicious (97/100) · Family: LokiBot
Detections (4 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- Microsoft Defender: Trojan:Win32/AgentTesla!ml
- Emsisoft (Emergency Kit): Trojan.Crypt
- Kaspersky (KVRT): UDS:Backdoor.MSIL.Androm.gen
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 6 weighted signals:
- Extracted LokiBot config (1 C2) - engine signal, weight 0.80, confidence 0.90
- 3 behavioral detection(s): Credential Access: browser credential store read [high] (rule
tl-browser-credential-access) - dynamic signal, weight 0.60, confidence 0.90 - Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 25 external host(s) at runtime (21 HTTP) - network signal, weight 0.40, confidence 0.80
- Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
7063 behavior events · 1 ATT&CK techniques · 16 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- settings-win.data.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Roaming\DBD376\666D4B.lck -
6b86b273ff34fce19d6b804eff5a3f5747ada4eaa22f1d49c01e52ddb7875b4b - 4b5f78c3b66473a07df5e4378aeeccc50245fd1590b1eb1a64ec579cd4373444 -
4b5f78c3b66473a07df5e4378aeeccc50245fd1590b1eb1a64ec579cd4373444 - 24efc6a4be2555f641e99732c515a8be1ce8eaebe0bb62c3a726323a9256d94c -
24efc6a4be2555f641e99732c515a8be1ce8eaebe0bb62c3a726323a9256d94c - 0befdc7c7013e52c4352556e42f2f11a8272b002af3b26e02fbff605f462273b -
0befdc7c7013e52c4352556e42f2f11a8272b002af3b26e02fbff605f462273b - 35e208de093ce1ec09b9a2ce6944c10ce3f81c7878a4eb187f889f1e55137b5c -
35e208de093ce1ec09b9a2ce6944c10ce3f81c7878a4eb187f889f1e55137b5c - 729d82b277bdf16b62cce5fbb44cfdc0f9d9b3093304c2af618c332fe1a0863e -
729d82b277bdf16b62cce5fbb44cfdc0f9d9b3093304c2af618c332fe1a0863e - 1708d7719d5711f84b722a475ae642d1d4a4a55fee6c7ab928b8a1391eaaedf8 -
1708d7719d5711f84b722a475ae642d1d4a4a55fee6c7ab928b8a1391eaaedf8 - 87ce764047d8d75503b6f4ce7d47268f723952acee2deabf06a13aa47e8135be -
87ce764047d8d75503b6f4ce7d47268f723952acee2deabf06a13aa47e8135be - 3f521a3a874e45846610b68640d2a719736c476a6d69d4f0adc1cc58e964d7c6 -
3f521a3a874e45846610b68640d2a719736c476a6d69d4f0adc1cc58e964d7c6 - c018e4e43582fc9ead01ef3e4d0f29407d33d6c111d74d605179c29c379dc5ac -
c018e4e43582fc9ead01ef3e4d0f29407d33d6c111d74d605179c29c379dc5ac - 08693de46f537e1b65d02abb1ea3a3831acbb97c4f5f0c37af0e11bebf88a595 -
08693de46f537e1b65d02abb1ea3a3831acbb97c4f5f0c37af0e11bebf88a595 - b8629a9632e48038b50ea4c85c6b54730bdf6d699fc478b7549fad8d10644173 -
b8629a9632e48038b50ea4c85c6b54730bdf6d699fc478b7549fad8d10644173 - bd4c4912209802bb457983177d94b220d20dc9775ff973f90bd1c6afd729bc9c -
bd4c4912209802bb457983177d94b220d20dc9775ff973f90bd1c6afd729bc9c - 07490f4293371122e2182ddd03dd2a65e491e83044c1f2bcf38263c782efe541 -
07490f4293371122e2182ddd03dd2a65e491e83044c1f2bcf38263c782efe541 - 63fe4443e14b00b15357605ed0cc597c1a005786f62af44be375ae7091d61720 -
63fe4443e14b00b15357605ed0cc597c1a005786f62af44be375ae7091d61720
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787905553&P2=404&P3=2&P4=YebndKZ866xVVx4Gx4j5xLvbGSRfk5kL9YTt6%2fqCSUlQMOgQDUtQ9mrqYfPl3nHKI737Fnexda%2bLgZprIcK4Rg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787905601&P2=404&P3=2&P4=EGKtJNfnq5RRSK5lRpv4gynU%2bCbvb%2bEf2bBQel4aW62VE5EF5OF%2bNFyOPIW3eJfwuWa0Gd86LK5gLYpN3zOyvg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://63.250.40.204/~wpdemo/file.php?search=728736
Embedded IP addresses
- 20.184.175.16
- 52.123.252.212
- 57.155.104.224
- 4.230.171.124
- 52.253.84.76
- 74.178.240.61
- 4.150.223.99
- 135.232.92.34
- 74.178.240.51
- 74.179.77.204
- 203.26.79.13
- 20.112.250.133
- 40.99.134.2
- 52.123.128.14
- 135.233.45.222
- 52.148.114.188
- 4.247.188.224
- 4.150.223.101
- 52.182.141.63
- 63.250.40.204
- 72.145.35.111
- 20.42.73.28
- 4.209.250.170
- 135.234.160.246
- 52.110.12.4
More LokiBot samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report