MALICIOUS — ea814dbe50bf1781e9763644869548170850e437801d6cbaf7b5af11076c3592
MALICIOUS — ea814dbe50bf1781e9763644869548170850e437801d6cbaf7b5af11076c3592 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (84/100), attributed to the Mimikatz family. 3 of 56 detection engines flagged it.
Identification
- SHA-256:
ea814dbe50bf1781e9763644869548170850e437801d6cbaf7b5af11076c3592 - SHA-1:
8c15bf06b456989fb3f3c3272a36ebb95bb96e54 - MD5:
bb59ed464f260850ae3baba0f922a897 - imphash:
a62c37bb124396bb0a64df608e37feb8 - ssdeep:
24576:1nCNadAGNifcniQWWzPk6FRcAGkjMrZR:1n0mi0FPkyjm - TLSH:
T182518C2585172173F0FEDA94ACA088ECE022F1BC6436994DD947EC5DA0E4237E9F12D9 - Submitted as: ea814dbe50bf1781e9763644869548170850e437801d6cbaf7b5af11076c3592
- File type: pe · Size: 868352 bytes
- Verdict: malicious (84/100) · Family: Mimikatz
Detections (3 of 56 engines)
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Kaspersky (KVRT): UDS:Trojan-PSW.Win32.Mimikatz.fig
Why this verdict
The malicious score of 84/100 is the fusion of 5 weighted signals:
- Kaspersky (KVRT) flagged UDS:Trojan-PSW.Win32.Mimikatz.fig (rule
UDS:Trojan-PSW.Win32.Mimikatz.fig) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Contacted 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Memory forensics: 4 finding(s) elsewhere in the guest, not attributed to this sample, e.g. RWX/private injected region in SppExtComObj.E (pid 5760) (rule
windows.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
38 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
- www.bing.com
- th.bing.com
- licensing.mp.microsoft.com
- fe3cr.delivery.mp.microsoft.com
Dropped files
- de012ca492e6dffeb55151898b382923f6590d52d1332e24db7773dcc0caebc2 -
de012ca492e6dffeb55151898b382923f6590d52d1332e24db7773dcc0caebc2
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- asset.sciter.com
Embedded IP addresses
- 40.79.167.9
- 52.123.252.215
- 4.230.171.124
- 48.211.4.16
- 57.155.101.212
- 52.253.84.76
- 74.178.76.54
- 20.42.73.24
- 20.165.94.63
- 104.18.33.89
- 74.178.240.61
- 135.233.45.221
- 52.110.12.22
- 52.110.12.20
More Mimikatz samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report