MALICIOUS — ec8519640b20e745b41d4872be4f320efd34ebd9921e2ca9c131019f22a9d716
MALICIOUS — ec8519640b20e745b41d4872be4f320efd34ebd9921e2ca9c131019f22a9d716 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Multiverze family. 5 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
ec8519640b20e745b41d4872be4f320efd34ebd9921e2ca9c131019f22a9d716 - SHA-1:
510b10948faec5d415e7da3198a7760fd1ea0caf - MD5:
01ff42c4eb47ab877e270755fcd1ef23 - imphash:
0d52988c17b6d0ad679318ef76f1e151 - ssdeep:
1536:BL+O/U7OBmKGS6CBK0t/ZCXPGuxgDM5YKBGNc/xf6KWcs8+SUkIcekqY1o/uImzJ:BLxUyjp3xCTyDMsUWyw+Ubx7Ne - TLSH:
T1693D5BD29D037521E07ADA886C1476FC84A2F8AD3935814D635BC90E10F797BB93236E - Submitted as: ec8519640b20e745b41d4872be4f320efd34ebd9921e2ca9c131019f22a9d716
- File type: pe · Size: 134154 bytes
- Verdict: malicious (100/100) · Family: Multiverze
Detections (5 of 56 engines)
- ClamAV (daily): Win.Malware.Ulise-9886066-0
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- Microsoft Defender: Trojan:Win32/Multiverze!pz
- Emsisoft (Emergency Kit): Generic.Dacic.1660.B70A67F1
- Kaspersky (KVRT): HEUR:Trojan.Win64.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 13 weighted signals:
- ClamAV (daily) flagged Win.Malware.Ulise-9886066-0 (rule
Win.Malware.Ulise-9886066-0) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s) across 1 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Memory forensics: 1 finding(s) attributed to the sample across 1 technique(s), e.g. RWX/private injected region in tsk_111688586c (pid 8792) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Win32/Multiverze!pz (rule
Trojan:Win32/Multiverze!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Generic.Dacic.1660.B70A67F1 (rule
Generic.Dacic.1660.B70A67F1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win64.Agent.gen (rule
HEUR:Trojan.Win64.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.50, confidence 0.70 - Contacted 10 external host(s) and 32 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://pm2pavba27wr4m34.onion/command.txt?smbdff - static signal, weight 0.35, confidence 0.60
- encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60 - Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
1898 behavior events · 1 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- odc.officeapps.live.com
- www.msn.com
- settings-win.data.microsoft.com
- assets.msn.com
- www.bing.com
- licensing.mp.microsoft.com
- th.bing.com
- fe3cr.delivery.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\cached-consensus -
783648682a2037bb60454c6c602eaebcba7a9bfde3b9f56f47377cb675a37f08
Embedded URLs
- http://pm2pavba27wr4m34.onion/command.txt?smbdff
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://131.188.40.189/tor/status-vote/current/consensus
- http://216.218.219.41/tor/server/fp/6280691a06f9298e7699c75ef56a301b3fb7d05b
- http://216.218.219.41/tor/server/fp/fa6aadfc1a0c9de9bd80472cb612e1c244244832
- http://216.218.219.41/tor/server/fp/ac9d89e7a99b7f95e115be6d5d219d4196b09790
- http://216.218.219.41/tor/server/fp/acb898b28acabbd78f23af2fb06fc864a4111646
- http://216.218.219.41/tor/server/fp/acbbb426ce1d0641a590bf1fc1cf05416fc0ff6f
- http://204.13.164.118/tor/server/fp/8eae810fa33f26341605d59f82d8ad58f7ea6cc5
- http://204.13.164.118/tor/server/fp/8ec879f5955ad3db5c13bca686ee5967469b909c
- http://204.13.164.118/tor/server/fp/7ac25dc9e4606154de38305bdc5a40bcbcb6d04a
- http://216.218.219.41/tor/server/fp/57337f05f8ad1368ce5a7990389bcc5305ba9db2
- http://216.218.219.41/tor/server/fp/8eccba855814f6369d3efdbd02fc6bf5ab258b03
- http://204.13.164.118/tor/server/fp/6dfeb41c04cce846871338e85dd5acf5cfb6c1dd
- http://216.218.219.41/tor/server/fp/cb81470343e29df2406ad8d9365eb5d091238f1a
- http://204.13.164.118/tor/server/fp/ac9d89e7a99b7f95e115be6d5d219d4196b09790
Embedded domains
- pm2pavba27wr4m34.onion
Embedded IP addresses
- 20.42.73.28
- 4.230.171.124
- 85.210.193.152
- 20.247.185.124
- 172.215.188.232
- 104.18.33.89
- 74.179.77.164
- 20.184.175.15
- 74.178.76.128
- 86.59.21.38
- 135.233.95.144
- 131.188.40.189
- 216.218.219.41
- 52.110.12.56
- 52.110.12.16
- 204.13.164.118
- 20.42.65.88
- 194.109.206.212
- 23.191.200.23
- 192.42.115.102
- 72.153.5.132
- 52.148.114.188
- 64.65.62.189
- 52.110.12.37
- 52.110.12.50
More Multiverze samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report