MALICIOUS — ec9e34da9a7a3d70338cf39ef2c470d12c334732fe009cd2fd8b313efdccd578
MALICIOUS — ec9e34da9a7a3d70338cf39ef2c470d12c334732fe009cd2fd8b313efdccd578 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Fileinfector family. 5 of 56 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
ec9e34da9a7a3d70338cf39ef2c470d12c334732fe009cd2fd8b313efdccd578 - SHA-1:
808709f8385774b551fb20cb7cdb30bfb76386bd - MD5:
1bcae6d03dfaf91cba05b64330cbe968 - imphash:
895fbb56c02c3d2bca3125cef5da8730 - ssdeep:
3072:v15Jt5EsmcLMt5EsmcLMt015Jt5EsmcLMt015Jt5EsmcLMt015Jt015Jt5EsmcLq:t5hZ0Zl5hZl5hZl5O5hZl5O5hZl5x - TLSH:
T16F499FC531953A10EDF4F858ED04EC2CB15389A222363BD86402D57FB4B97F706A986E - Submitted as: ec9e34da9a7a3d70338cf39ef2c470d12c334732fe009cd2fd8b313efdccd578
- File type: pe · Size: 398612 bytes
- Verdict: malicious (100/100) · Family: Fileinfector
Detections (5 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Dropper.Fileinfector-9830254-0
- Detect It Easy (packer/type): DIE:MinGW
- Microsoft Defender: Trojan:Win32/Vindor!pz
- Kaspersky (KVRT): Virus.Win32.Lamer.ks
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 14 weighted signals:
- ClamAV (daily) flagged Win.Dropper.Fileinfector-9830254-0 (rule
Win.Dropper.Fileinfector-9830254-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Vindor!pz (rule
Trojan:Win32/Vindor!pz) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.Lamer.ks (rule
Virus.Win32.Lamer.ks) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 2 external host(s) and 17 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497, T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:MinGW (rule
DIE:MinGW) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://www.pinkworld.com, http://www.youporn.com, http://www.redtube.com - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: UPX, high-entropy-sections:UPX1, MinGW - static signal, weight 0.25, confidence 0.55
- Dropped 23 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
102927 behavior events · 2 ATT&CK techniques · 38 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- www.bing.com
- assets.msn.com
Dropped files
- C:\Windows\System32\vcruntime140_threads.dll -
8ed2465e646a3f1819b812a339b68c8b7854203bd40ec4ac287f8ec78fe7e096 - C:\Windows\System32\mfcm140.dll -
f06e7a6516108312738e259956013b954fad7d3f48033e19b77448ec36123d6f - C:\Windows\win.ini -
d1c4c28150954a402846e221dc853d5b73133d7d5b1cb08411101a935d955b37 - C:\Windows\System32\NOISE.DAT -
964faa1e9ec6b25611b36bf209e922e0a43df531b37985cdcfa537c92877f388 - C:\exc.exe -
2f5b499000acc32b93d45cd55a91f46f22e414be576459447594f37cb683f6ae - C:\Windows\py.exe -
1942176b496d6098be53ec252ef9c49aa29be5854ebce76b3463828e8460f7f0 - C:\Windows\DtcInstall.log -
5dee1012ef365fbe7b0627e44d9562bd26918d14d6f7bc915df1173fdc029bef - C:\Windows\System32\PrintConfig.dll -
52d91da7c6341fcfd2b1ce27ae3da2d923b7898fc36cc9900483b8675da4a4a3 - C:\Windows\System32\mfc140.dll -
bfdceffa27e073a87534def74b8b0978447d6e8c93e1660cb1af82fe97e54742 - C:\Windows\System32\debug.log -
d534774e9d1b66e6de14956e95d9cf769cdfdc6ea2e7d3821964b054c22f5700 - C:\Windows\System32\msvcp140_1.dll -
3d37838ff8b9f0a05f47d23877ad3bf1569b67c7f6af70c950814ea93c8fcf2b - C:\Windows\System32\msclmd.dll -
b56d5795c0fb0f83ead361c4c3d38e4df20b1055600c19c60931f6688c7465d3 - C:\Windows\Professional.xml -
d03e39751dd508c16a0955d486f2fc5c4bae09ec14087b48162ee27a420fe60b - C:\Windows\System32\vcomp140.dll -
664ea1d8ca50ae9f7bef1f9a9846cca814f0d589a7b51acbe20b749f98152cf1 - C:\Windows\System32\msvcp140_2.dll -
b9fbcbe6c5d566a66dd12b1887b273f932abe0b2d72ca4b3aaa72d065ef9af19
Embedded URLs
- http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl0O
- http://office.microsoft.com
- http://www.pinkworld.com
- http://www.youporn.com
- http://www.redtube.com
- http://www.assparade.com/
- http://www.freeav.com/
- http://www.antispyware.com/
- http://www.antivirus.com/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- crl.microsoft.com
- www.microsoft.com
- office.microsoft.com
- www.pinkworld.com
- www.youporn.com
- www.redtube.com
- www.assparade.com
- www.freeav.com
- www.antispyware.com
- www.antivirus.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 4.150.223.108
- 4.144.132.114
- 52.123.252.239
- 4.230.171.124
- 52.110.12.14
- 52.110.12.21
- 172.178.240.162
- 85.210.196.11
- 52.148.114.188
- 92.223.78.30
- 52.110.12.31
- 52.110.12.52
- 72.153.5.133
File paths
- d:\w7rtm\com\complus\dtc\dtc\adme\deployment.cpp
More Fileinfector samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report