MALICIOUS — edad60a97b0e3715e282c7f8f1a1848008615e619db210cb36bb9bc0e2cf3268
MALICIOUS — edad60a97b0e3715e282c7f8f1a1848008615e619db210cb36bb9bc0e2cf3268 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Picsys family. 6 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
edad60a97b0e3715e282c7f8f1a1848008615e619db210cb36bb9bc0e2cf3268 - SHA-1:
e23487bce76f9774e563cb15ee76286285db542e - MD5:
107cc0a78995eecf0610833e51c3a2f3 - imphash:
359d89624a26d1e756c3e9d6782d6eb0 - ssdeep:
1536:y4QQ6NSyM61l19piO+LV8YEoI/EU9RUe4myv49qCLjtKRLYqd74VsO+hnJY:y4X6NSyfnpijeYEoIcq4c0CLxKRtsVYO - TLSH:
T14A3802CC9A563D64DC2FAAF05CEFC2AD7481959E61AB324D3EC560391C0E01BCC7529A - Submitted as: edad60a97b0e3715e282c7f8f1a1848008615e619db210cb36bb9bc0e2cf3268
- File type: pe · Size: 81622 bytes
- Verdict: malicious (100/100) · Family: Picsys
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Worm.Picsys-6804101-0
- Detect It Easy (packer/type): DIE:Turbo Linker
- Microsoft Defender: Worm:Win32/Yoof!pz
- Trellix Stinger (McAfee): W32/Picsys.worm!752FE334CE30
- Kaspersky (KVRT): P2P-Worm.Win32.Picsys.b
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Worm.Picsys-6804101-0 (rule
Win.Worm.Picsys-6804101-0) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s) across 1 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged Worm:Win32/Yoof!pz (rule
Worm:Win32/Yoof!pz) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged W32/Picsys.worm!752FE334CE30 (rule
W32/Picsys.worm!752FE334CE30) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged P2P-Worm.Win32.Picsys.b (rule
P2P-Worm.Win32.Picsys.b) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 1 external host(s) and 19 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 a#¤, Turbo Linker - static signal, weight 0.25, confidence 0.55
- Dropped 22 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
132 behavior events · 1 ATT&CK techniques · 27 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- v7x3a5l9.hypermart.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- officeclient.microsoft.com
- www.msn.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
Dropped files
- C:\Windows\System32\macromd\icqcracker.exe -
99df8daf2c48096fe3d7d0438e0b820c8a1c1bb1462cdf81a87c6b2770e7ee52 - C:\Windows\System32\macromd\Flash Golf.exe -
bd43288a0297171875a5d469042f06f63039ac1e478e313a20e537edceb594e5 - C:\Windows\System32\macromd\jenna jameson sex scene huge dick blowjob.scr -
a2d024e5455d0a12a41ec8c41f717c4af3d7072425e105f480494e26360dc2e2 - C:\Windows\System32\macromd\Want to see a massive horse cock in a tight little teen's pussy.mpg.pif -
4e73fb633fe07dceee3e30284e9aa58cc6c8c8fc92965187f2bc7d7b697c751c - C:\Windows\System32\macromd\illegal porno - 15 year old raped by two men on boat.mpg.pif -
784b49bc18aabd076cf46b59c8155b55bac8313190a428172d3cacf97af05da8 - C:\Windows\System32\macromd\Website Hacker.exe -
74f6493fd465b8d78ec247d835d47e12306ba851155d8ba593386e81925d8e71 - C:\Windows\System32\macromd\AIM Flooder.exe -
75515fe40e99a477b5437e2c53487ec96fb5e5c99fadadf770ce4a0c8d2329aa - C:\Windows\System32\macromd\CKY3 - Bam Margera World Industries Alien Workshop.exe -
32a662ea73dd7a02b911efe8e44180d710461f49adbcf0d55076552e124a2a4c - C:\Windows\System32\macromd\Windows 2000.exe -
c9f3bf70e2e0089b69acf96c936ad4024b286ab6bb174f0f54fece7d968710a2 - C:\Windows\System32\macromd\cute girl giving head.exe -
18a11a8820c577502d00d21628e78920f7dfdd7f2f0555a18287b28ad939dc35 - C:\Windows\System32\macromd\16 year old on beach.exe -
2eb158376c52dc29d00a71e7434c1f98e5f7af72eca67f0d4f85a29bbc7c04fd - C:\Windows\System32\macromd\hot girl on the beach sucking cock and fucking guy.mpg.exe -
15ba9a83b1a538bb6d737841ba39ce9b5677e75544252418bf067c9e10da84ed - C:\Windows\System32\macromd\virtua girl - adriana.pif -
e905ef4bb2ec51d857d4288ec8eecbe027facc7e7ec05d0393aa665f225322c7 - C:\Windows\System32\macromd\aimhacker.exe -
cd1a9cd35830f201ba4d34827bca71f10081572460a2da510ee3791a3af9c1c0 - C:\Windows\System32\macromd\GTA3 crack.exe -
5c97ebb1f8ea724913f153e43eaa0eafa8ffa8fd65fe6a49e0facfce708a73b6
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- http://v7x3a5l9.hypermart.net/cgi-bin/w.cgi?192.168.122.108A5166B8917C9812D45627754E3F0
Embedded domains
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- v7x3a5l9.hypermart.net
Embedded IP addresses
- 4.150.223.102
- 52.123.252.219
- 172.215.188.232
- 4.230.171.124
- 104.18.33.89
- 52.230.60.54
- 74.178.76.128
- 135.232.92.97
- 4.150.223.103
- 74.178.240.61
- 4.150.223.115
- 38.113.1.151
- 72.153.5.137
- 52.110.12.30
- 52.148.114.188
- 52.110.12.31
More Picsys samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report