MALICIOUS — ee6a71f7aa1038cb3491a3eb727690976c54c5aba10627c881ceac299e9c9669
MALICIOUS — ee6a71f7aa1038cb3491a3eb727690976c54c5aba10627c881ceac299e9c9669 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (79/100), attributed to the ClipBanker family. 4 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ee6a71f7aa1038cb3491a3eb727690976c54c5aba10627c881ceac299e9c9669 - SHA-1:
e30b7d9d77e85ba6bc294ff4d1e6d0b6f8a73bfd - MD5:
12b066a19475cdd69cbc5af15a0d6c51 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
24576:x8VJ2Ixy1wCPTdBt7268z0CMfFaJkYnF79LSCkhvMZBFmHkUpQM/jU+jp87C43Y:x8VJpsvPPtqJYPYnZdSCkhlrUU43 - TLSH:
T173528D39D896EEFEF93B248A797284EE03FA926D4A243C6B18DD5B744416C17341B103 - Submitted as: ee6a71f7aa1038cb3491a3eb727690976c54c5aba10627c881ceac299e9c9669
- File type: pe · Size: 941056 bytes
- Verdict: malicious (79/100) · Family: ClipBanker
Detections (4 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:MSIL/ClipBanker.MA!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Strictor.265578
MITRE ATT&CK
Why this verdict
The malicious score of 79/100 is the fusion of 5 weighted signals:
- Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - Contacted 25 external host(s) at runtime (16 HTTP) - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - 1 behavioral detection(s): Discovery: enumerates installed security software [low] (rule
tl-security-software-discovery) - dynamic signal, weight 0.20, confidence 0.90 - Packing/obfuscation: high-entropy-sections:.text, Microsoft Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
1303 behavior events · 0 ATT&CK techniques · 5 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- settings-win.data.microsoft.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Dropped files
- 453a9a5978c959664c6c1696671a7bc189c6a3eaf6d6378cc18b7af3a13a701d -
453a9a5978c959664c6c1696671a7bc189c6a3eaf6d6378cc18b7af3a13a701d - 8f641b4d1c9666abd0fe42845ecafc9507ce2f2de1255b518a2e9704b4f23ee9 -
8f641b4d1c9666abd0fe42845ecafc9507ce2f2de1255b518a2e9704b4f23ee9 - 4e82bb36546bbc0c8ff7737ec5c94c2ec90e39a84ae1e3b06342bd00833bc30a -
4e82bb36546bbc0c8ff7737ec5c94c2ec90e39a84ae1e3b06342bd00833bc30a - b83da9ddfe56703a3a3e2c2150759c89c3c4c1edbfec9982994582999b680995 -
b83da9ddfe56703a3a3e2c2150759c89c3c4c1edbfec9982994582999b680995 - 188f617342ccbbdba89c283eab2306d179b07c60149639215eccedc3238f520a -
188f617342ccbbdba89c283eab2306d179b07c60149639215eccedc3238f520a
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787764644&P2=404&P3=2&P4=V8OwsISv9bmnlGtgWfaYV3Vhzlz7jiTrmN2JcYLHokOp4mQehdboa9lcVY1zLvC%2bIOso%2bzkdAfxqeuK1LcXZjA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 20.184.175.17
- 20.42.179.204
- 4.230.171.124
- 20.247.184.197
- 4.247.188.224
- 52.110.12.37
- 52.110.12.46
- 104.46.162.224
- 20.165.94.63
- 74.178.240.51
- 20.50.201.200
- 52.123.128.14
- 52.123.129.14
- 20.236.44.162
- 40.99.133.226
- 203.26.79.13
- 74.179.77.204
- 51.116.253.168
- 135.233.45.221
- 135.233.95.80
- 52.148.114.188
- 52.110.12.30
- 135.234.160.244
- 72.145.35.108
- 52.110.12.31
More ClipBanker samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report