MALICIOUS — f25fdfbb31c0d89df91a27714e6cf3c0df2f657669d1a83e467264259ff4a248
MALICIOUS — f25fdfbb31c0d89df91a27714e6cf3c0df2f657669d1a83e467264259ff4a248 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the OnlineGames family. 8 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
f25fdfbb31c0d89df91a27714e6cf3c0df2f657669d1a83e467264259ff4a248 - SHA-1:
22fa76374ffeb5bb93523867b42b6026f5fe15d8 - MD5:
7684e970ef85aa78bd5deccb2765ba33 - imphash:
f400c050927c73561aafeea55143db40 - ssdeep:
12288:WBAsu/1OsCzbT7YebtN2rMFpouF0/De0:jMzEgNPFpoz/x - TLSH:
T16E4D6B683C116D44CBB6B1506CA5A80DFCB2747C09BE098642CFC76F93BEC3B255694A - Submitted as: f25fdfbb31c0d89df91a27714e6cf3c0df2f657669d1a83e467264259ff4a248
- File type: pe · Size: 580326 bytes
- Verdict: malicious (96/100) · Family: OnlineGames
Detections (8 of 52 engines)
- capa (capabilities): capability:collection/keylog
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.OnlineGames-65
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:Win32/BHO!pz
- Trellix Stinger (McAfee): Trojan-FUHM!7684E970EF85
- Kaspersky (KVRT): Trojan-Downloader.Win32.Gamup.qjl
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Trojan.OnlineGames-65 (rule
Win.Trojan.OnlineGames-65) - engine signal, weight 0.90, confidence 0.95 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://stat.wamme.cn/C8C/gl/cnzz60.html?page=http://www.WebDllx.com/NewRun, http://stat.wamme.cn/C8C/gl/cnzz60.html?page=http://www.WebDllx.com/NoDllx, http://stat.wamme.cn/C8C/gl/cnzz61.html?page=http://www.WebDllx.com/RunExeFail - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: UPX, Microsoft Linker - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://stat.wamme.cn/C8C/gl/cnzz60.html?page=http://www.WebDllx.com/NewRun
- http://stat.wamme.cn/C8C/gl/cnzz60.html?page=http://www.WebDllx.com/NoDllx
- http://stat.wamme.cn/C8C/gl/cnzz61.html?page=http://www.WebDllx.com/RunExeFail
- http://www.baiduo.org/
- http://i.maxthon.cn/
- http://stat.wamme.cn/C8C/gl/cnzz60.html
Embedded domains
- stat.wamme.cn
- 2345.com
- 2345.com
- www.baiduo.org
- i.maxthon.cn
File paths
- C:\WINDOWS\system32\drivers\etc\service5.ini
- C:\Program
- c:\windows\KB978978.log
- C:\WINDOWS\system\sdax.txt
- e:\JinZQ\Hook
- C:\WINDOWS\system32\drivers\etc\service3.ini
More OnlineGames samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report