MALICIOUS — f3f6a3ff07cc0d15591bea359c61854eda69e7d2881706891bc894f6c91a2c62
MALICIOUS — f3f6a3ff07cc0d15591bea359c61854eda69e7d2881706891bc894f6c91a2c62 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Arkei family. 5 of 56 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f3f6a3ff07cc0d15591bea359c61854eda69e7d2881706891bc894f6c91a2c62 - SHA-1:
84aabf5a9fe78a115e3cb7fe28103e55451e9921 - MD5:
ef6b0f415addb4dcaba9c3a5dd5a3a4a - imphash:
0e60d546989cfb1b298567f1ff6841a3 - ssdeep:
24576:lGkhRxucXpplsxcd26LZBAKj2YwHUDnPb22L:lNptUmyUDPb9 - TLSH:
T1A8558D3E172BB663E639C62858049F5E0CF1FC5A51B12CCD5577883EE3E5C6B2A80219 - Submitted as: f3f6a3ff07cc0d15591bea359c61854eda69e7d2881706891bc894f6c91a2c62
- File type: pe · Size: 1326592 bytes
- Verdict: malicious (99/100) · Family: Arkei
Detections (5 of 56 engines)
- capa (capabilities): capability:collection/keylog
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Trojan:Win32/Qakbot.GJ!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Fragtor.39384
- Kaspersky (KVRT): UDS:Trojan-Spy.Win32.Stealer.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- Extracted Arkei config (1 C2) - engine signal, weight 0.80, confidence 0.90
- Microsoft Defender flagged Trojan:Win32/Qakbot.GJ!MTB (rule
Trojan:Win32/Qakbot.GJ!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Fragtor.39384 (rule
Gen:Variant.Fragtor.39384) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:Trojan-Spy.Win32.Stealer.gen (rule
UDS:Trojan-Spy.Win32.Stealer.gen) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- capa (capabilities) flagged capability:collection/keylog (rule
capability:collection/keylog) - engine signal, weight 0.35, confidence 0.70 - Memory forensics: 4 finding(s) elsewhere in the guest, not attributed to this sample, e.g. RWX/private injected region in SppExtComObj.E (pid 6008) (rule
windows.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
1468 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- www.bing.com
- assets.msn.com
- fe3cr.delivery.mp.microsoft.com
- licensing.mp.microsoft.com
- v10.events.data.microsoft.com
Dropped files
- d9e307f199e1a025c29a2899d4c6f881aedbe0fb12578e1a925b83cef9ce5268 -
d9e307f199e1a025c29a2899d4c6f881aedbe0fb12578e1a925b83cef9ce5268 - ef3577f6a0edb23dd14a4f6efa7ef3dc281e50b75173fc043cc901eb949d898f -
ef3577f6a0edb23dd14a4f6efa7ef3dc281e50b75173fc043cc901eb949d898f - bb7cb81d7faad798fe01192c7319c4395b0392ed1205b5606bf8384131d64d1e -
bb7cb81d7faad798fe01192c7319c4395b0392ed1205b5606bf8384131d64d1e
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 20.42.65.91
- 4.230.171.124
- 40.84.97.4
- 4.144.132.114
- 74.178.240.51
- 74.178.76.128
- 13.69.109.131
- 40.79.150.121
- 74.178.240.61
- 52.110.12.38
- 52.110.12.8
File paths
- T:\:`:d:h:l:p:t:x:
- X:\:`:d:h:l:p:t:x:
- X:\:`:d:h:
- X:\:`:d:h:l:p:t:
- T:\:d:l:t:
- X:\:`:B;F;J;N;R;V;Z;^;b;f;j;n;r;v;z;~;
- T:\:~:
More Arkei samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report