MALICIOUS — f4f71fdf8025f496310afcbb043535808884d1050f5b17fe373ae4b2580a0ec1
MALICIOUS — f4f71fdf8025f496310afcbb043535808884d1050f5b17fe373ae4b2580a0ec1 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f4f71fdf8025f496310afcbb043535808884d1050f5b17fe373ae4b2580a0ec1 - SHA-1:
a18d411210e77cb0db1b3de6be102517bd9fc12c - MD5:
c08eb9d1c0b19371c1ecaa55fae84251 - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
3072:0EqjLyKpVFRqPdUX+gDJyegJBlvZHcH1:0vjLyKpVFRqPdUX+gDJyegJBlvZHcH1 - TLSH:
T17240439F919F848EF16AA6937A0C0FAE50DD10852332BA824524F7C79F37903D70995E - Submitted as: f4f71fdf8025f496310afcbb043535808884d1050f5b17fe373ae4b2580a0ec1
- File type: pe · Size: 175711 bytes
- Verdict: malicious (92/100)
Detections (5 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Generic-9831620-0
- Microsoft Defender: Trojan:Win32/CryptInject!pz
- Emsisoft (Emergency Kit): Trojan.GenericKD.39862403
- Kaspersky (KVRT): Virus.Win32.Lamer.ks
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Generic-9831620-0 (rule
Win.Trojan.Generic-9831620-0) - engine signal, weight 0.90, confidence 0.95 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://www.pinkworld.com, http://www.youporn.com, http://www.redtube.com - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: UPX - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.pinkworld.com
- http://www.youporn.com
- http://www.redtube.com
- http://www.assparade.com/
- http://www.freeav.com/
- http://www.antispyware.com/
- http://www.antivirus.com/
Embedded domains
- www.pinkworld.com
- www.youporn.com
- www.redtube.com
- www.assparade.com
- www.freeav.com
- www.antispyware.com
- www.antivirus.com
Embedded IP addresses
- 6.1.1.6
File paths
- C:\Windows\system32\svchost.exe
- c:\windows\system32\wuaueng.dll
- C:\Windows\SoftwareDistribution
- C:\Windows\SysWOW64\wusa.exe
- C:\Windows\SysWOW64\wuapi.dll
- C:\26ada506c19cc0b35fb64f492f55e2\wsusscan.cab
- C:\Windows\SoftwareDistribution\ScanFile\2b4e3c91-ac39-462d-9ffa-b65b57ff5a9d\Source.cab:
- C:\Windows\SoftwareDistribution\Download\fbffd999691b70a044083664d2fb7c25_ctc
- C:\Windows\SoftwareDistribution\Download\fbffd999691b70a044083664d2fb7c25_ctc\Windows6.1-KB2999226-x64.cab:
- C:\Windows\system32\wuauclt.exe
- C:\Windows\system32\wuaueng.dll
- C:\Windows\SoftwareDistribution\Download\fbffd999691b70a044083664d2fb7c25\Windows6.1-KB2999226-x64.cab,
- C:\Windows\SoftwareDistribution\Download\fbffd999691b70a044083664d2fb7c25\inst
- C:\bf8599ee00a29f8face02c0393301bd8\wsusscan.cab
- C:\Windows\SoftwareDistribution\ScanFile\9d085694-7e0b-4598-b6c9-47d08f306a11\Source.cab:
- C:\7dc80b3ae5891b6d71b530973761\wsusscan.cab
- C:\Windows\SoftwareDistribution\ScanFile\a249cf70-4a46-4da4-b8e3-9276e3c7c856\Source.cab:
- C:\2869ea415a12e75ba3\wsusscan.cab
- C:\Windows\SoftwareDistribution\ScanFile\5d2c4541-99ac-4c50-917f-b6fe22c2a61b\Source.cab:
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report