MALICIOUS — f6db82a44b3ed7e370c21c111ea46a0d74334d6c04c2d8346f4e8fff9df06922
MALICIOUS — f6db82a44b3ed7e370c21c111ea46a0d74334d6c04c2d8346f4e8fff9df06922 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 56 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
f6db82a44b3ed7e370c21c111ea46a0d74334d6c04c2d8346f4e8fff9df06922 - SHA-1:
8cd32e10f28955647cbb3a4883df4b5e9b63ae9e - MD5:
35484533fcf12141fc6d96933247cbbf - imphash:
6ed4f5f04d62b18d96b26d6db7c18840 - ssdeep:
24576:QVHDsn6PdlOenej4cQ2QR90yF38Gv+R0gR7jy+weRO15pebn082Sf7U9/9Us:qHw6P3ReMcQ2RyFMnR0gR7jtHMn+mSgD - TLSH:
T1D9562345198A3F03D4DB680B3D52E85E6D62214D3E4A7A03B792C1362E0FD5F6E1D0AB - Submitted as: f6db82a44b3ed7e370c21c111ea46a0d74334d6c04c2d8346f4e8fff9df06922
- File type: pe · Size: 1391104 bytes
- Verdict: malicious (98/100)
Detections (4 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- Microsoft Defender: Trojan:Win32/Injector.RAQ!MTB
- Emsisoft (Emergency Kit): Gen:Heur.Mint.Zard.24
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Injector.RAQ!MTB (rule
Trojan:Win32/Injector.RAQ!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Heur.Mint.Zard.24 (rule
Gen:Heur.Mint.Zard.24) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win32.Generic (rule
HEUR:Trojan.Win32.Generic) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s) across 1 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 4 external host(s) and 12 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
8688 behavior events · 2 ATT&CK techniques · 17 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- zipansion.com
- publisher.linkvertise.com
- c.pki.goog
- direct-link.net
- linkvertise.com
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- settings-win.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
Dropped files
- C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12 -
63b14543360f5e89942ea8d5113526e64fbc71c1207328f0136b3a495d921dd0 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12 -
2c53646c452689d561e8930ab89a0395b67faf7c2fa6e50f51d8ae25ce03e363 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8AC0ED8906442A67C7B113D790F1875D -
e48d85075d26aa05753cbb66c048897d2aa7dc364efa96fa33c72d04813f90db - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8 -
d2bb091268ade68ad8121d2184d0fbce128070156304bd4de312e6fbd267409c - C:\Users\analyst\AppData\Local\Microsoft\Windows\INetCache\IE\H9BOFF51\AFK9IqzvctpL[1].htm -
b323364172d200dda3fdaab6f2a4ae6f85829e10f250bd24816afdbdb27fc459 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7D588C464E3D4F9F1F5D043A1B7C9A7E -
135d30f845b0a0f56c466da6d7b5400979078e64e55d814e9cf8c6a59798b49a - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7D588C464E3D4F9F1F5D043A1B7C9A7E -
0e304e4e49b199714b36fea929b2853688f03bb89a51c38cd2b9025b41234655 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B625C9EE8BD3E6849AFA2339291AE3C -
0373711e906e01f02591cbe44f00065142335629a5f1e39e05b4c844f280e57e - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B625C9EE8BD3E6849AFA2339291AE3C -
4878ccb047bc9c4ec05933efafc1f5f877c954356acdb414c8c140a7ed63e561 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8 -
875f265af96c2ffe0819afccd615c1ec72d7fd5cfabcdeefc5a1b22dccf90f3c - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8AC0ED8906442A67C7B113D790F1875D -
fe5cf9d7cd57e98c4ea69e46d633425b415ea483b2d966fb2a8d588332affed2 - bacb1eef82912cc96219e9a3953a9c461671ad6472d61654dda5ab5e63cba695 -
bacb1eef82912cc96219e9a3953a9c461671ad6472d61654dda5ab5e63cba695 - 1cd6223d25c0bfe56088768e871cda9f7ce9d7fda2e2866cf64175e575e2cb61 -
1cd6223d25c0bfe56088768e871cda9f7ce9d7fda2e2866cf64175e575e2cb61 - 4ad447282d55c3f8144a39c752086b7e9d9676fa859f7ae3dcf238be81369fc0 -
4ad447282d55c3f8144a39c752086b7e9d9676fa859f7ae3dcf238be81369fc0 - 4a55b39c66e7d9aff323e602b79a1e1640a1ea162e2225a38ee0ed67a57b2415 -
4a55b39c66e7d9aff323e602b79a1e1640a1ea162e2225a38ee0ed67a57b2415
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://zipansion.com/2pRLi
- http://c.pki.goog/r/gsr1.crl
- http://c.pki.goog/r/r4.crl
- http://c.pki.goog/we1/pyeoXlQPF4E.crl
- http://c.pki.goog/we1/OpMCQT6sVwg.crl
- http://c.pki.goog/we1/USODfqcOxVM.crl
Embedded domains
- schemas.microsoft.com
- zipansion.com
- publisher.linkvertise.com
- direct-link.net
- linkvertise.com
Embedded IP addresses
- 13.69.116.108
- 40.84.97.4
- 4.230.171.124
- 40.84.85.40
- 20.165.94.54
- 74.179.77.204
- 20.42.72.131
- 52.230.59.222
- 20.184.175.11
- 172.64.154.167
- 20.165.94.63
- 92.223.78.30
- 72.154.7.96
- 52.110.12.37
- 52.110.12.42
- 52.148.114.188
- 104.18.1.75
- 172.67.144.180
- 104.18.0.75
- 104.21.61.249
File paths
- w:\#d
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report