MALICIOUS — tl-final-qa.exe
MALICIOUS — tl-final-qa.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the AsyncRAT family. 0 of 34 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
f74cb7c98991bbd530815bf2d09f04e0d0eeda5f27ffc63eb6e760eb03167c14 - SHA-1:
5d0200c48f777a2956c623b45e6800067fdd48f2 - MD5:
71dd85e7da834d68bf34333d92a869d1 - imphash:
b17bb7c314fd2b059817ab62cad9ea81 - ssdeep:
12288:+ZklB0ws0Ljq0dfaq2mItbTYDMgWsg+Nz6MCKJVPDh7LGdB6MWP:++n0APfB27NcQ56NuM9JVPDFSB6MWP - TLSH:
T14D4D8C001112E383D4A5FFB49C89CEDC9073EA9031BF198C6396D1AE96D7D4B94C94BA - Submitted as: tl-final-qa.exe
- File type: pe · Size: 602134 bytes
- Verdict: malicious (97/100) · Family: AsyncRAT
Detections (0 of 34 engines)
No engine flagged this sample.
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 6 weighted signals:
- 1 behavioral detection(s): Defense Evasion: disable AV / Defender [high] (rule
tl-defender-tamper) - dynamic signal, weight 0.60, confidence 0.90 - Extracted AsyncRAT config (1 C2) - engine signal, weight 0.80, confidence 0.65
- Contacted 10 host(s) at runtime - network signal, weight 0.55, confidence 0.85
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.45, confidence 0.90 - 1 IDS alert(s): ThreatLens DGA-like NXDOMAIN burst - network signal, weight 0.50, confidence 0.80
- Embedded network infrastructure: http://schemas.microsoft.com/SMI/2016/WindowsSettings, 1.0.0.0 - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
4695 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- wdcp.microsoft.com
- d.1.d.1.c.4.2.1.4.9.5.2.6.e.8.b.0.0.0.0.0.0.0.0.0.0.0.0.0.8.e.f.ip6.arpa.
- 76.0.240.10.in-addr.arpa.
- 1.0.240.10.in-addr.arpa.
- wpad
- 251.0.0.224.in-addr.arpa.
- 9.189.218.68.in-addr.arpa.
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- geo.prod.do.dsp.mp.microsoft.com
- kv601.prod.do.dsp.mp.microsoft.com
- cp601.prod.do.dsp.mp.microsoft.com
- 10.240.0.1
- ff02:0:0:0:0:0:1:2
- 68.218.189.9
- 224.0.0.251
- 10.240.0.76
- ff02:0:0:0:0:0:0:fb
- fe80:0:0:0:b8e6:2594:124c:1d1d
- ff02:0:0:0:0:0:1:3
- 224.0.0.252
Embedded URLs
- http://schemas.microsoft.com/SMI/2016/WindowsSettings
Embedded domains
- schemas.microsoft.com
Embedded IP addresses
- 1.0.0.0
File paths
- X:\:`:d:h:l:p:t:x:
- T:\:d:l:t:
- X:\:h:x:
- T:\:d:l:x:
- T:\:h:p:
- T:\:h:
- T:\:d:p:
More AsyncRAT samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report