MALICIOUS — f78702cc70d7c53554c1ad1e239d105dc97bac68fddcb061248d6cedacedc5c9
MALICIOUS — f78702cc70d7c53554c1ad1e239d105dc97bac68fddcb061248d6cedacedc5c9 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the StopCrypt family. 8 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f78702cc70d7c53554c1ad1e239d105dc97bac68fddcb061248d6cedacedc5c9 - SHA-1:
691424d66afc24ba517ce5dc72fb52a8dcc86918 - MD5:
1e5932c14c79fd8da3e44872a340eaee - imphash:
9510c947cc2282bdda1a9b4a47d8d006 - ssdeep:
12288:Mmxe9rQqC8CrnnBwY4pnrOIUlejyMYT5MeSBU9PALYl7P:MzSqUL2VpnrXUleWdtmBcALYR - TLSH:
T1F24DE08D8D1F9F01DDE1EA142803566EE443ECB6A1FDAC88D6E2F05DFAB11638858057 - Submitted as: f78702cc70d7c53554c1ad1e239d105dc97bac68fddcb061248d6cedacedc5c9
- File type: pe · Size: 600576 bytes
- Verdict: malicious (99/100) · Family: StopCrypt
Detections (8 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): Win.Packed.Fragtor-9908420-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:Microsoft Visual C/C++
- Microsoft Defender: Ransom:Win32/StopCrypt.MSK!MTB
- Emsisoft (Emergency Kit): Trojan.Crypt
- Kaspersky (KVRT): UDS:Trojan.Win32.DiskWriter.gen
- Trellix Stinger (McAfee): Lockbit-FSWW!1E5932C14C79
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Win.Packed.Fragtor-9908420-0 (rule
Win.Packed.Fragtor-9908420-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Ransom:Win32/StopCrypt.MSK!MTB (rule
Ransom:Win32/StopCrypt.MSK!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Crypt (rule
Trojan.Crypt) - engine signal, weight 0.55, confidence 0.85 - Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - Contacted 25 external host(s) at runtime (2 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Visual C/C++ (rule
DIE:Microsoft Visual C/C++) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 15.54.17.21 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-sections:.text, Microsoft Visual C/C++ - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
15 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- v10.events.data.microsoft.com
- login.live.com
- settings-win.data.microsoft.com
- v20.events.data.microsoft.com
- desktop-hsgcbep
- fd.api.iris.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- tsfe.trafficshaping.dsp.mp.microsoft.com
- watson.events.data.microsoft.com
- www.bing.com
- http://www.msftconnecttest.com/connecttest.txt
- www.msftconnecttest.com/connecttest.txt
Dropped files
- 0f41ed7e9a26658b12cf766d5a423b3007cd04d6e7acfd33ec87ef9f9a60180f -
0f41ed7e9a26658b12cf766d5a423b3007cd04d6e7acfd33ec87ef9f9a60180f - feeff5c31ff14a0eaa4c9328b70a5720391679f2a6730822532577dcf2ac2096 -
feeff5c31ff14a0eaa4c9328b70a5720391679f2a6730822532577dcf2ac2096 - 34214083ce60696dc171d58c3152856c1a0eb661a4741e22a340bdd52258b130 -
34214083ce60696dc171d58c3152856c1a0eb661a4741e22a340bdd52258b130
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- inference.location.live.net
Embedded IP addresses
- 15.54.17.21
- 23.40.52.85
- 23.40.52.69
- 23.40.52.111
- 20.184.175.4
- 4.247.188.224
- 40.79.167.9
- 52.123.252.218
- 20.247.184.142
- 4.230.171.124
- 48.211.4.16
- 23.40.52.174
- 72.154.7.248
- 52.178.17.235
- 23.221.133.185
- 135.234.160.245
- 52.123.252.193
- 172.178.240.161
- 23.33.238.116
- 52.110.12.8
- 23.33.238.207
- 52.110.12.18
- 23.198.40.44
- 40.126.14.164
- 172.192.176.118
File paths
- C:\geku-cinirogi\yeziyatogacan\ho.pdb
More StopCrypt samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report