MALICIOUS — f7a874c61002aa8d23bb89b407ab1a8bd13a22e0fe0bc0deed2ab3b7135a325a
MALICIOUS — f7a874c61002aa8d23bb89b407ab1a8bd13a22e0fe0bc0deed2ab3b7135a325a is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Bladabindi family. 9 of 56 detection engines flagged it, exhibiting 6 ATT&CK techniques.
Identification
- SHA-256:
f7a874c61002aa8d23bb89b407ab1a8bd13a22e0fe0bc0deed2ab3b7135a325a - SHA-1:
8d80e0931a0a34c93105dcf176e03831e4930c95 - MD5:
fec7cc3bea19a3fdfc2a2392b63c0ecd - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
3072:pqS4dwGNlcNO1AdNd+iIyGYhKDj7IqWVdfeLX152AapkUYwA1Ilk:8NGcANdyXrX7IqOp+52hYwAWe - TLSH:
T1D441390AC60E4D27C6BFAE1C257386BFF5C9CD1BE4391915223F32B34422563A53612A - Submitted as: f7a874c61002aa8d23bb89b407ab1a8bd13a22e0fe0bc0deed2ab3b7135a325a
- File type: pe · Size: 181376 bytes
- Verdict: malicious (100/100) · Family: Bladabindi
Detections (9 of 56 engines)
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- ClamAV (daily): Win.Trojan.Bladabindi-9815414-0
- YARA: InQuest Labs: AgentTesla
- Detect It Easy (packer/type): DIE:Microsoft Linker
- LIEF (executable format parser): lief:invalid-authenticode
- Microsoft Defender: Backdoor:MSIL/Bladabindi.AJ
- Emsisoft (Emergency Kit): Gen:Variant.Msilheracles.148494
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 19 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Bladabindi-9815414-0 (rule
Win.Trojan.Bladabindi-9815414-0) - engine signal, weight 0.90, confidence 0.95 - 3 behavioral detection(s) across 3 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.66, confidence 0.90 - YARA: InQuest Labs flagged AgentTesla (rule
AgentTesla) - engine signal, weight 0.70, confidence 0.70 - Microsoft Defender flagged Backdoor:MSIL/Bladabindi.AJ (rule
Backdoor:MSIL/Bladabindi.AJ) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Msilheracles.148494 (rule
Gen:Variant.Msilheracles.148494) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win32.Generic (rule
HEUR:Trojan.Win32.Generic) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 2 external host(s) and 13 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082, T1622, T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged Microsoft Linker (rule
Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
34515 behavior events · 3 ATT&CK techniques · 30 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- ocsp.globalsign.com
- ocsp2.globalsign.com
- crl.globalsign.com
- edge.microsoft.com
Dropped files
- C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\DDA81A73291E20E6ACF6CACA76D5C942_EF9FD27853537FD53F66EAF87CF47D75 -
95d4fbdf40d76e14ab584c41bda10980863c23b6924d9ed07127fd011696f1c3 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\DF8D319B9741B9E1EBE906AACEA5CBBA_8C7B46E5FACDC2A5AD8CBF060924F7CE -
2e5e37bc01105bc9407522d7dc1b5c174e74ba307435c26940afe3fc6b99edbf - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B0B1E3C3B1330A269DBEE4BA6313E7B4 -
9d671644da6cb2f870a9ecf02fe0afe292a61d66f9082cad18acb04680294948 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B0B1E3C3B1330A269DBEE4BA6313E7B4 -
dd12c5733bc4b682e1da6353c8c27650f53d11a8ada8fd8a2d06f23cecae5ebd - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B039FEA45CB4CC4BBACFC013C7C55604_D21903E2722B551F252C717985D24037 -
6754e2d7e64725b1910042b5945fd0bb90cd6067a304bbe7bd08172189ac662a - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_D21903E2722B551F252C717985D24037 -
5e7c2af82a52ed37e56d8839fd8bc7dac67579298378a031bb11d2bc61a71175 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\60B3F7207DEB992031C120EB71F562CD -
54f08bfd73dd3477610059c4a1d92723e698def0efa7ad4661584a51d9aab79b - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\60B3F7207DEB992031C120EB71F562CD -
ded0082e12de795ddb77c555ae3bd372850cd4bca70d6285c73eac6d168ecf33 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0DA515F703BB9B49479E8697ADB0B955_4136D3715888E22D65EBE484B233D81B -
39184eeaf2f86545de57345ce931636757a4ed8c7f20126f29451bbd9d0212e1 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0DA515F703BB9B49479E8697ADB0B955_A026C9CD7BA14377D055F4A2325D4501 -
53390c86042b15be48c9e31c59e90a9d63aed21afb07123ef5f2122621e7efa7 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DDA81A73291E20E6ACF6CACA76D5C942_EF9FD27853537FD53F66EAF87CF47D75 -
bebe2853a3485d1c2e5c5be4249183e0ddaff9f87de71652371700a89d937128 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0DA515F703BB9B49479E8697ADB0B955_A026C9CD7BA14377D055F4A2325D4501 -
30325c181eca01251fdc7a646b81de72852b8ea5e5fdb53617a63a5d2f485db1 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0DA515F703BB9B49479E8697ADB0B955_4136D3715888E22D65EBE484B233D81B -
806a78dbc85578627b91e2b0ce84ff4b6005a9d20d2c69eabf75e565944a650a - 2a8892aaf89274b74badb0acdd469758772f661c37677ba202fcba4e787dad30 -
2a8892aaf89274b74badb0acdd469758772f661c37677ba202fcba4e787dad30 - e68dbc03639a860c53a265c135929b5c8b4f2c29c26d311441a26380a6ae0c33 -
e68dbc03639a860c53a265c135929b5c8b4f2c29c26d311441a26380a6ae0c33
Embedded URLs
- http://ocsp.globalsign.com/rootr103
- http://crl.globalsign.com/root.crl0G
- https://www.globalsign.com/repository/0
- http://ocsp2.globalsign.com/rootr306
- http://crl.globalsign.com/root-r3.crl0b
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
- http://crl.globalsign.com/root.crl0Y
- http://ocsp2.globalsign.com/gscodesigng30V
- http://crl.globalsign.com/gs/gscodesigng3.crl0
- http://www.digicert.com/ssl-cps-repository.htm0
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- ocsp.globalsign.com
- crl.globalsign.com
- www.globalsign.com
- ocsp2.globalsign.com
- crl.microsoft.com
- secure.globalsign.com
- www.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- cacerts.digicert.com
Embedded IP addresses
- 4.150.223.112
- 20.247.184.142
- 4.230.171.124
- 104.18.20.226
- 184.84.165.171
- 184.84.165.136
- 20.42.179.204
- 20.184.175.17
- 20.184.175.9
- 172.178.240.162
- 92.223.78.30
- 72.145.35.97
- 52.148.114.188
- 194.34.132.153
- 52.110.12.30
More Bladabindi samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report