MALICIOUS — f8f942517d4a40ea43dd592eb5f395773dea7267abd13fbfeeb9c8f8a65dddaa
MALICIOUS — f8f942517d4a40ea43dd592eb5f395773dea7267abd13fbfeeb9c8f8a65dddaa is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Fugrafa family. 6 of 56 detection engines flagged it, exhibiting 6 ATT&CK techniques.
Identification
- SHA-256:
f8f942517d4a40ea43dd592eb5f395773dea7267abd13fbfeeb9c8f8a65dddaa - SHA-1:
741143f9fe702767a9dec3c64c6f877e9c64d57d - MD5:
ab7633da8bdf1b2f1fd11532491df226 - imphash:
84a5c39eb178b6e678403c890a52017c - ssdeep:
1536:GbYUb5NE3yZIp+6HO5J4ggpMFpiKIKEu0dX4YEJ5eiqIpL7OS:GbYUb5QoJ4g+qiQZj6OLKS - TLSH:
T1A03C0CF18518EB5CE5496BE53130FECE9605E6D22456F0C7400DB53838A3837E266AE7 - Submitted as: f8f942517d4a40ea43dd592eb5f395773dea7267abd13fbfeeb9c8f8a65dddaa
- File type: pe · Size: 117941 bytes
- Verdict: malicious (100/100) · Family: Fugrafa
Detections (6 of 56 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Trojan.Fugrafa-9733007-0
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
- Microsoft Defender: Trojan:Win32/Doina!pz
- Emsisoft (Emergency Kit): Trojan.GenericKD.37882935
- Kaspersky (KVRT): Backdoor.Win32.Small.ml
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 15 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Fugrafa-9733007-0 (rule
Win.Trojan.Fugrafa-9733007-0) - engine signal, weight 0.90, confidence 0.95 - YARA: delivr.to detections flagged DLV_Maldoc_VBA_AutoExec (rule
DLV_Maldoc_VBA_AutoExec) - engine signal, weight 0.70, confidence 0.70 - Microsoft Defender flagged Trojan:Win32/Doina!pz (rule
Trojan:Win32/Doina!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.GenericKD.37882935 (rule
Trojan.GenericKD.37882935) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Backdoor.Win32.Small.ml (rule
Backdoor.Win32.Small.ml) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s) across 1 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 2 external host(s) and 42 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082, T1497 - dynamic signal, weight 0.40, confidence 0.75
- capa (capabilities) flagged capability:collection/keylog (rule
capability:collection/keylog) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Dropped 19 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
71905 behavior events · 2 ATT&CK techniques · 20 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- www.ip2location.com
- best-targeted-traffic.com
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- odc.officeapps.live.com
- www.msn.com
- settings-win.data.microsoft.com
- assets.msn.com
- www.bing.com
- licensing.mp.microsoft.com
Dropped files
- C:\Windows\System32\wufggfr.exe -
dd3be3314deafcaa69fe7f8eb785d469d243e1e1e3bafa94055cf1d7c70ca16e - C:\Users\analyst\AppData\Local\Microsoft\Windows\INetCache\IE\XRUA1FHR\install[5].htm -
73f091e944f1a2133646754dd3e5a9480f941987498a5120579e2eb4b5b0d696 - C:\Windows\System32\wsfank.exe -
54dd89f56ee1cd94a8e5a770a1fc3cbebeda12656a0ddbd4c9024f9f1fed0dfe - C:\Windows\System32\wxkihwwfo.exe -
7c5fee0b80e3166cecbfa5c774248d4eeea0d50cd2e509efce174a954f1b06d9 - C:\Windows\System32\wmhgd.exe -
646c345564c6f0ef354ac8c77aa508002ea7adb60cad677c966801ab54cba5e9 - C:\Windows\System32\wbmce.exe -
7587b8349e27fbac609514c9c63201aba49574b534860b6ed6eccfd9698ed33a - C:\Windows\System32\wno.exe -
18666cab9a3e68448356679dd696ca4325b226cfec3c3e6009b79cf6530cd002 - C:\Windows\System32\wfrk.exe -
bd80619172a7a82bec5edbc6e28cf6fb5effc5ec4ff46391737e1f889e705955 - C:\Windows\System32\whmxiwjs.exe -
e8b32dce8e486fd1cf3b45c404618e5d26d0541827f42b0ae4f658cc135f4f4b - C:\Windows\System32\wlhdamd.exe -
04d9c150df35aa44f2dffddc83c95c96d79bb32dc886b467fa089fd678ccf489 - C:\Windows\System32\wvhaehg.exe -
cb5933e4eb8f6117735b193b6933a1995e5537bdcf3845d07bf685901ed45f7f - C:\Windows\System32\wdsfgu.exe -
2ee92890e4fc332c40c0ad042a406634a37c1575ea4b535a7b35566212cef652 - C:\Windows\System32\wxbet.exe -
3fce1e0a5f62d8e7cd1ddc25a66d985cc1b3fe1fb93d63a1a188ac1e41c42062 - C:\Windows\System32\wnccjif.exe -
ee67e1f8ae1a20ae652dfd471f2e1c81d7317e947ddbd32e73fb7e8d80fb38d7 - C:\Windows\System32\wuivq.exe -
d0043355f01103a877ba369f5599f3310e28edfd059f2d3b008652b47a08a243
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://www.ip2location.com/
- http://best-targeted-traffic.com/install.php?unq=22w82623157cgrihgxn&version=1.7&pais=Unknown
- http://best-targeted-traffic.com/install.php?unq=22a826231514vjmajjj&version=1.7&pais=Unknown
- http://best-targeted-traffic.com/install.php?unq=22q826231516jxedyvg&version=1.7&pais=Unknown
- http://best-targeted-traffic.com/install.php?unq=22g826231519klkgmof&version=1.7&pais=Unknown
- http://best-targeted-traffic.com/install.php?unq=22e826231523weetjfv&version=1.7&pais=Unknown
- http://best-targeted-traffic.com/install.php?unq=22x826231526agbceis&version=1.7&pais=Unknown
- http://best-targeted-traffic.com/install.php?unq=22k826231530kmiooeu&version=1.7&pais=Unknown
- http://best-targeted-traffic.com/install.php?unq=22h826231534mkqeyoc&version=1.7&pais=Unknown
- http://best-targeted-traffic.com/install.php?unq=22x826231538ujimwpw&version=1.7&pais=Unknown
- http://best-targeted-traffic.com/install.php?unq=22o826231544tgalbho&version=1.7&pais=Unknown
- http://best-targeted-traffic.com/install.php?unq=22o826231548hvpnoed&version=1.7&pais=Unknown
- http://best-targeted-traffic.com/install.php?unq=22p826231552wijbhai&version=1.7&pais=Unknown
- http://best-targeted-traffic.com/install.php?unq=22k826231557bmqtmxe&version=1.7&pais=Unknown
- http://best-targeted-traffic.com/install.php?unq=22i82623161iqtnjgih&version=1.7&pais=Unknown
- http://best-targeted-traffic.com/install.php?unq=22k82623166pltrctdn&version=1.7&pais=Unknown
- http://best-targeted-traffic.com/install.php?unq=22b826231612fvihwnx&version=1.7&pais=Unknown
- http://best-targeted-traffic.com/install.php?unq=22e826231619pgrpntp&version=1.7&pais=Unknown
Embedded domains
- www.ip2location.com
- best-targeted-traffic.com
Embedded IP addresses
- 4.150.223.101
- 4.230.171.124
- 172.215.188.232
- 20.247.184.197
- 135.232.92.97
- 74.178.240.61
- 4.150.223.109
- 103.224.182.247
- 172.67.71.137
- 135.234.160.247
- 135.233.45.222
- 52.148.114.188
- 72.145.35.111
- 52.110.12.51
- 52.110.12.20
More Fugrafa samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report