MALICIOUS — fa67ac137d8d4b6c920c4a9da827039973ea805cf34ed6481b83c75a21f70eaa
MALICIOUS — fa67ac137d8d4b6c920c4a9da827039973ea805cf34ed6481b83c75a21f70eaa is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100). 6 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fa67ac137d8d4b6c920c4a9da827039973ea805cf34ed6481b83c75a21f70eaa - SHA-1:
84e5d65678007e7d1884d2e09aa84aa6cafb3585 - MD5:
fddb8e0352719c801425e1130fcf4f98 - imphash:
3e4757b6c44f364955a909104e3b2b4d - ssdeep:
3072:egwXxL0Uio0G5d89Xxm5Of5QriYljikMTmAcThAkZThMTMz6NZsG0neViuCPGh:sxL0Sh8SCQrisixTmAcThAkZThMTMisG - TLSH:
T17D3E9D1B625FCC5FD3154A673E80CA2E2C83E5CD81B5846042CEE65E482DC3B7B991B6 - Submitted as: fa67ac137d8d4b6c920c4a9da827039973ea805cf34ed6481b83c75a21f70eaa
- File type: pe · Size: 146167 bytes
- Verdict: malicious (97/100)
Detections (6 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Genpack-9875154-0
- Detect It Easy (packer/type): DIE:VMProtect
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): GenPack:Trojan.Agent.EXMP
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Malware.Genpack-9875154-0 (rule
Win.Malware.Genpack-9875154-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 26 external host(s) at runtime (23 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:VMProtect (rule
DIE:VMProtect) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://creativecommons.org/publicdomain/zero/1.0/, https://www.gnu.org/software/automake/manual/automake.html, http://fsmsh.com/2753 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-sections:.lol 1, VMProtect - static signal, weight 0.25, confidence 0.55
- Dropped 83 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Extracted generic config (4 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
25470 behavior events · 0 ATT&CK techniques · 98 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- settings-win.data.microsoft.com
Dropped files
- C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jwebserver.exe -
810586eb6d44a7dcca6ac88cc5b61e669070428f0c60f4c8873c2af4f6d8dd36 - fb9da81483d8cb6a38659fdd8cb72183bead27ad47194cccd1ef16d1e401ad9b -
fb9da81483d8cb6a38659fdd8cb72183bead27ad47194cccd1ef16d1e401ad9b - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-timezone-l1-1-0.dll -
51d4ee80cfb02358bfd2470cf5b844ee638de3f63a3e02cd5f4c90a8b0402db8 - C:\Program Files\desktop.ini -
2e9cbe2ff7e4157140cbf76b50b551a01fa2f2a8c906a5778eacdca569996f23 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jrunscript.exe -
ba536d4b4e0b63f7385c96541e375fd76f2dedc9a7a882838836867514c8e80f - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-sysinfo-l1-1-0.dll -
71e89f91c7c40f622453b1dd8bd9fa261a3e40f29ae62f7323bbc1ee6e35d8db - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jimage.dll -
c4bf13f0b4eedf9c27111b98ca2a91abdae26eeeb7483dc3377694a04892ea6d - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-profile-l1-1-0.dll -
1180af906c609ba4eece5a13f0a8e8ae8bda64bfe476cfdb747101505688c11f - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\lcms.dll -
90fa0c0e3da08f9818bfd3780e9acfea824f3dd682c32b349238318c24f6b424 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\instrument.dll -
80c7d429928c19193e936e640d6cc75a49b14dbd00f34a9a5437bca36fd8d10d - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jsvml.dll -
68acd7e1628f8d77e0b77e23a35eab33dec7030fc511bc7f83b24ff96faaa440 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-crt-time-l1-1-0.dll -
b104672e4feca7beba9bca162cdb5d99d756c64a79d50eda316b1d6acebe71b7 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\java.exe -
24bd4509f300c7cf5b4e3270cd8b244f472198e2cdf5559088f0c419a2e5b960 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jli.dll -
dea07cae905dc9ebd1c59fb446ab129a63cd44e9f995bfa3bf19b2890a2849fc - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\j2pkcs11.dll -
5d86b82311937951f1668674c54fb8e365c526772586c5a8590692bda1fb6f84
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- https://www.gnu.org/software/automake/manual/automake.html
- http://fsmsh.com/2753
- https://autotools.io/index.html
- http://miller.emu.id.au/pmiller/books/rmch/
- http://mozilla.org/MPL/2.0/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787828173&P2=404&P3=2&P4=FN8rEx4cmSsWRzCm3WAWpFOUltjDT00TLGQVDn7ZiI2syMBO%2fNUnMzg%2b8VUVww%2bLu3MhgSMM6kJP4ngDjjPY8A%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787828199&P2=404&P3=2&P4=dG5bnH7QYgXsrxRSdSpWVZN6Kbj8lkC1Yz4mjzZMaL%2fFvZyqohBWIZM%2b2J0dTaDyt1TX4%2fNXIgwMG3sfJgYM7A%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- creativecommons.org
- geocities.com
- www.gnu.org
- fsmsh.com
- autotools.io
- miller.emu.id.au
- mozilla.org
Embedded IP addresses
- 4.150.223.111
- 40.84.97.4
- 4.230.171.124
- 20.247.184.197
- 20.165.94.63
- 20.165.94.54
- 20.42.73.28
- 20.76.201.171
- 52.123.129.14
- 40.99.133.242
- 52.123.128.14
- 20.184.175.3
- 135.234.160.246
- 20.165.94.46
- 203.26.79.13
- 52.148.114.188
- 172.178.240.162
- 72.153.5.138
- 51.11.192.50
- 48.200.63.27
- 52.168.117.168
- 4.247.188.224
- 51.11.192.48
- 40.79.150.123
- 52.110.12.54
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report