MALICIOUS — fb8e48f36086d184e3c60d83a9a41d497e15c3a34bb63881f6b93b477da15e7e
MALICIOUS — fb8e48f36086d184e3c60d83a9a41d497e15c3a34bb63881f6b93b477da15e7e is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the DCOM family. 8 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fb8e48f36086d184e3c60d83a9a41d497e15c3a34bb63881f6b93b477da15e7e - SHA-1:
d7a691e2b7bc0bf3d5bc5bad2c8f58ed9b8bdc62 - MD5:
4438ef6e6aab63db13e622c57b09ad4d - imphash:
c4998075f1324ce0f644f12a548d76b1 - ssdeep:
6144:ppMM8EV1ODGD3DBrpMM8EP7X6Wc3mUOiitsyZw9cRCuukhK6ca2JJ4l2H:UxazAIQDitw9zkhDcq2H - TLSH:
T14C4DAD8C51187B05DAB2E9144D14DE5D70A3F4FD22BD2AC81607C13FB1E6ABB987824E - Submitted as: fb8e48f36086d184e3c60d83a9a41d497e15c3a34bb63881f6b93b477da15e7e
- File type: pe · Size: 596764 bytes
- Verdict: malicious (96/100) · Family: DCOM
Detections (8 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:ÒuÛëÔ
- ClamAV (daily): Win.Exploit.DCOM-5
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Exploit:Win32/RpcDcom!pz
- Emsisoft (Emergency Kit): Trojan.Agent.FRPG
- Trellix Stinger (McAfee): Agent-FQX!4438EF6E6AAB
- Kaspersky (KVRT): Virus.Win32.Lamer.kp
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Exploit.DCOM-5 (rule
Win.Exploit.DCOM-5) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: 212.33.237.86 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-sections:ÒuÛëÔ - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/windows0
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
- http://mozilla.org/MPL/2.0/
- http://www.digicert.com/ssl-cps-repository.htm0
- http://crl3.digicert.com/assured-cs-2011a.crl03
- http://crl4.digicert.com/assured-cs-2011a.crl0
- http://cacerts.digicert.com/DigiCertAssuredIDCodeSigningCA-1.crt0
- http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
- http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
- http://crl.thawte.com/ThawteTimestampingCA.crl0
Embedded domains
- www.microsoft.com
- crl.microsoft.com
- mozilla.org
- www.digicert.com
- cacerts.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- ts-aia.ws.symantec.com
- ts-crl.ws.symantec.com
- crl.thawte.com
Embedded IP addresses
- 212.33.237.86
File paths
- C:\Program
- C:\\Program
- C:\\$SysReset\Scratch\csrss.exe
- C:\\ajomgk\bin\execsc.exe
- C:\\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFontCac#\0246845f487e5f33d3564eff578665a3\PresentationFontCache.ni.exe
- f:\dd\wpf\src\windows.snk
- c:\builds\moz2_slave\rel-m-rel-w32_bld-000000000000\build\obj-firefox\dist\include\nsAutoPtr.h
- c:\builds\moz2_slave\rel-m-rel-w32_bld-000000000000\build\obj-firefox\webapprt\win\webapprt-stub.pdb
- X:\:
More DCOM samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report