SUSPICIOUS — mfc140u.dll
SUSPICIOUS — mfc140u.dll is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100), attributed to the AntiDebug family. 2 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
fc9b1f94752d7080436824b480e83ba1ec930e3f7baa881f4e842b882e715cfc - SHA-1:
8d963d5ffc5cdb75de1e22ab9a82b56ac985a70e - MD5:
90bd2d218dbd4a5532ab13dfe2a43839 - imphash:
7ed052f5d4b4d1c0e67280d5b3c470d7 - ssdeep:
98304:wUon/oeUxcmSmfdqkFLOAkGkzdnEVomFHKnPj:von/7yBFf5FLOyomFHKnPj - TLSH:
T1D5659D050617207AF0F2A964AC8094DCF452FDECA43A59997343DEAC53DEE3778E11A2 - Submitted as: mfc140u.dll
- File type: pe · Size: 5651104 bytes
- Verdict: suspicious (54/100) · Family: AntiDebug
Detections (2 of 55 engines)
- capa (capabilities): capability:collection/keylog
- YARA: Yara-Rules community: YR_AntiDebug_Checks
MITRE ATT&CK
Why this verdict
The suspicious score of 54/100 is the fusion of 3 weighted signals:
- capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
Embedded domains
- www.microsoft.com
- crl.microsoft.com
File paths
- D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\mfc140u.amd64.pdb
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Include\afxwin1.inl
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Include\afxwin2.inl
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\afxstate.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\appcore.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\array_s.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\auxdata.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\dbcore.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\dockcont.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\filecore.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\filetxt.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\oleasmon.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\olecli1.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\oleconn.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\oledrop2.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\olefact.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\oleipfrm.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\olelink.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\olemon.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\olestrm.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\sockcore.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\viewcore.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\viewform.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\winctrl2.cpp
- D:\a\_work\1\s\src\vctools\VC7Libs\Ship\ATLMFC\Src\MFC\winfrm.cpp
More AntiDebug samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report