MALICIOUS — fd8b094127925088c09ce59830d1d30d6b934bc4d10d249621c494f259d20600
MALICIOUS — fd8b094127925088c09ce59830d1d30d6b934bc4d10d249621c494f259d20600 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Vindor family. 12 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fd8b094127925088c09ce59830d1d30d6b934bc4d10d249621c494f259d20600 - SHA-1:
e0f641e11b50106e915cc8d9ad689a22dbc75d2b - MD5:
bcde1ea966603701526b654d462a0c18 - imphash:
01392ca861cf87b8d28ad9ea90016bb4 - ssdeep:
24576:uTlbt1yIifqFu0RDa0ynSHRpawN3loXVav9MkXCqnstLyUktHIiLycH8b:uT5GqFNDOnwN3zv9MdqnstLet3Lyc - TLSH:
T1205A39CD1105AA51FFB18EE41D1BBA9D1462B0B813FF296C1A42813A51E3C7FFCA6059 - Submitted as: fd8b094127925088c09ce59830d1d30d6b934bc4d10d249621c494f259d20600
- File type: pe · Size: 1996985 bytes
- Verdict: malicious (98/100) · Family: Vindor
Detections (12 of 52 engines)
- capa (capabilities): capability:collection/keylog
- MalwareAnalyser heuristics (entropy/packer): ASPack
- ClamAV (daily): Win.Worm.Vindor-9886047-0
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: Trellix/McAfee ATR: ATR_LockBit_Ransomware
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Worm:Win32/AutoRun!pz
- Emsisoft (Emergency Kit): Gen:Heur.Mint.Autorunner.1
- Trellix Stinger (McAfee): Vindor-FTWO!BCDE1EA96660
- Kaspersky (KVRT): Worm.Win32.AutoRun.vx
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Win.Worm.Vindor-9886047-0 (rule
Win.Worm.Vindor-9886047-0) - engine signal, weight 0.90, confidence 0.95 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - YARA: Trellix/McAfee ATR flagged ATR_LockBit_Ransomware (rule
ATR_LockBit_Ransomware) - engine signal, weight 0.35, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://stackoverflow.com/a/15281070/18475, http://stanislavs.org/stopping-command-line-applications-programatically-with-ctrl-c-events-from-net/, http://www.symauth.com/cps0 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: ASPack, high-entropy-sections:.text, Microsoft Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://www.digicert.com/ssl-cps-repository.htm0
- http://crl3.digicert.com/assured-cs-2011a.crl03
- http://crl4.digicert.com/assured-cs-2011a.crl0
- http://cacerts.digicert.com/DigiCertAssuredIDCodeSigningCA-1.crt0
- http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
- http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
- http://crl.thawte.com/ThawteTimestampingCA.crl0
- http://msdn.microsoft.com/en-us/library/windows/desktop/ms681388
- http://msdn.microsoft.com/en-us/library/windows/desktop/ms681383
- https://gist.github.com/jvshahid/6fb2f91fa7fb1db23599
- http://stackoverflow.com/a/15281070/18475
- http://stanislavs.org/stopping-command-line-applications-programatically-with-ctrl-c-events-from-net/
- http://www.w3.org/2001/XMLSchema-instance
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-cs-g1.crl05
- http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
- http://crl.verisign.com/pca3.crl0
- https://www.verisign.com/cps0
- http://logo.verisign.com/vslogo.gif04
- http://www.symauth.com/cps0
- http://www.symauth.com/rpa04
- http://crl.verisign.com/pca3-g5.crl0
- http://www.symauth.com/cps09
- http://evcs-crl.ws.symantec.com/evcs.crl0
Embedded domains
- schemas.microsoft.com
- www.digicert.com
- cacerts.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- ts-aia.ws.symantec.com
- ts-crl.ws.symantec.com
- crl.thawte.com
- msdn.microsoft.com
- gist.github.com
- stackoverflow.com
- stanislavs.org
- www.w3.org
- shim.app
- shimgenerator.app
- crl.verisign.com
- www.verisign.com
- logo.verisign.com
- www.symauth.com
- evcs-crl.ws.symantec.com
- evcs-aia.ws.symantec.com
- crl.microsoft.com
- www.microsoft.com
- office.microsoft.com
- schemas.datacontract.org
Embedded IP addresses
- 0.8.2.0
- 11.0.07.79
Registry keys
- HKEY_CURRENT_USER\Software\Adobe\Adobe
- HKEY_CURRENT_USER\Software\Adobe\Acrobat
File paths
- c:\borrar\EmptyDll\Release\EmptyDll.pdb
- d:\w7rtm.public.x86fre\internal\strongnamekeys\fake\windows.snk
- X:\:`:d:h:l:p:t:x:
- R:\:d:
- X:\:`:d:h:l:p:t:
- P:\:h:t:
- X:\:@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=
- P:\:
- d:\dbs\el\oc\target\x86\ship\postc2r\x-none\olicenseheartbeat.pdb
- P:\:`:l:p:
- H:\:d:h:p:
- T:\:d:l:t:
More Vindor samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report