MALICIOUS — 1e447bd1dc992ba893df8b40e2f4d50fae71ec5db144f88115b16129f16d10fa
MALICIOUS — 1e447bd1dc992ba893df8b40e2f4d50fae71ec5db144f88115b16129f16d10fa is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Conteban family. 2 of 56 detection engines flagged it, exhibiting 6 ATT&CK techniques.
Identification
- SHA-256:
1e447bd1dc992ba893df8b40e2f4d50fae71ec5db144f88115b16129f16d10fa - SHA-1:
386985c9046ff65ede49bd86f484024a51caf14f - MD5:
191ece391362f1aa9c4df646a406279b - imphash:
77e21619d22a3b7e86cecb64561a33b5 - ssdeep:
98304:Lxbl3s/CB8awSWKUKYwZuhrfsjbGl8AHXIBLiDgWNL7WlGrAwgbGYodLdW34HIQ:1FyUlwSWKt7Z4fsml8PoDgyWQkbUdLoK - TLSH:
T1E56633DC9426BCC1DEFDE5E18C64CE2F818514E1AA3D201DE48B640EDDE3873A571A62 - Submitted as: 1e447bd1dc992ba893df8b40e2f4d50fae71ec5db144f88115b16129f16d10fa
- File type: pe · Size: 6288997 bytes
- Verdict: malicious (97/100) · Family: Conteban
Detections (2 of 56 engines)
- Microsoft Defender: Trojan:Win32/Conteban.A!ml
- Kaspersky (KVRT): not-a-virus:UDS:RiskTool.Win32.Qhost.vc
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 10 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Conteban.A!ml (rule
Trojan:Win32/Conteban.A!ml) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged not-a-virus:UDS:RiskTool.Win32.Qhost.vc (rule
not-a-virus:UDS:RiskTool.Win32.Qhost.vc) - engine signal, weight 0.55, confidence 0.85 - 2 behavioral detection(s) across 2 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.43, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 2 external host(s) and 19 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082, T1622, T1497.001, T1497 - dynamic signal, weight 0.40, confidence 0.75
- Embedded network infrastructure: http://nsis.sf.net/NSIS_Error, http://blackmarble.chrisbelldesigns.com - static signal, weight 0.35, confidence 0.60
- Dropped 8 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
28264 behavior events · 2 ATT&CK techniques · 27 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- nexm.nightenvironment.com
- forums.chrisbelldesigns.com
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- google.com
- ipv6.msftconnecttest.com
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
Dropped files
- C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9C69E496D546F49A980D7350EC49A180 -
e5e96d2482e1e4f0a80ce685ea34d84f3c2bc5df2840a3f0dec384434dbfec05 - C:\Windows\System32\Drivers\etc\hosts -
2d6bdfb341be3a6234b24742377f93aa7c7cfb0d9fd64efa9282c87852e57085 - C:\Users\analyst\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db -
abff7cefa59f344f487437a028d8a95c7407ac1d026e0e232c2e4b10423022b4 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9C69E496D546F49A980D7350EC49A180 -
fea0b5ab9f85935c8e612738e5844e2485065481d607c32e0ff3b6d9fa1bac9d - C:\Users\analyst\AppData\Local\Temp\nsvB66.tmp\System.dll -
ecff54a59e546d13f92221aa49d90127f0eb301565abee3e22177ea54eb36e73 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05DDC6AA91765AACACDB0A5F96DF8199 -
a6f8f5d4ffd1e825ffce9a55861f16aa4dbe67871b1696b976194dd8be1fdf29 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75A092F4522006A97542D6AC4F4E69D2 -
c139c526367c8bb45a988882193a90009ee7b1e7c95f4c609b34721b8a0dda06 - C:\Users\analyst\AppData\Local\Temp\nsvB66.tmp\Math.dll -
a8d94f24b0910d5eab1b8208769208d0948b0049541c5e94a0f22697c3bfaded - C:\Users\analyst\AppData\Local\Temp\nsvB66.tmp\background_small.ole -
7107595f6c37c48a122f3406f76b9ea0f34fd69297492a59483c0dcf67b5b5a4 - C:\Users\analyst\AppData\Local\Microsoft\Windows\Explorer\thumbcache_48.db -
d3c9d1ff7b54b653c6a1125cac49f52070338a2dd271817bba8853e99c0f33a9 - C:\Users\analyst\AppData\Local\Temp\nsvB66.tmp\background.ole -
82802ecc3920fb27eeefb70ea5327fe38c8661eaf67cf8099fb6864b163b7fc0 - C:\Users\analyst\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db -
7f4e824fc48443e0eba51bc4f486297952ee474067140ad9cb51ef51d4742e6d - C:\Users\analyst\AppData\Local\Temp\nsvB66.tmp\UserInfo.dll -
2a9e79bc62826d177a067c546e172002ef6be5d69745a82ae8a220fe399abcdc - C:\Users\analyst\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db -
0fa91f33953e87297463c2ac0daa45cd4b8a150842286ca207b0b837f2bb2419 - C:\Users\analyst\AppData\Local\Temp\nsvB66.tmp\GraphicalInstaller.dll -
797972483c2fce68f900c3e365ac70f4f4e2fbf3415c79895b851d255cb8d86d
Embedded URLs
- http://nsis.sf.net/NSIS_Error
- http://blackmarble.chrisbelldesigns.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- http://c.pki.goog/wr2/oBFYYahzgVI.crl
Embedded domains
- e.no
- p.ch
- zz.su
- nsis.sf.net
- blackmarble.chrisbelldesigns.com
- nexm.nightenvironment.com
- forums.chrisbelldesigns.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 20.184.175.10
- 4.230.171.124
- 4.155.90.37
- 57.155.101.212
- 74.179.77.164
- 13.89.179.15
- 74.178.240.61
- 172.215.188.225
- 172.64.154.167
- 52.110.12.26
- 52.110.12.3
- 92.223.78.30
- 20.184.175.6
- 4.150.223.108
- 52.148.114.188
- 72.154.7.17
- 52.110.12.14
- 52.110.12.45
More Conteban samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report