MALICIOUS — 20ccf4376c09e8d1cedaf474efe23cd561b8b5a48f6f360c99e5e587980678ac
MALICIOUS — 20ccf4376c09e8d1cedaf474efe23cd561b8b5a48f6f360c99e5e587980678ac is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Alfonso family. 3 of 55 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
20ccf4376c09e8d1cedaf474efe23cd561b8b5a48f6f360c99e5e587980678ac - SHA-1:
e4736f83cd8fc8199b133ce65e93a9babc4a00ca - MD5:
413d97c2ccf9f9f63fbfc529956d2d53 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
98304:9QWXEAApT8o+Gq6BdJX2z+8HTBrHJWGs2NyqeoNE/7SRYYG:9QW0q6BdJ8tHTVHJack+c - TLSH:
T12263019F5B065882C6DCB850446A2C2DE514D58EE02C03C6D53E9F2BA8E4FFB701DE66 - Submitted as: 20ccf4376c09e8d1cedaf474efe23cd561b8b5a48f6f360c99e5e587980678ac
- File type: pe · Size: 4812288 bytes
- Verdict: malicious (98/100) · Family: Alfonso
Detections (3 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- Microsoft Defender: Trojan:MSIL/AsyncRat.AMBB!MTB
- Kaspersky (KVRT): HEUR:Trojan-Ransom.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 10 weighted signals:
- 3 behavioral detection(s) across 3 rule(s): Credential Access: browser credential store read [high] (rule
tl-browser-credential-access) - dynamic signal, weight 0.66, confidence 0.90 - Microsoft Defender flagged Trojan:MSIL/AsyncRat.AMBB!MTB (rule
Trojan:MSIL/AsyncRat.AMBB!MTB) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan-Ransom.Win32.Generic (rule
HEUR:Trojan-Ransom.Win32.Generic) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 1 external host(s) and 7 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Extracted Alfonso config (0 C2) - engine signal, weight 0.45, confidence 0.60
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-sections:.text (rule
high-entropy-sections:.text) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
- Dropped 2 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
5883 behavior events · 2 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- f0598195.xsph.ru
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
- www.bing.com
- th.bing.com
- watson.events.data.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\nixware_launch.exe -
c094d8ce27f855fb72842c51c239455447ee2c5851c8cb35cd1a235c603f40a8 - C:\Users\analyst\AppData\Local\Temp\Crack nixware.exe -
9ce8f2d8b96211f317fab0495c0e5a99722fbeced59120d7f8bb8decf648a488
Embedded URLs
- http://java.com/download
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://f0598195.xsph.ru/collect.php
Embedded domains
- java.com
- f0598195.xsph.ru
Embedded IP addresses
- 4.144.132.223
- 4.150.223.115
- 4.230.171.124
- 172.215.188.225
- 172.64.154.167
- 162.159.142.9
- 135.234.160.245
- 141.8.197.42
- 4.150.223.96
- 20.42.65.94
- 40.84.97.4
- 72.153.5.60
- 92.223.78.30
- 52.148.114.188
- 52.110.12.40
- 52.110.12.24
File paths
- n:\Z
- Y:\;b
More Alfonso samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report