MALICIOUS — a54441cfa0cd8efa6e4e489a43cb1d63b1a89d94547523c264f2a5915dcc20f6
MALICIOUS — a54441cfa0cd8efa6e4e489a43cb1d63b1a89d94547523c264f2a5915dcc20f6 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the LightStone family. 8 of 56 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
a54441cfa0cd8efa6e4e489a43cb1d63b1a89d94547523c264f2a5915dcc20f6 - SHA-1:
220405669b21c2ebd518dc8f7609085526de8c08 - MD5:
cc30bceff91c1e6e599c6091584b1189 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
49152:8RshXwDTMk3e7BEBcEaYM6o40ewIWMpKVjXzCCjm:8RshXwPMkbBcELeKIV5m - TLSH:
T1C65CD066C6FA6E77DDFC329C5C33C5EF3AE6A896603C01504B57B43621562A70B3012A - Submitted as: a54441cfa0cd8efa6e4e489a43cb1d63b1a89d94547523c264f2a5915dcc20f6
- File type: pe · Size: 2414080 bytes
- Verdict: malicious (100/100) · Family: LightStone
Detections (8 of 56 engines)
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): Win.Malware.Uztuby-9848412-0
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Backdoor:MSIL/DCRat.D!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Ransom.Prometheus.2
- Trellix Stinger (McAfee): PWS-FDFT!CC30BCEFF91C
- Kaspersky (KVRT): HEUR:Backdoor.MSIL.LightStone.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 16 weighted signals:
- ClamAV (daily) flagged Win.Malware.Uztuby-9848412-0 (rule
Win.Malware.Uztuby-9848412-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Backdoor:MSIL/DCRat.D!MTB (rule
Backdoor:MSIL/DCRat.D!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Ransom.Prometheus.2 (rule
Gen:Variant.Ransom.Prometheus.2) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PWS-FDFT!CC30BCEFF91C (rule
PWS-FDFT!CC30BCEFF91C) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Backdoor.MSIL.LightStone.gen (rule
HEUR:Backdoor.MSIL.LightStone.gen) - engine signal, weight 0.55, confidence 0.85 - 2 behavioral detection(s) across 2 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.43, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Contacted 1 external host(s) and 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1082 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-sections:.text (rule
high-entropy-sections:.text) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.text, Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 4 finding(s) elsewhere in the guest, not attributed to this sample, e.g. RWX/private injected region in SppExtComObj.E (pid 5876) (rule
windows.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
3736 behavior events · 2 ATT&CK techniques · 9 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- a0598939.xsph.ru
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- www.bing.com
- assets.msn.com
- th.bing.com
- fe3cr.delivery.mp.microsoft.com
- settings-win.data.microsoft.com
Dropped files
- f7d0a36d2f80e3034aa11258925dc93a0e623ed0ea2834e254d211af7aad5ee4 -
f7d0a36d2f80e3034aa11258925dc93a0e623ed0ea2834e254d211af7aad5ee4 - 4d95e78bb8e3847805c34450dce2da1f2b9f33cc1412281878b1a31c7db5c7b3 -
4d95e78bb8e3847805c34450dce2da1f2b9f33cc1412281878b1a31c7db5c7b3 - 008e1e685c1bb4d20286551f328cd38834b299f6945e302eadb53afb2ba90a7a -
008e1e685c1bb4d20286551f328cd38834b299f6945e302eadb53afb2ba90a7a - aef52811b74cd4b4e93d4605c117ef4d6bbc3da0284b7f69c055779499cac551 -
aef52811b74cd4b4e93d4605c117ef4d6bbc3da0284b7f69c055779499cac551 - 4ebd803c4d624bf73e81d59d036ccc338d164553c7ad8173fd6d5d63260dac1e -
4ebd803c4d624bf73e81d59d036ccc338d164553c7ad8173fd6d5d63260dac1e - 82b9099ddc88265a18a969f66013f14280dab3ac4a4aabd6476cae98b3a0fb38 -
82b9099ddc88265a18a969f66013f14280dab3ac4a4aabd6476cae98b3a0fb38 - 6101e83a3a6732ce8f69cd82b96830c44333616e7fa7ff6f0db2a57faf0f737d -
6101e83a3a6732ce8f69cd82b96830c44333616e7fa7ff6f0db2a57faf0f737d - 0239a3372936c96852622fdfed8e291c5d9658587d4c9d313aa70d2050d69ecf -
0239a3372936c96852622fdfed8e291c5d9658587d4c9d313aa70d2050d69ecf - 4204d4d7ecd1243f857fcc4e40983b6257eee4207586d1f3250fa68aaaa69e65 -
4204d4d7ecd1243f857fcc4e40983b6257eee4207586d1f3250fa68aaaa69e65
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://a0598939.xsph.ru/pipeHttpUpdategame.php?tDnzzFVKSprnyxcaqcm82SVEF=sjSJjddtUB3QwltK3ShJ7TNev7bS3&sit4Xv2IFOJFdag=pAPrYCg57YVxYm&a9e4901c96f87409e3de17e86e8f7ede=d68b9c2f0ea45675007ea9ee452167a9&2e833206f835d875a293ef325c79ff70=gZkZ2YyQjMhJTNlNDZ4YjM1MzNmhDZ0UmZwUGNxMWOiN2M1ImZ5Q2Y&tDnzzFVKSprnyxcaqcm82SVEF=sjSJjddtUB3QwltK3ShJ7TNev7bS3&sit4Xv2IFOJFdag=pAPrYCg57YVxYm
Embedded domains
- d.es
- a0598939.xsph.ru
Embedded IP addresses
- 52.168.112.67
- 4.149.160.182
- 52.123.252.220
- 4.230.171.124
- 74.178.240.51
- 40.79.167.9
- 4.247.188.224
- 135.233.95.144
- 172.64.154.167
- 141.8.197.42
- 52.110.12.46
- 52.110.12.55
More LightStone samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report