MALICIOUS — b007ad3f0cc8cc3199cec4351a531c07a3ee3dcec5542ed41bfc9d0f4bf56fc0
MALICIOUS — b007ad3f0cc8cc3199cec4351a531c07a3ee3dcec5542ed41bfc9d0f4bf56fc0 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Vobfus family. 4 of 52 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
b007ad3f0cc8cc3199cec4351a531c07a3ee3dcec5542ed41bfc9d0f4bf56fc0 - SHA-1:
1359ba24909e352abbba21ac3a2e031e2ca3ce57 - MD5:
c8e8ea980c10f1f008accd842bd9b2d8 - imphash:
1000cf882e08f17da2dc5a24f96c3baa - File type: pe · Size: 77824 bytes
- Verdict: malicious (100/100) · Family: Vobfus
Detections (4 of 52 engines)
- ClamAV (daily): Win.Worm.Autorun-440
- Microsoft Defender: Worm:Win32/Vobfus.AC
- Emsisoft (Emergency Kit): Gen:Trojan.Chinky.2
- Kaspersky (KVRT): Worm.Win32.Vobfus.exjr
MITRE ATT&CK
Dynamic analysis (windows)
61195 behavior events · 2 ATT&CK techniques · 4 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ns1.thepicturehut.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- settings-win.data.microsoft.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- tas02.sls.update.microsoft.com
- www.bing.com
- fe3cr.delivery.mp.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/12436/files/618081187920326daa94d9ed8a3218ef4a86dd6b107e5049515a6d9bb48c00ee —
618081187920326daa94d9ed8a3218ef4a86dd6b107e5049515a6d9bb48c00ee - 72d8dbb9d8568b74362e63b2bb8d7b5f0fc78df89f1bab7dce3960ed38c92082 —
72d8dbb9d8568b74362e63b2bb8d7b5f0fc78df89f1bab7dce3960ed38c92082 - 16040446bd5dd23966153ea5ea371089a41b0122141e939ecc263a522716fad6 —
16040446bd5dd23966153ea5ea371089a41b0122141e939ecc263a522716fad6 - 76209128f02c85ca801e427b0a578436b860076b3a3fcf084afd6a8495a12610 —
76209128f02c85ca801e427b0a578436b860076b3a3fcf084afd6a8495a12610
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786522078&P2=404&P3=2&P4=YcR%2f7CCNZq695Bhs6l9xF86PMeRF%2bnM0ymdwHBGphMk0AHwSrP%2fRvu005jXWyHK0jttzW4F%2biwk0zbhZli%2bwSg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786522154&P2=404&P3=2&P4=lAM1XhIkgDls%2buDm0TZUPLFK%2f9hSEMUwF4hdA2wola4k61h8GX2ucjARl%2bL2Cn6mU7nyGYnyaxw5KJ%2f6%2b8OZwg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- ns1.thepicturehut.net
Embedded IP addresses
- 172.217.25.195
- 4.247.188.224
- 4.150.223.97
- 20.247.184.142
- 4.230.171.124
- 135.232.92.137
- 74.179.77.164
- 20.42.73.26
- 40.79.167.9
- 52.110.12.3
- 135.234.160.246
- 52.110.12.40
- 135.233.95.80
- 203.26.79.13
- 172.178.240.161
- 72.153.5.60
- 52.148.114.188
- 52.110.12.46
- 52.110.12.33
More Vobfus samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report