MALICIOUS — bf4c180bbd8d5c6e2fa9be06f0ef1c0770a8a9f519cee7d77b286ae6cab4ecd1
MALICIOUS — bf4c180bbd8d5c6e2fa9be06f0ef1c0770a8a9f519cee7d77b286ae6cab4ecd1 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Vobfus family. 4 of 52 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
bf4c180bbd8d5c6e2fa9be06f0ef1c0770a8a9f519cee7d77b286ae6cab4ecd1 - SHA-1:
bcb4be37e2c911ab4c0ba042220116ba9acaa67c - MD5:
1da8555fee48604b0d6b043f924ce97c - imphash:
1000cf882e08f17da2dc5a24f96c3baa - File type: pe · Size: 77824 bytes
- Verdict: malicious (100/100) · Family: Vobfus
Detections (4 of 52 engines)
- ClamAV (daily): Win.Worm.Autorun-440
- Kaspersky (KVRT): Worm.Win32.Vobfus.exjr
- Microsoft Defender: Worm:Win32/Vobfus.AC
- Emsisoft (Emergency Kit): Gen:Trojan.Chinky.2
MITRE ATT&CK
Dynamic analysis (windows)
62286 behavior events · 2 ATT&CK techniques · 4 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ns3.thepicturehut.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- www.bing.com
- assets.msn.com
- licensing.mp.microsoft.com
- tas02.sls.update.microsoft.com
- fe3cr.delivery.mp.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/12246/files/956c4745b8dd9b27442902ba3e84289d079fd07eae0fa38920fa74ffc9919a56 —
956c4745b8dd9b27442902ba3e84289d079fd07eae0fa38920fa74ffc9919a56 - adc35b65bf55608e51cc2c54aefa148f8cb34f337e6b5ed5706ada8e14b86a78 —
adc35b65bf55608e51cc2c54aefa148f8cb34f337e6b5ed5706ada8e14b86a78 - f5879e09ecc8b17dfeabdcfc034cd6a067b1d6df136116fb4f24c8359575916a —
f5879e09ecc8b17dfeabdcfc034cd6a067b1d6df136116fb4f24c8359575916a - 8cd4a8335357208ec1f86bc333bf3ef2adc68d1c382880038931a9eb32070bfd —
8cd4a8335357208ec1f86bc333bf3ef2adc68d1c382880038931a9eb32070bfd
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786516041&P2=404&P3=2&P4=UdCK7YERpyhtQYVW6o27CPQoDaHfo2oLe1nVT9iTqvDST3zlv%2b9l%2fpSHZ5tHSUc63DRT0gvcOCYuuNCQLETR4w%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786516103&P2=404&P3=2&P4=G01dF24dn1vTyLooroPsNlXMd6vwKocxMNVY60lpY47FG3q%2f8RMc6ljGArd%2fVe91QJxWnt5gXtnLNOZ%2fZ%2b%2fR%2fg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- ns3.thepicturehut.net
Embedded IP addresses
- 52.110.12.1
- 52.110.12.26
- 52.168.117.174
- 52.123.252.224
- 4.230.171.124
- 40.84.97.4
- 4.144.132.114
- 74.179.77.204
- 135.232.92.97
- 20.184.175.12
- 74.178.76.128
- 52.123.252.203
- 74.179.71.159
- 203.26.79.13
- 52.123.252.227
- 135.234.160.246
- 135.234.160.244
- 20.42.73.24
- 40.79.150.120
- 72.154.7.111
- 135.233.95.144
- 52.148.114.188
- 4.247.188.233
- 48.192.143.121
- 52.110.12.10
More Vobfus samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report