Advice Request Malware sample that leads to a weird site

Please provide comments and solutions that are helpful to the author of this topic.

Nagisa

Level 7
Thread author
Verified
Jul 19, 2018
341
I was wandering through the Abuse.ch and uploading undetected samples to the Hybrid Analysis. There were one sample that got rated suspicious, I saw it and looked it a bit more about it. Only detection were from APEX. Falcon Sandbox result were not reliable as the file had Anti-VM. When I visited the URL it found, this screen came up.

1613337285358.png


Intezer didn't show much thing either. Thousands of unique genes...

I would like to know what this file is about.



 
Last edited:

struppigel

Moderator
Verified
Staff Member
Well-known
Apr 9, 2020
656
I agree with @McMcbrad here. The file is truncated. The directory entries for import table and IAT point outside of the file.

Edit: The strings point to something Bittorrent related.
.cc is an extension for C source code. I wouldn't be too sure that context.cc was meant as URL. You will find similar strings in the file like main.cc and BtRejectMessage.cc.

bittorrent.png
 
Last edited:

struppigel

Moderator
Verified
Staff Member
Well-known
Apr 9, 2020
656
VT only extracted the string "context.cc" from the body and put it under referring files. That does not mean these files actually communicated with this URL or even meant this as a URL.

content.png


It's more likely vice versa: Someone realised it is a common string in C applications and you can register this as valid URL to generate traffic.
But even that is only speculation and I don't like speculating too much.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top