MALICIOUS — the_zeus_binary_chapros
MALICIOUS — the_zeus_binary_chapros is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (85/100), attributed to the Obfuscator family. 4 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
12f38f9be4df1909a1370d77588b74c60b25f65a098a08cf81389c97d3352f82 - SHA-1:
5050b57e01bb2aa9730f826f36ad4d41477d8bd9 - MD5:
3840a6506d9d5c2443687d1cf07e25d0 - imphash:
68f24b9125068c7f6c9d08a606f28a36 - ssdeep:
3072:YOFLCvlWlD+p6mxu6fTUKsFaPzOHTmICX2HONer91BTh+0THw8io:TGWlD+oAu8wsOCJGHONiDM0TLio - TLSH:
T19A43E19263013290F575D2A0FC782DAE15EF10F5DABE53C63DABAE8E19930531E149C8 - Submitted as: the_zeus_binary_chapros
- File type: pe · Size: 227328 bytes
- Verdict: malicious (85/100) · Family: Obfuscator
Detections (4 of 51 engines)
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: VirTool:Win32/Obfuscator.AEC
- Emsisoft (Emergency Kit): Gen:Heur.VIZ.5
MITRE ATT&CK
Why this verdict
The malicious score of 85/100 is the fusion of 6 weighted signals:
- Microsoft Defender flagged VirTool:Win32/Obfuscator.AEC (rule
VirTool:Win32/Obfuscator.AEC) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Heur.VIZ.5 (rule
Gen:Heur.VIZ.5) - engine signal, weight 0.55, confidence 0.85 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (windows)
53 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- bg.microsoft.map.fastly.net
- settings-prod-scus-2-tagged.southcentralus.cloudapp.azure.com
- mr-b02.tm-azurefd.net
- ln-0007.ln-msedge.net
- staging.to-do.officeppe.com
- s-0005.dual-s-msedge.net
- teams.cloud.microsoft
- outlook.office.com
- SYD-efz.ms-acdc.office.com
- outlook.office365.com
- atm.outlook.mira.tm.svc.cloud.microsoft
- outlook.cloud.microsoft
- settings-prod-sea-2-tagged.southeastasia.cloudapp.azure.com
- www.msftconnecttest.com
- onedsblobvmssprdcus04.centralus.cloudapp.azure.com
- onedsblobvmssprdwus03.westus.cloudapp.azure.com
- searchapp.bundleassets.example
- teams-mrc-ww-perf.tm-4.office.com
- www.bing.com
- tas02.sls.update.microsoft.com
Dropped files
- d014ff8fed1365cb5c5ab4aacc91603cd72484a7ff8d81608cd467bdedbb62a1 -
d014ff8fed1365cb5c5ab4aacc91603cd72484a7ff8d81608cd467bdedbb62a1 - 692f289b3d0aba8d703b903f089f7e5f25896c52eae07d9b33d375be19be60b4 -
692f289b3d0aba8d703b903f089f7e5f25896c52eae07d9b33d375be19be60b4 - 8af3b8e59d5e4ecbd6903a761693e7894948535b2d55f090fd5e0f4fce6a92e9 -
8af3b8e59d5e4ecbd6903a761693e7894948535b2d55f090fd5e0f4fce6a92e9
Embedded domains
- glb.sls.prod.dcat.dsp.trafficmanager.net
- mr-b02.tm-azurefd.net
- ln-0007.ln-msedge.net
- staging.to-do.officeppe.com
- s-0005.dual-s-msedge.net
- glb.api.prod.dcat.dsp.trafficmanager.net
Embedded IP addresses
- 23.33.238.109
More Obfuscator samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report