MALICIOUS — 22af2b3c9671b08dbce2d85675da42424a80f694b8089f5a03dc297b80cd3fb8
MALICIOUS — 22af2b3c9671b08dbce2d85675da42424a80f694b8089f5a03dc297b80cd3fb8 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Upatre family. 4 of 55 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
22af2b3c9671b08dbce2d85675da42424a80f694b8089f5a03dc297b80cd3fb8 - SHA-1:
152c1a0e59aff6026e0baa27151a545fa58c018e - MD5:
280bcd58cddbab3682c78a649635dac8 - imphash:
9e1e9b49d57df8a9abb7a9f51fb7e71a - ssdeep:
384:9cd6w+NomiUBQZVoRiCKKtYh2pNvdAajICjDfLAqjC4l6e1j:qIomvQ7oTOUVAaMSEq2WXj - TLSH:
T1CB2A65CE41342B67C33708E61632ED5F2096B0E20AED36191D8DD03E54C2CA7DD66A7A - Submitted as: 22af2b3c9671b08dbce2d85675da42424a80f694b8089f5a03dc297b80cd3fb8
- File type: pe · Size: 20642 bytes
- Verdict: malicious (99/100) · Family: Upatre
Detections (4 of 55 engines)
- ClamAV (daily): Win.Downloader.Upatre-10027952-0
- Microsoft Defender: TrojanDownloader:Win32/Upatre.A
- Emsisoft (Emergency Kit): Trojan.Ppatre.Gen.1
- Kaspersky (KVRT): Trojan-Spy.Win32.Zbot.siyn
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Downloader.Upatre-10027952-0 (rule
Win.Downloader.Upatre-10027952-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 3 finding(s), e.g. process hollowing in lasma.exe (pid 4152) (rule
windows.hollowprocesses.HollowProcesses) - memory signal, weight 0.70, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 28 external host(s) at runtime (28 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
10792 behavior events · 2 ATT&CK techniques · 5 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- tmupi.com
- x2.c.lencr.org
- ye.c.lencr.org
- ye1.c.lencr.org
- partners-gs.com
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\lasma.exe -
c6df4ec3b9517fefedeb6bbb3193f122103c84339c8fd5e3cfb84bde7dace52c - 0eb5469c742d8bf1a21e4f6734722ffc384afff6d1771b6eb8b0c63f5e414383 -
0eb5469c742d8bf1a21e4f6734722ffc384afff6d1771b6eb8b0c63f5e414383 - dfd8782d636fc0f57d723063aacadfd8e48285cd1d9dda72bf92d9019c5429af -
dfd8782d636fc0f57d723063aacadfd8e48285cd1d9dda72bf92d9019c5429af - ba715da334280614f5ba51964bcac0147117bc7ff1327986a258246d0d93f510 -
ba715da334280614f5ba51964bcac0147117bc7ff1327986a258246d0d93f510 - a182574fac2e76fb00c4053f33d3921912ad1c6f616504c9badb238715a2b442 -
a182574fac2e76fb00c4053f33d3921912ad1c6f616504c9badb238715a2b442
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787785851&P2=404&P3=2&P4=LT8iSTjV9CrG73m46H0DFJ23EldSGr%2b03ee3n%2bi2w5hXR2IpEZ3TWYM12c0jYv7Jqis1Asu7IR0qXgh4GvkEpA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://ye1.c.lencr.org/32.crl
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787785939&P2=404&P3=2&P4=SEHAe4dGfGNoDBPTmv%2bK60mnJ8SZEr%2bUDdCpAdm%2bgdt89bMtxHrgAsd8rn3HVn%2bKQTdcvRZqeetIW6mJDGrp%2fw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- tmupi.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- ye1.c.lencr.org
- partners-gs.com
Embedded IP addresses
- 104.208.16.94
- 20.42.179.192
- 4.230.171.124
- 4.144.132.223
- 135.233.95.144
- 51.132.193.104
- 74.178.240.51
- 20.165.94.63
- 20.76.201.171
- 52.123.129.14
- 40.99.134.18
- 52.123.128.14
- 4.150.223.102
- 203.26.79.13
- 172.178.240.163
- 4.247.188.233
- 193.166.255.171
- 52.110.12.2
- 52.110.12.46
- 52.148.114.188
- 135.232.92.34
- 172.178.240.162
- 172.66.2.5
- 72.153.5.132
- 82.197.80.15
File paths
- c:\4q5d9z\ags2rt.exe
- C:\ebf0c2355c23813738af82914fdc36700a589e1c70384b9b28ba0e2b9e44d7d9
- C:\66ea788400400bd7d060e320795ae13829990d9af9c6f3b802b92bf921e4c2f0
- C:\irqMIx7M.exe
- C:\5eed8247a25f031830feabe1c3c3e95d9b3b26071a21f381089d37977c33713f
- C:\82a4beea1f5705bfa329fc38980798c63f2c3bb450c9ccb53e9aa272a82bb9d0
- C:\mdJNm5pb.exe
- C:\lM0EGqJv.exe
- C:\ggSUGdvp.exe
- C:\HXBEVJZo.exe
- C:\xkQidA2h.exe
- C:\ehWUSBwz.exe
- C:\9ecd7c18b15cd3ca1b7cbe9a240d4c6010f068ccca7520655c92cc477a98e304
- C:\Documents
- C:\DOCUME~1\cuckoo\LOCALS~1\Temp\d743eae0def94b27180bb7a38874844c0eb9d335
- C:\60a27c74cddc5085978b088ceb961ac601db83175bbb18246fa9cf43ff2351ec
- C:\552f94d6f0be1799c415b331521a086d737e82282117991393cfcbe9e4e367c4
- C:\7fa203521d23de8e30ee4acb43e5e8e04c0dca3a2fe582c9752f66456b580f7f
- C:\b8c0b222736f6b9667afc87e88b697294c0e62e6ce554419a065b2956334b17a
- C:\uc5kyVpw.exe
- C:\g3KYdM5J.exe
- C:\4AIARkxW.exe
- C:\VqVSVmgx.exe
- C:\f28178a6841dd7957840bab43139cbafa0dfc8f27086aa9c48ee8945e1d96ba4
- C:\3Y5JXi2g.exe
More Upatre samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report