MALICIOUS — 238a2591f8f443e1523d536a10dd42ee2315fb2f1cd3108c9992f8a46ab8286d
MALICIOUS — 238a2591f8f443e1523d536a10dd42ee2315fb2f1cd3108c9992f8a46ab8286d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the PWSZbot family. 8 of 55 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
238a2591f8f443e1523d536a10dd42ee2315fb2f1cd3108c9992f8a46ab8286d - SHA-1:
0ad5287313290cdcb2d485f9b605b5f65ffd41d1 - MD5:
bb5755a853c73782a06308ce62b5bbd2 - imphash:
2eb47895ee25649cf9e79d6e6127836a - ssdeep:
1536:WZFJTafg3hnfq4yyFB1iRT9bPKzvcOZ70AKgs1Dq:2FGgRfqI7 - TLSH:
T1E437BDDD42BC1F26C33A04E51772E95FA19BF0E11DAC75161949603E80C78A3AE22E77 - Submitted as: 238a2591f8f443e1523d536a10dd42ee2315fb2f1cd3108c9992f8a46ab8286d
- File type: pe · Size: 72644 bytes
- Verdict: malicious (100/100) · Family: PWSZbot
Detections (8 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): Windows Authenticode
- ClamAV (daily): Win.Malware.Bublik-9948473-0
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:Windows Authenticode
- Microsoft Defender: PWS:Win32/Zbot.AF!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Ransom.Loki.2724
- Trellix Stinger (McAfee): PWSZbot-FIT!BB5755A853C7
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Win.Malware.Bublik-9948473-0 (rule
Win.Malware.Bublik-9948473-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 3 finding(s), e.g. process hollowing in retro.exe (pid 6372) (rule
windows.hollowprocesses.HollowProcesses) - memory signal, weight 0.70, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 29 external host(s) at runtime (27 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Windows Authenticode (rule
DIE:Windows Authenticode) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Windows Authenticode - static signal, weight 0.25, confidence 0.55
- Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
10809 behavior events · 2 ATT&CK techniques · 6 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- concepthomesuk.com
- bigonheating.com
- groupesorepco.com
- yr.c.lencr.org
- yr2.c.lencr.org
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\retro.exe -
706485e41d2f0bc38dd4099ea890458fb03f4283a65ec9ab6187d13add9f1c14 - 88869fd787e8bc2162ee5ecb1f227cd7f28427e8adaac13faebefdba9112957e -
88869fd787e8bc2162ee5ecb1f227cd7f28427e8adaac13faebefdba9112957e - 36cdf49413aa391d6728511581e5c8cc2a0546f65ec668321075d040794e58da -
36cdf49413aa391d6728511581e5c8cc2a0546f65ec668321075d040794e58da - 79c37a688ffdc3e2705b0ea6ac8e2791d0313a54f84daa719ed480222c2fc92f -
79c37a688ffdc3e2705b0ea6ac8e2791d0313a54f84daa719ed480222c2fc92f - d35862b68b97aee4a71bff61211be876843b119636010e28238ecbc919853d7b -
d35862b68b97aee4a71bff61211be876843b119636010e28238ecbc919853d7b - 0a299d87db5759a738217e1577348d6e6136b7d2969106b41023c6ccd7493b26 -
0a299d87db5759a738217e1577348d6e6136b7d2969106b41023c6ccd7493b26
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787813745&P2=404&P3=2&P4=YAz8pFYSnoc4aRFmt%2foWmqBjkks50oLBM7dIX6LbyL%2fmAzbT%2bdvkm6hn5e4DZT4SaGO3uwsHH4gEwQmJ6S2WrQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787813787&P2=404&P3=2&P4=dYP0HSntPkMZ6R51ci8%2fLXeIACfK3vSN9vbbtKzrDbfvXISOr%2f8lFZfotDGJDFe8LGspa2OwSCA2zbqVuOmMTA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://yr.c.lencr.org/
- http://yr2.c.lencr.org/109.crl
Embedded domains
- concepthomesuk.com
- bigonheating.com
- groupesorepco.com
- x1.c.lencr.org
- yr.c.lencr.org
- yr2.c.lencr.org
Embedded IP addresses
- 4.150.223.98
- 4.230.171.124
- 20.247.185.124
- 85.210.196.11
- 74.178.76.128
- 52.168.117.175
- 135.233.95.135
- 40.104.4.2
- 20.236.44.162
- 52.123.128.14
- 52.123.129.14
- 20.42.65.90
- 40.84.97.4
- 203.26.79.13
- 135.233.45.221
- 74.179.71.159
- 46.32.240.37
- 135.234.160.246
- 52.148.114.188
- 52.110.12.42
- 4.150.223.110
- 20.42.65.84
- 125.56.205.32
- 125.56.205.57
- 72.153.5.61
File paths
- C:\66799e92d92e661
- C:\Users\Lisa\Desktop\0VuTYzZe.exe
- C:\b50b3f82a63cb22e0daa83a0be40d7827301d502652c94b198f4d5ea3f7a7c49
- C:\Users\Lisa\Desktop\fNpaslUQ.exe
- C:\997872bc0a5669f3ec39561b305d8c4c3eb1723a9aba47eb049e4968d338b4eb
- C:\FN1DqXoh.exe
- C:\56b021621d3d11c024e04464372b9f698100f2f9611886a3e90907af40817756
- C:\9eb5ee606e4365ba82dc2dc50848b815d176eae8e809d9d87307a02261a7a01b
- C:\Documents
- C:\5faf31f47613880612b6a7d37fc86e2766237027f236543b1801b52fd5d5b3c3
- C:\Users\Lisa\Desktop\Y7OCm8AC.exe
- C:\jP0KQx_D.exe
- C:\d40f9a6dc6b05f43edbb3f1808fdcb0a2f2506141416c141df55cec56825e55c
- C:\f5d6fd5afdc44c6d553ea721bc3ced0c5baedb36381618b63dd15731eaa6933d
- C:\3a06be49a19e1e4d28703768c42fadce616eec9f0d093737bdded61a66fe4ab6
- C:\f1004ab8df274481cf58e4687e3bbd7b27649b59920756b460942d127d23236c
- C:\guMPq4bR.exe
- C:\9d5cd452687917c34c8ab7e28d23684647a9de4f88b1b5184313879fb1619e2d
- C:\b33b4e49d76dcb0903a5fc84033fba5d239807df5bf5672311c24f95b7851364
- C:\ZyIcY4bY.exe
- C:\79e2ffb3dbde0e4b1e291503cadb38ef3d42174ddcf21a4f2cdbc880a0fd8830
- C:\j2NxJiFs.exe
- C:\db0ce11af3ac948bc982a648dbe57ac9fb3ab1b60da452e38dd1379d20383fbb
- C:\DwjW1VaO.exe
- C:\a7f87530943ab3b8851619d9e7ef41ce7bcdb25391b24e896c48328d783f049b
More PWSZbot samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report