MALICIOUS — 289805a8bcf2d236b137984ed925ad161b2e7f19234974f658b94a103037e2fe
MALICIOUS — 289805a8bcf2d236b137984ed925ad161b2e7f19234974f658b94a103037e2fe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Unruy family. 8 of 56 detection engines flagged it, exhibiting 7 ATT&CK techniques.
Identification
- SHA-256:
289805a8bcf2d236b137984ed925ad161b2e7f19234974f658b94a103037e2fe - SHA-1:
94563f3d168a1aae8e622391e6cf11cf1fe2eb64 - MD5:
f7503a0109453d031f46b7cf2de5ea2a - imphash:
55fe2519db5cc8102e98db551ca473a5 - ssdeep:
49152:1qYTPZu8JhUTUavDVTyRBpEEtgFA1v1qGe6kq7siQrDH52JdORm5QDXNZPQrBpr:Sog6Dgil4Vy7si4H50ORm5CXTCBh - TLSH:
T17A673BCE461E6720C73BCA312D50A78D9061B1D521B97E2D0E064636389627FFDB236E - Submitted as: 289805a8bcf2d236b137984ed925ad161b2e7f19234974f658b94a103037e2fe
- File type: pe · Size: 6982934 bytes
- Verdict: malicious (100/100) · Family: Unruy
Detections (8 of 56 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- capa (capabilities): capability:credential-access
- ClamAV (daily): Win.Dropper.Unury-7408224-0
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: TrojanDownloader:Win32/Unruy.C
- Emsisoft (Emergency Kit): Gen:Variant.Ser.Jaik.685
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 100/100 is the fusion of 19 weighted signals:
- ClamAV (daily) flagged Win.Dropper.Unury-7408224-0 (rule
Win.Dropper.Unury-7408224-0) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - Microsoft Defender flagged TrojanDownloader:Win32/Unruy.C (rule
TrojanDownloader:Win32/Unruy.C) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Ser.Jaik.685 (rule
Gen:Variant.Ser.Jaik.685) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win32.Generic (rule
HEUR:Trojan.Win32.Generic) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - access stored credentials (rule
access stored credentials) - capa signal, weight 0.50, confidence 0.80 - YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.55, confidence 0.70 - Contacted 1 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- YARA: MalwareAnalyser built-in flagged Windows_Injection_Api_Combo (rule
Windows_Injection_Api_Combo) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:credential-access (rule
capability:credential-access) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: https://www.mendeley.com/library, https://service.elsevier.com/app/answers/detail/a_id/22094/kw/migrate/supporthub/mendeley/, https://crashpad.chromium.org/ - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Dropped 4 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Extracted generic config (5 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. RWX/private injected region in SppExtComObj.E (pid 4676) (rule
windows.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
965 behavior events · 0 ATT&CK techniques · 5 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- licensing.mp.microsoft.com
- th.bing.com
- fe3cr.delivery.mp.microsoft.com
- settings-win.data.microsoft.com
- v10.events.data.microsoft.com
Dropped files
- C:\program files (x86)\Adobe\acrotray .exe -
4a5f71f8e5038f3d6cde0aab63a1df56532e88d1ea248c6b807adf1605fc40f8 - C:\Users\analyst\AppData\Local\microsoft\OneDrive\onedrive.exe -
57d13078d46a1c8f7d815f7ec078cc367fc5e4c40c40119ad98e0603ed830436 - C:\program files (x86)\Adobe\acrotray.exe -
6518bacdb8c39dfe55eef4aa6f04e3fc90bb9f65387b4ddf9fc99b22513a99e2 - C:\program files (x86)\internet explorer\wmpscfgs.exe -
b018452c4615ff87605802d767497ea9ab5d33c61023e2a9ffdc4c6b18e8c6b3 - 7cb6c0820fbe71647ee3f2b0f9507b0ce7cda5ecec2ee8268ed70fd124067ff6 -
7cb6c0820fbe71647ee3f2b0f9507b0ce7cda5ecec2ee8268ed70fd124067ff6
Embedded URLs
- http://www.microsoft.com/exporting
- https://www.mendeley.com/library
- https://service.elsevier.com/app/answers/detail/a_id/22094/kw/migrate/supporthub/mendeley/
- https://nw-umwatson.events.data.microsoft.com/Telemetry.Request
- https://crashpad.chromium.org/
- https://crashpad.chromium.org/bug/new
- http://www.w3.org/2000/xmlns/
- http://www.w3.org/XML/1998/namespace
- http://www.sysinternals.com
- https://cutter.re
- https://github.com/radareorg/cutter/graphs/contributors
- https://cutter.re/docs/user-docs
- https://www.sysinternals.com
- https://watson.telemetry.microsoft.com
- https://www.virustotal.com/about/terms-of-service
- https://www.virustotal.com
- https://clients2.google.com/service/update2/crx
- https://www.virustotal.com/en/about/terms-of-service/
- http://msdn.microsoft.com/en-us/library/aa389231
- http://msdn.microsoft.com/en-us/library/aa384749
- https://msdl.microsoft.com/download/symbols
- http://www.microsoft.com/whdc/devtools/debugging/default.mspx
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
- https://helpx.adobe.com/acrobat/kb/acrobat-failed-load-core-dll.html
- http://msdn.microsoft.com/library/default.asp?url=/library/en-us/ldap/ldap/
Embedded domains
- www.microsoft.com
- www.mendeley.com
- service.elsevier.com
- field.cc
- nw-umwatson.events.data.microsoft.com
- crashpad.chromium.org
- augloop-int.officeppe.com
- registry.cc
- blink.net
- arena.cc
- settings.cc
- zip.cc
- thunks.cc
- thread.cc
- common.cc
- www.w3.org
- crbug.com
- pb.cc
- crash.pb.cc
- www.sysinternals.com
- s.whois-servers.net
- search.in
- github.com
- prj.name
- asm.bytes.space
Embedded IP addresses
- 10.3.4.1
- 5.2.3.5
- 1.101.3.4
- 4.150.223.108
- 52.123.252.234
- 4.230.171.124
- 4.155.94.229
- 135.233.95.135
- 57.154.63.210
- 74.178.240.61
- 104.18.33.89
- 20.184.175.22
- 135.233.45.223
- 52.110.12.20
- 52.110.12.55
- 52.110.12.52
Registry keys
- HKLM\System\CurrentControlSet\Control\Session
- HKEY_CURRENT_USER\Software\Classes
- HKLM\Software\Microsoft\Windows
- hklm\software
- HKLM\System\CurrentControlSet
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
- HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat
- HKEY_LOCAL_MACHINE\Software\Adobe\Adobe
- HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe
- HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Acrobat
- HKEY_USERS\[USER_SID]\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.adobe.acrobat.chrome_webcapture
- HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active
- HKEY_LOCAL_MACHINE\Software\Adobe\
- HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Installer\
- HKEY_CLASSES_ROOT\acrobat2018\DefaultIcon
- HKEY_CLASSES_ROOT\acrobat2018\shell\open\command
- HKEY_CLASSES_ROOT\acrobat2018\shell\open\ddeexec\application
- HKEY_CLASSES_ROOT\acrobat2018
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Edge\NativeMessagingHosts\com.adobe.acrobat.chrome_webcapture
- HKEY_CLASSES_ROOT\Installer\Products\68AB67CA3301FFFF7706B0F070721300\SourceList\Net
- HKEY_LOCAL_MACHINE\Software\WOW6432Node\Adobe\Acrobat
- HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Installer
File paths
- D:\a\1\s\exe\Win32\Release\WinObj.pdb
- c:\long
- D:\SAMSUNG\DeXonPC_Extern\cryptopp_8_2_0\sha_simd.cpp
- D:\SAMSUNG\DeXonPC_Extern\cryptopp_8_2_0\rijndael_simd.cpp
- f:\agent\_work\1\s\exe\Win32\Release\Procmon.pdb
- f:\Agent\_work\22\s\Win32\Release\sigcheck.pdb
- D:\B\T\Acrobat\Viewer\win\EXEs\ViewerExe\ChromeSandboxLaunch.cpp
- D:\B\T\Imports\Open\Chrome\Chrome\src\base\win\win_util.cc
- D:\B\T\Imports\Open\Chrome\Chrome\src\base\file_version_info_win.cc
- D:\B\T\Imports\Open\Chrome\Chrome\src\base\files\file_util_win.cc
- D:\B\T\Imports\Open\Chrome\Chrome\src\chrome\browser\browser_process_impl.cc
- D:\B\T\Imports\Open\Chrome\Chrome\src\sandbox\win\src\win_utils.cc
- D:\B\T\Imports\Open\Chrome\Chrome\src\sandbox\win\src\broker_services.cc
- D:\B\T\Imports\Open\Chrome\Chrome\src\services\service_manager\sandbox\win\sandbox_win.cc
- D:\B\T\Imports\Open\Chrome\Chrome\src\sandbox\win\src\target_process.cc
- D:\B\T\Imports\Open\Chrome\Chrome\src\sandbox\win\src\sandbox_policy_base.cc
- D:\B\T\Imports\Open\Chrome\Chrome\src\sandbox\win\src\filesystem_policy.cc
- D:\B\T\Imports\Open\Chrome\Chrome\src\sandbox\win\src\named_pipe_policy.cc
- D:\B\T\Imports\Open\Chrome\Chrome\src\sandbox\win\src\process_thread_policy.cc
- D:\B\T\Imports\Open\Chrome\Chrome\src\sandbox\win\src\registry_policy.cc
- D:\B\T\Imports\Open\Chrome\Chrome\src\sandbox\win\src\signed_policy.cc
- D:\B\T\Imports\Open\Chrome\Chrome\src\sandbox\win\src\filesystem_dispatcher.cc
- D:\B\T\Imports\Open\Chrome\Chrome\src\sandbox\win\src\named_pipe_dispatcher.cc
- D:\B\T\Imports\Open\Chrome\Chrome\src\sandbox\win\src\process_thread_dispatcher.cc
- D:\B\T\Imports\Open\Chrome\Chrome\src\sandbox\win\src\registry_dispatcher.cc
More Unruy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report