MALICIOUS — 2998b10e63ca51062d20ed9145b6ffd0f18cce0a4f4404cda2ab2f72c30b1cfd
MALICIOUS — 2998b10e63ca51062d20ed9145b6ffd0f18cce0a4f4404cda2ab2f72c30b1cfd is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Upantix family. 6 of 56 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
2998b10e63ca51062d20ed9145b6ffd0f18cce0a4f4404cda2ab2f72c30b1cfd - SHA-1:
ee32de5ecb988989a5e689156730e8c790251d19 - MD5:
0ae2ab8adf75e26ecbb4456991b04c6f - imphash:
24b60c57cc33f3e633431b7ad497fda7 - ssdeep:
1536:3UUUUUUUUUUHdTD+vvvvvvvvvh+UUUUUUUC9mIkkkkkkTyhhhhhhhMqgAIzCzGV2:blN9RkkkkkkTLqc2Knyi2 - TLSH:
T13D3CE1003636788CC7249FA12524598DA21552C58A7D6DDE9B03072D3CB78FBB8D8FB6 - Submitted as: 2998b10e63ca51062d20ed9145b6ffd0f18cce0a4f4404cda2ab2f72c30b1cfd
- File type: pe · Size: 118139 bytes
- Verdict: malicious (100/100) · Family: Upantix
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Generic-9908425-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:Turbo Linker
- Microsoft Defender: Trojan:Win32/Upantix.GM!MTB
- Kaspersky (KVRT): HEUR:Packed.Win32.Upantix.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Generic-9908425-0 (rule
Win.Trojan.Generic-9908425-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Upantix.GM!MTB (rule
Trojan:Win32/Upantix.GM!MTB) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Packed.Win32.Upantix.gen (rule
HEUR:Packed.Win32.Upantix.gen) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - 1 behavioral detection(s) across 1 rule(s): C2: connection to non-standard port [medium] (rule
tl-c2-rare-port) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 1 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: UPX, high-entropy-sections:UPX1, Turbo Linker - static signal, weight 0.25, confidence 0.55
- Dropped 3 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Memory forensics: 4 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
1381 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- us.undernet.org
- update.googleapis.com
- desktop-hsgcbep
- login.live.com
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- www.bing.com
- assets.msn.com
- edge.microsoft.com
- time.windows.com
- settings-win.data.microsoft.com
Dropped files
- C:\Windows\win32dc\Sims 2_crack.exe -
4434df9186cfcf523f4be8d998fbeefc9fa4120769fdd0d82961e414a44961a9 - C:\Windows\win32dc\Doom 3_codes.exe -
6387168ca413be5a512e6b911d2fec910aae882a0ac15cb6338e6269318bb335 - C:\Windows\win32dc\Quake3_serial.exe -
5f691b08bb5080fc4cd243bbf3dd299f5912aa7749bf89526e679fdbb028d8d6
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- us.undernet.org
Embedded IP addresses
- 4.150.223.109
- 20.247.185.124
- 4.230.171.124
- 199.71.214.87
- 57.155.101.212
- 52.148.114.188
- 72.153.5.133
- 52.110.12.30
- 52.110.12.42
- 20.42.73.24
More Upantix samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report