MALICIOUS — Aurora15Connector.exe
MALICIOUS — Aurora15Connector.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Lazy family. 7 of 55 detection engines flagged it, exhibiting 7 ATT&CK techniques.
Identification
- SHA-256:
2cba01a2b8c4d45a37e70cdd96dc1eb1570a53c990c1403b08131abf569e4e36 - SHA-1:
00bc456203f50f0877f32f0ff0e6911a33687c32 - MD5:
6fd5d55aff64c959fa849bc40e83560f - imphash:
71415c283d04646269151399de66082d - ssdeep:
98304:3PCUkdXL18pGWdq3UETQNhvfSi9EnLnOnvRBqTLVGN:aUcb18ge6hTQNhvfoOnvXsW - TLSH:
T1516B9CAA062F5173F1F6ED846C2CDADC84A0B09B54339B5C5503AE5EC8D1037ADE16E8 - Submitted as: Aurora15Connector.exe
- File type: pe · Size: 9981440 bytes
- Verdict: malicious (100/100) · Family: Lazy
Detections (7 of 55 engines)
- capa (capabilities): capability:execution/powershell
- ClamAV (daily): Win.Malware.Lazy-10060471-0
- YARA: bartblaze: BB_Clipbanker
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Emsisoft (Emergency Kit): Gen:Variant.Yogi.46633
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 17 weighted signals:
- ClamAV (daily) flagged Win.Malware.Lazy-10060471-0 (rule
Win.Malware.Lazy-10060471-0) - engine signal, weight 0.90, confidence 0.95 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 21 external host(s) at runtime (19 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- YARA: bartblaze flagged BB_Clipbanker (rule
BB_Clipbanker) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://ea.com/license, http://127.0.0.1, http://aurora15.onlyonemzy.com/fifa15/connect/releases/1.0.7/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/Aurora15Connector.ex - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60 - Extracted generic config (3 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
9713 behavior events · 2 ATT&CK techniques · 7 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- aurora15.onlyonemzy.com
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Dropped files
- c:\users\analyst\appdata\local\aurora15connector\updates\update-608305fefd024ea0abeeae0ec1e8906f\operation.owner -
5a017cba7b21203d7d98aa0d0f68a6aaab170e26f2ebb6677bbadfb5ae43a6b7 - C:\Users\analyst\AppData\Local\Aurora15Connector\launcher-update.journal -
ae3bf18a94b6236d2d5e5cf83cec169a450a8ea73e574f7f30b73383625eedbf - c:\users\analyst\appdata\local\aurora15connector\aurora15connector.exe -
b2eef0b7c37208746899eed32f4fb727c59f03ea82ea23e4e47b93bd764d1f99 - c:\users\analyst\appdata\local\aurora15connector\updates\update-608305fefd024ea0abeeae0ec1e8906f\launcher-ceb86ab174ed4eb98b41991898ec4757.ready -
da185bfa669040796751f88cb6e5e116158388b223d16f891bb6154d62bf478f - C:\Users\analyst\AppData\Local\Aurora15Connector\Aurora15Connector.ini -
3d49fe92bfb99eec8ab483963e33e61b5b4bb38f2359907e727420a8fdf5c25e - C:\Users\analyst\AppData\Local\Aurora15Connector\logs\launcher.log -
7fbfd9e6ac9f22e699952d5cbb836bfac5270c3479a5b516c19199c881c75551 - c:\users\analyst\appdata\local\aurora15connector\launcher-managed.state -
dfe467d300e9aaba611fad496308b93ffae2c68e4798e966bf58903c5d7f6012
Embedded URLs
- http://ea.com/license
- http://www.w3.org/1999/xhtml
- http://schemas.microsoft.com/win/2004/08/events/event
- https://aka.ms/GlobalizationInvariantMode
- https://go.microsoft.com/fwlink/?linkid=2233907
- http://www.w3.org/XML/1998/namespace
- http://www.w3.org/2000/xmlns/
- http://127.0.0.1
- http://aurora15.onlyonemzy.com/fifa15/connect/releases/1.0.7/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/Aurora15Connector.ex
- http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarysi
- http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsi
- http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysi
- http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsdeviceclai
- http://schemas.microsoft.com/ws/2008/06/identity/claims/windowssubauthorit
- http://schemas.xmlsoap.org/ws/2005/05/identity/claims/denyonlysi
- http://www.w3.org/2000/xmlns
- http://www.w3.org/2001/XMLSchema#boolea
- http://www.w3.org/2001/XMLSchema#strin
- http://www.w3.org/2003/11/xpath-datatype
- https://aurora15.onlyonemzy.com
- https://aurora15.onlyonemzy.com/fifa15/connect/releases/1.0.7/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/client.zi
- https://aurora15.onlyonemzy.com/fifa15/connect/releases/1.0.8/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/Aurora15Connector.ex
- https://discord.gg/aurorafu
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Embedded domains
- github.com
- fesl.ea.com
- spring14.gosredirector.ea.com
- ea.com
- www.w3.org
- schemas.microsoft.com
- discord.gg
- go.microsoft.com
- adjacent.in
- aurora15.onlyonemzy.co
- fifasetup.in
- aurora15.onlyonemzy.com
- schemas.xmlsoap.org
- missing-saved.in
- saved.in
- aka.ms
Embedded IP addresses
- 1.1.42.0
- 4.2.1.0
- 5.29.10.5
- 29.19.5.29
- 152.5.29.3
- 5.29.35.5
- 29.37.5.29
- 17.5.29.141
- 1.12.10.1
- 1.9.16.2
- 1.9.16.3
- 3.2.8.1
- 1.101.2.1
- 1.101.3.4
- 203.0.113.1
- 4.150.223.109
- 57.155.101.212
- 4.230.171.124
- 20.247.184.197
- 85.210.196.11
- 135.233.95.144
- 74.178.240.51
- 20.42.73.31
- 20.76.201.171
- 52.123.128.14
File paths
- C:\Users\Natha\Documents\Playground\Aurora15\tools\EA-MITM\out\EA-MITM_x64_Release.pdb
- C:\FIFA
- C:\Other
- C:\Games\FIFA
- C:\Program
- C:\Users\someone\AppData\Local\Aurora15Connector\x.tm
- D:\FIFA
- c:\\
More Lazy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report