MALICIOUS — 4ad3a8df654be8a34847ee298e8ad9fe33879aece1c2c11e01fd9d3e2601c534
MALICIOUS — 4ad3a8df654be8a34847ee298e8ad9fe33879aece1c2c11e01fd9d3e2601c534 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Uztuby family. 6 of 56 detection engines flagged it, exhibiting 6 ATT&CK techniques.
Identification
- SHA-256:
4ad3a8df654be8a34847ee298e8ad9fe33879aece1c2c11e01fd9d3e2601c534 - SHA-1:
f8f68116ac1a59d6d42dfa8a2f44a1e58ba0dd25 - MD5:
909d06a37bc38348a4b0d3b504502035 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
24576:o+OUan3FLgjUmzKsiynroqgXsCX8y1OHUzBytB3pkiKkz1A:Ljs1LXm9EmCMy1aL6iJz1 - TLSH:
T1C359928F092C4732E37581A7067DD1CBE1E370912EE976E40D60A5369443A9B6CB2B37 - Submitted as: 4ad3a8df654be8a34847ee298e8ad9fe33879aece1c2c11e01fd9d3e2601c534
- File type: pe · Size: 1812992 bytes
- Verdict: malicious (100/100) · Family: Uztuby
Detections (6 of 56 engines)
- capa (capabilities): capability:execution/powershell
- ClamAV (daily): Win.Packed.Uztuby-9891175-0
- YARA: ReversingLabs: RL_RedLine_Stealer
- Microsoft Defender: Trojan:MSIL/SpyNoon!atmn
- Emsisoft (Emergency Kit): Trojan.MSIL.Basic.8.Gen
- Kaspersky (KVRT): UDS:Trojan-Spy.MSIL.Stealer.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 16 weighted signals:
- ClamAV (daily) flagged Win.Packed.Uztuby-9891175-0 (rule
Win.Packed.Uztuby-9891175-0) - engine signal, weight 0.90, confidence 0.95 - 2 behavioral detection(s) across 2 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.63, confidence 0.90 - YARA: ReversingLabs flagged RL_RedLine_Stealer (rule
RL_RedLine_Stealer) - engine signal, weight 0.80, confidence 0.70 - Microsoft Defender flagged Trojan:MSIL/SpyNoon!atmn (rule
Trojan:MSIL/SpyNoon!atmn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.MSIL.Basic.8.Gen (rule
Trojan.MSIL.Basic.8.Gen) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:Trojan-Spy.MSIL.Stealer.gen (rule
UDS:Trojan-Spy.MSIL.Stealer.gen) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Contacted 1 external host(s) and 9 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Extracted DCRat config (0 C2) - engine signal, weight 0.45, confidence 0.60
- capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://steamcommunity.com/profiles/ - static signal, weight 0.35, confidence 0.60
- Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
7514 behavior events · 3 ATT&CK techniques · 6 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- fe3cr.delivery.mp.microsoft.com
- th.bing.com
- slscr.update.microsoft.com
- settings-win.data.microsoft.com
Dropped files
- C:\Users\Default User\cc11b995f2a76da408ea6a601e682e64743153ad -
cd7d4d848c51768d6f5e71497f6f62ea9ea30e4ff7e3ce96f0fb64417bd3cfe5 - C:\Users\tladmin\Links\9e8d7a4ca61bd92aff00cc37a7a4d62a2cac998d -
ec8ee8506db72d09367bb5f6644dc4dd691ad636f1e11f4a123896ee7f3d1807 - C:\Users\analyst\AppData\Local\Temp\mDrGTrNGV7 -
707188e772af8798b73de1dfc383d982c0e4e7fbcc18a9cc632a5d75d7c3f20c - C:\Users\analyst\AppData\Local\Temp\MR7hvNs4f6.bat -
4070d2e81ba347cbf246b20947cbf2d6ca3c256ea4b8121521a2cb9eb5ebf4b9 - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc\15578420d58b0158f8bfeb03b6cdeebd1963d4e0 -
571a5fe79d348e8acf0c1aa1f92440f22313287f6aa89b7347c3cf793985b537 - C:\Documents and Settings\24dbde2999530ef5fd907494bc374d663924116c -
d02adb3b197e1b8e97530d2417ab4ceaca16ce72fb7c3e53bfbe28f84f0f2a59
Embedded URLs
- https://steamcommunity.com/profiles/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://188.120.243.11/linepollWpdledownloads.php?M19iN6hHHj=tWiTYTam0e64IOR0MNK8t4fMT0wY&5ea155bda8f1e6fcd0adab73e01e7d3c=929a71901eec3f8f17576a81c70985e4&2a23bef9879f26a7c670fe6efb51cf18=QY0IzNjJDNhJWY1MTNihDN1EjYzQjNmZmZlhzYwIWYxEjY1YDOyUTM&M19iN6hHHj=tWiTYTam0e64IOR0MNK8t4fMT0wY
- http://188.120.243.11/linepollWpdledownloads.php?INYu6ZlTeEgmPEB=zIZc&o0768=Ez8kKaF7FiTK&MNtySHvBG1gxLXVdXby8DgdgdVL=G5gf7i&5ea155bda8f1e6fcd0adab73e01e7d3c=929a71901eec3f8f17576a81c70985e4&2a23bef9879f26a7c670fe6efb51cf18=QY0IzNjJDNhJWY1MTNihDN1EjYzQjNmZmZlhzYwIWYxEjY1YDOyUTM&INYu6ZlTeEgmPEB=zIZc&o0768=Ez8kKaF7FiTK&MNtySHvBG1gxLXVdXby8DgdgdVL=G5gf7i
- http://188.120.243.11/linepollWpdledownloads.php?YdE=LzctCvlE2&IflMqVEea0RQ7qWO8zQYTmmGlF=jTqo1R&5ea155bda8f1e6fcd0adab73e01e7d3c=929a71901eec3f8f17576a81c70985e4&2a23bef9879f26a7c670fe6efb51cf18=QY0IzNjJDNhJWY1MTNihDN1EjYzQjNmZmZlhzYwIWYxEjY1YDOyUTM&YdE=LzctCvlE2&IflMqVEea0RQ7qWO8zQYTmmGlF=jTqo1R
Embedded domains
- steamcommunity.com
Embedded IP addresses
- 20.184.175.9
- 52.230.60.54
- 4.230.171.124
- 135.232.92.97
- 135.233.95.144
- 172.215.188.232
- 4.150.223.102
- 52.168.117.169
- 104.18.33.89
- 135.234.160.245
- 188.120.243.11
- 20.184.175.10
- 4.150.223.109
- 52.148.114.188
- 72.145.35.96
- 52.110.12.56
- 52.110.12.22
Registry keys
- HKEY_CLASSES_ROOT\tdesktop.tg\shell\open\command
More Uztuby samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report