MALICIOUS — 5152497c90ce739f9452884d52fd77e9ce273ad5ac20024b5fc4af12e3a56e4a
MALICIOUS — 5152497c90ce739f9452884d52fd77e9ce273ad5ac20024b5fc4af12e3a56e4a is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Upatre family. 7 of 55 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
5152497c90ce739f9452884d52fd77e9ce273ad5ac20024b5fc4af12e3a56e4a - SHA-1:
b259c89076d43ddb956d2df51c5a2be64bebd2f3 - MD5:
bed42f1f3580997929315888f36e1596 - imphash:
17cc0459e1fd2359e9c730258c651d3c - ssdeep:
384:hGjw95yGif6kPYprsQTUohIflAZTg88wGlMRD41nlFSsgA/ou:hGGywkP2sQJ+flW09kD41lF5gAou - TLSH:
T15230DCDD05A90F2BC33614E55632D94F919FF0E1399E36090B8DA07D80C28A39D6AE77 - Submitted as: 5152497c90ce739f9452884d52fd77e9ce273ad5ac20024b5fc4af12e3a56e4a
- File type: pe · Size: 36136 bytes
- Verdict: malicious (99/100) · Family: Upatre
Detections (7 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): MPRESS
- ClamAV (daily): Win.Packed.Upatre-9857150-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:MPRESS
- Microsoft Defender: Trojan:Win32/Zbot.SIBE12!MTB
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Win.Packed.Upatre-9857150-0 (rule
Win.Packed.Upatre-9857150-0) - engine signal, weight 0.90, confidence 0.95 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 24 external host(s) at runtime (21 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:MPRESS (rule
DIE:MPRESS) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: MPRESS - static signal, weight 0.25, confidence 0.55
- Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
13362 behavior events · 2 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- msedge.api.cdp.microsoft.com
- windows.msn.com
- licensing.mp.microsoft.com
- oneocsp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\fcaip.exe -
467992ff786ca8286a64f70b8085465b4afc216a98d6ec7aa05830217ceb0eef
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787930444&P2=404&P3=2&P4=YNZoyFenouCf9crDPrsLUXlUhJ8BPTqNdVlUYB1ij0qV%2bHiuaAkPboANzRcgelny39pdlc3IGtA0%2byfblaL2FA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787930459&P2=404&P3=2&P4=CpMZ3BRsFzre%2fmIQzucnhvwwg7enggb9gTlX0d4kO9uvCbjzpQK1hhZE6A2h3cvLQttLaRiRgOnp0pIozFFv6w%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 4.207.44.75
- 52.253.84.76
- 20.42.179.204
- 4.230.171.124
- 74.178.232.29
- 74.178.76.128
- 52.168.117.169
- 74.178.240.51
- 135.232.92.137
- 203.26.79.13
- 52.123.128.14
- 20.236.44.162
- 40.99.134.2
- 52.123.129.14
- 172.178.240.163
- 20.42.65.91
- 20.42.73.25
- 52.148.114.188
- 135.234.160.244
- 72.145.35.104
- 20.165.94.46
- 172.215.188.232
- 92.223.78.30
- 52.110.12.10
File paths
- C:\2bNrROo7.exe
- C:\7hfNrkO1.exe
- C:\dd3L0nCC.exe
- C:\U8R6E2KM.exe
- C:\yOXbMTfW.exe
- C:\6ykJC1CS.exe
- C:\mV7F6mCP.exe
- C:\JOE5_Pln.exe
- C:\JWM0ir4z.exe
- C:\x9depRSB.exe
- C:\2HNXapBI.exe
- C:\MVS2N3ef.exe
- C:\byXpdz91.exe
- C:\MtsTWgDV.exe
- C:\QQLfuTmU
- C:\087aoGbm.exe
- C:\aa30a10bd5c3d3c268b04aba72af7200def89103765e6f81d1cdcf5f2c2bb3aa
- C:\6d27efe990ce2af964ab21f515859dd61b734460c9d03336285b9348bc7963fe
- C:\3c41ee577048b8b96f981d18b981780883feab41a7d912eeb1f2e1e6dbfad4b5
- C:\1efbbb8e212138a449e07e3bfa53d4b50a4b77342c8ea0210819c06731eaaef4
- C:\488fd456faaa983bde963e591e26648b54c54b6081e78cfab807a3524fc27bbb
- C:\121d52298b17e8ebf0e4bbf74430c004fa9c3e8c21fed9a1b2c153e82410ab68
- C:\e95e49f2087b39d56e601aacbf03851c71399cfd3753cd69e3e7f63300569d9f
- C:\ade82c7ea8dc0783a2ce07738fd5a94ef7c552a62d20db140c1aa3f75468d431
- C:\86b446fb4d1b1bb0de78a1c39771c8e5f14b463c176f073014b23d1279cf63c7
More Upatre samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report