MALICIOUS — 6863eea360ec75cb564172f02f4d8fcab8a5b67e5bee57d5c17ff70e904d60c1
MALICIOUS — 6863eea360ec75cb564172f02f4d8fcab8a5b67e5bee57d5c17ff70e904d60c1 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the PWSZbot family. 7 of 56 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
6863eea360ec75cb564172f02f4d8fcab8a5b67e5bee57d5c17ff70e904d60c1 - SHA-1:
b3de940a33208daa0b22b62d1b44ba99fb06d777 - MD5:
c7866f982a98290d315f7c9a0ba5ab4f - imphash:
812f4ca969807d6b225076a40b7e2874 - ssdeep:
768:qS7nh4aQC9xIp/tdgI2MyzNORQtOflIwoHNV2XBFV72B4lA7ZsUI+q:qS7nK8KptdgI2MyzNORQtOflIwoHNV2B - TLSH:
T14E2FC4A81E271303E65E10EAD466890D15FE61F069CC6E498B038DEAD7D04973CE4DB7 - Submitted as: 6863eea360ec75cb564172f02f4d8fcab8a5b67e5bee57d5c17ff70e904d60c1
- File type: pe · Size: 32654 bytes
- Verdict: malicious (100/100) · Family: PWSZbot
Detections (7 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): MPRESS
- ClamAV (daily): Win.Downloader.Upatre-5744087-0
- Detect It Easy (packer/type): DIE:MPRESS
- Microsoft Defender: Trojan:Win32/Downloader!pz
- Emsisoft (Emergency Kit): Trojan.Downloader.JQBF
- Trellix Stinger (McAfee): PWSZbot-FFA!C7866F982A98
- Kaspersky (KVRT): Trojan.Win32.Bublik.beuk
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 16 weighted signals:
- ClamAV (daily) flagged Win.Downloader.Upatre-5744087-0 (rule
Win.Downloader.Upatre-5744087-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 1 finding(s) attributed to the sample across 1 technique(s), e.g. process hollowing in ffengh.exe (pid 7740) (rule
windows.hollowprocesses.HollowProcesses) - memory signal, weight 0.70, confidence 0.85 - Microsoft Defender flagged Trojan:Win32/Downloader!pz (rule
Trojan:Win32/Downloader!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Downloader.JQBF (rule
Trojan.Downloader.JQBF) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PWSZbot-FFA!C7866F982A98 (rule
PWSZbot-FFA!C7866F982A98) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Bublik.beuk (rule
Trojan.Win32.Bublik.beuk) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s) across 1 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 6 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:MPRESS (rule
DIE:MPRESS) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged MPRESS (rule
MPRESS) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: MPRESS - static signal, weight 0.25, confidence 0.55
- Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 4 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
45143 behavior events · 2 ATT&CK techniques · 6 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- drippingstrawberry.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- officeclient.microsoft.com
- www.msn.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- th.bing.com
- edge.microsoft.com
- v10.events.data.microsoft.com
- time.windows.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\ffengh.exe -
1d15d7ed26c614d11fb8a30149041401f55e4c1dafb6b0440503cbd7a27911dc - ab1f1102d8994a313dedaa1cacd8cf0e66c14220dcb8f23693b342c1dcbcc6ff -
ab1f1102d8994a313dedaa1cacd8cf0e66c14220dcb8f23693b342c1dcbcc6ff - 40b698ad703c9adf18bc03b0e7cc805bf7c0b8f3cde12b706257d7dcc5c68a19 -
40b698ad703c9adf18bc03b0e7cc805bf7c0b8f3cde12b706257d7dcc5c68a19 - 4765ef5cd86ecbb7c76fd8234a15e7bf7c5b2d936a001ccc05c59afdffa26a94 -
4765ef5cd86ecbb7c76fd8234a15e7bf7c5b2d936a001ccc05c59afdffa26a94 - 88606063b80658ed69f22c64300b106c18b50ca3ff768244549193956df85130 -
88606063b80658ed69f22c64300b106c18b50ca3ff768244549193956df85130 - 93312eb5b27bb2b26b87abd2bba928518d6c94e3f34de7f10217d62a77bb92a5 -
93312eb5b27bb2b26b87abd2bba928518d6c94e3f34de7f10217d62a77bb92a5
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- drippingstrawberry.com
Embedded IP addresses
- 52.168.117.171
- 4.144.132.114
- 4.230.171.124
- 104.18.33.89
- 20.89.1.12
- 4.150.223.106
- 135.234.160.246
- 52.110.12.32
- 52.110.12.50
- 52.148.114.188
- 72.153.5.139
File paths
- C:\hqXlSFLw.exe
- C:\vwg5uISa.exe
- C:\01uBrAQr.exe
- C:\Users\WI2yhmtI
- C:\Users\Frank\Desktop\IWjMVbQS.exe
- C:\Users\admin\Downloads\9ed34a84ee86428230287ea44f06ac88974098bc2eb650207c930ab2a433d6c7.exe
- C:\Users\Frank\Desktop\OwzRKbJx.exe
- C:\Users\admin\Downloads\3b74ad868b8341b2ae5b18592db450131e129fffff2a0fa5a9fe46ea9742f817.exe
- C:\Users\george\Desktop\ffengh.exe
- C:\Users\admin\Downloads\ffengh.exe
- C:\Users\admin\Downloads\a7d2ace030ad3834625009927505d8a9085b1742505af078855550c20bcb1344.exe
- C:\a529627e01d0ccc84d7656e46d75ed6c734c99f76fbe1fe00026250b38d4ca76
- C:\Users\Frank\Desktop\oWvjQXVV.exe
- C:\Users\admin\Downloads\c0f7e9bdbf38ec781b961d9ff64df32d729aff826837d24a9b8b5d120119c852.exe
- C:\84047ab68631d6728cb57b6c077af51ddbcef85267822843d24aaf6c53cfe60f
- C:\Users\Frank\Desktop\zMDrSIPB.exe
- C:\Users\admin\Downloads\649a00484e60baf060757eeaf396ceddda925c922ff48c419f9b8a58402a78dc.exe
- C:\Users\Lisa\Desktop\BRALSqEv.exe
- C:\76b716e640c64de486f0d54dfcf6228cf04c285150af5d83c08ac91d220883e8
- C:\7c8e84001caa37f9719f955b48ef25954f55eeced6c905816ba3f747bc67de41
More PWSZbot samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report