MALICIOUS — 6960f8cd5a5a80b0e2c36938d1fad4efbe8b339f07ff42236b05ccba185b0b41
MALICIOUS — 6960f8cd5a5a80b0e2c36938d1fad4efbe8b339f07ff42236b05ccba185b0b41 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100), attributed to the Upatre family. 3 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6960f8cd5a5a80b0e2c36938d1fad4efbe8b339f07ff42236b05ccba185b0b41 - SHA-1:
87348fc74b89b2f5d4ad96717dfe63d6e90bf648 - MD5:
07aab1ac92ea60f4436065a83c941663 - imphash:
b1decad0f067131fff2e76ab43787f60 - ssdeep:
96:QwmYtPvLGau/wAnQWRRUh2CqDxSXv2BPLDxquuA2:ZmYt2dQWRRQw1BPq - TLSH:
T1BB2002CE80AC2B5BC76718BB2632D99EA162B0D605ED705E1D4CC12D40D28A3DD36D73 - Submitted as: 6960f8cd5a5a80b0e2c36938d1fad4efbe8b339f07ff42236b05ccba185b0b41
- File type: pe · Size: 8296 bytes
- Verdict: malicious (88/100) · Family: Upatre
Detections (3 of 55 engines)
- ClamAV (daily): Win.Malware.Upatre-7393915-0
- Microsoft Defender: Trojan:Win32/Zbot.FFH!MTB
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 88/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Malware.Upatre-7393915-0 (rule
Win.Malware.Upatre-7393915-0) - engine signal, weight 0.90, confidence 0.95 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- evedbonline.com
- alamx.com
File paths
- C:\d2b3f321ec7fbba1f310967df41f99b360a7d230a498a3e4781d558816f13294
- C:\1a94d7cb766cd8ff89bbde3132d9aeea77a759c8f9594a5a05a5a5552315fc78
- C:\5912113ec3d977607b86652b50addfdfaf4970d5d3e183819b5b60edf449692f
- C:\066bd690954eec76d44ce5dbe8c751789c9f1238c2cbfbd51118294137f32591
- C:\Users\Lisa\Desktop\rVcfQpiY.exe
- C:\Users\george\Desktop\program.exe
- C:\Users\admin\Downloads\gffos.exe
- C:\Users\george\Desktop\gffos.exe
- C:\Users\r.vult\AppData\Local\Temp\4667d5311e4645cd840e824ba212180e.exe
- C:\859b6cb58483f836af99762f94dbfb3a3a5675de2cfbd50c3a1b96b1258e53d2
- C:\KSj21WOx.exe
- C:\Users\admin\Downloads\aedc6f73ab8488d48ee78bb36eba79e8.exe
- C:\Users\admin\Downloads\8fbe712a314bcae7c8bef062d63d2689dfc1f1aebb5b2985c4c67167a3750dfa.exe
- C:\Users\Frank\Desktop\hRGGHBSo.exe
- C:\Users\r.vult\AppData\Local\Temp\7bd5f3cab47339453e75fe5d5a1ee301.exe
- C:\Users\admin\Downloads\e2a7faf7ca79f766e0779f8e128f542c44c2b2f874714d9ecd6dc6470bbe8e20.exe
- C:\SGT2z8lt.exe
- C:\tE_zGGda.exe
- C:\Users\Frank\Desktop\HHuNgBEb.exe
More Upatre samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report