MALICIOUS — 69cb6171f3bbfc5bbb6a46911a8e6bcfa6dd29c0bbc105e83b34bbec4ef1a3e1
MALICIOUS — 69cb6171f3bbfc5bbb6a46911a8e6bcfa6dd29c0bbc105e83b34bbec4ef1a3e1 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the QQpass family. 12 of 55 detection engines flagged it, exhibiting 6 ATT&CK techniques.
Identification
- SHA-256:
69cb6171f3bbfc5bbb6a46911a8e6bcfa6dd29c0bbc105e83b34bbec4ef1a3e1 - SHA-1:
255dc0038370103e7a59581415c091dc548fe763 - MD5:
ae3429611a476b6be3bf79ce7294b688 - imphash:
f1a539a5b71ad53ac586f053145f08ec - ssdeep:
24576:Ai9mrnEl/6oTNGKh3RZrkEu8C3XYGQYdWQ1Ud4tU/ny5Ucc5DBS:AE1TQABZU8YYGQaW2UdMkny2c2Y - TLSH:
T17162E5CE412D1719C63ACA312D40A6ADD0B171D12479BD1D0E0B867664E723FFC7A3AA - Submitted as: 69cb6171f3bbfc5bbb6a46911a8e6bcfa6dd29c0bbc105e83b34bbec4ef1a3e1
- File type: pe · Size: 4328805 bytes
- Verdict: malicious (100/100) · Family: QQpass
Detections (12 of 55 engines)
- capa (capabilities): capability:collection/keylog
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Dropper.QQpass-9937642-0
- YARA: bartblaze: BB_Clipbanker
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:Win32/Prepscram!pz
- Emsisoft (Emergency Kit): Gen:Variant.Virus.8
- Kaspersky (KVRT): Trojan.Win32.Agent.neyndy
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 19 weighted signals:
- ClamAV (daily) flagged Win.Dropper.QQpass-9937642-0 (rule
Win.Dropper.QQpass-9937642-0) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 27 external host(s) at runtime (22 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: bartblaze flagged BB_Clipbanker (rule
BB_Clipbanker) - engine signal, weight 0.35, confidence 0.70 - YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - query domain / anti-analysis (rule
query domain / anti-analysis) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: https://www.mendeley.com/library, https://service.elsevier.com/app/answers/detail/a_id/22094/kw/migrate/supporthub/mendeley/, http://support.mendeley.com/customer/portal/articles/227955 - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: UPX, high-entropy-sections:UPX1, Microsoft Linker - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Dropped 15 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Extracted generic config (14 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
2344 behavior events · 1 ATT&CK techniques · 16 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDrive.Sync.Service.exe -
5e817802879809a5f54a248701ef7986a270a1d2bb346d6a0690e7423d3aa4c7 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileSyncConfig.exe -
c8937d58c9bda1f93edb6e66ce82657a0d6a663138f27a2bca5fd2dd3bc15bc4 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe -
6bf4506b25587f21c74d596e426df11b09f6cb080c9651a5957c1c17075b671d - C:\Users\analyst\AppData\Local\Temp\wKzp2eiTGpZEE5v.exe -
3aba9d69f30540ec1b62a6232d7d2b2693e68312da3d754de50bca968374f4b7 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDriveLauncher.exe -
b0645eb37f380c6e54ea95e8dbf9ea8102b01d7da6ab2fe001e96322bbe1bd5f - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\Microsoft.SharePoint.NativeMessagingClient.exe -
6855d31e1a8be41ccad12eea03f5f205904260b966ddb392663030d9e5c54ae9 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\OneDrive.exe -
1b8f840baeff611117d382ce3fd9267c86e3089fbb0565a9be69f7c4b063e294 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDriveActionHelper.exe -
5e795f6b68adb2a442cd17f052be4094b8fb8dbc6a2d649428f355d718f68ccf - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDriveUpdaterService.exe -
a72969c4ad8e9b185ddeccc745d87415ba922042a813733069312413c524f090 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileCoAuth.exe -
d5d01d51dd3babdea19ad74574ad867ccd017f90b122bfcfe717173cf49aa11c - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDriveFileLauncher.exe -
9385b40e91e289dad9cef2bc61e4c1d0b3abbaa8368f8caed716df9dc91551ae - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDrivePatcher.exe -
8f33ae365e441b12e506c438de2cd4a4417218c6ea0d2ffdbd827c4a1ce5df66 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\OneDrive.App.exe -
75b68f3d4faa0e13c244e3d462cfc5a702162b07a0e97fb3d7c68cdd8d0515a9 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileSyncHelper.exe -
0d2ec8f337e74f2c6fd273cf02fbb6addb06c6e677ae6cb73065a5f7a6d6d9e3 - C:\Windows\CTS.exe -
0c17625a902a83bbd63c7fd9280aefc0278882318d4d48ec015fd17da666ec06
Embedded URLs
- http://www.microsoft.com/exporting
- https://www.mendeley.com/library
- https://service.elsevier.com/app/answers/detail/a_id/22094/kw/migrate/supporthub/mendeley/
- http://support.mendeley.com/customer/portal/articles/227955
- http://p.yusukekamiyamane.com/
- https://citationstyles.org
- https://github.com/Juris-M/citeproc-js
- https://plasma.kde.org
- https://www.zotero.org/
- https://rrchnm.org/
- https://www.gmu.edu/
- https://www.elsevier.com/legal/elsevier-website-terms-and-conditions
- https://www.elsevier.com/legal/privacy-policy
- http://citationstyles.org/
- https://github.com/citation-style-language/styles
- https://csl.mendeley.com
- http://creativecommons.org/licenses/by-sa/3.0/
- https://www.mendeley.com/guides?dgcid=Mendeley_Desktop_Help-menu-Help-guides
- https://www.mendeley.com?dgcid=Mendeley_Desktop_Help-menu-website
- https://service.elsevier.com/app/home/supporthub/mendeley/?dgcid=Mendeley_Desktop_Help-menu-FAQ
- https://service.elsevier.com/app/contact/supporthub/mendeley?dgcid=Mendeley_Desktop_Help-menu-Contact-Support
- https://mendeley.com/reference-management/web-importer/#id_1?dgcid=Mendeley_Desktop_Onboarding-Add-Importer
- https://www.mendeley.com/guides/using-citation-editor?dgcid=Mendeley_Desktop_Onboarding-Help-Cite
- https://www.mendeley.com/guides/desktop/04-read-highlight-annotate?dgcid=Mendeley_Desktop_Onboarding-Help-Cite
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- www.microsoft.com
- www.mendeley.com
- service.elsevier.com
- support.mendeley.com
- p.yusukekamiyamane.com
- citationstyles.org
- github.com
- plasma.kde.org
- www.zotero.org
- rrchnm.org
- www.gmu.edu
- www.elsevier.com
- csl.mendeley.com
- creativecommons.org
- mendeley.com
- domain.com
- www.w3.org
- ns.adobe.com
- field.cc
- nw-umwatson.events.data.microsoft.com
- crashpad.chromium.org
- augloop-int.officeppe.com
- registry.cc
- blink.net
- arena.cc
Embedded IP addresses
- 10.3.4.1
- 5.2.3.5
- 1.101.3.4
- 23.02.45.06
- 25.46.62.85
- 27.24.53.59
- 13.89.179.12
- 52.123.252.223
- 4.230.171.124
- 172.215.188.225
- 20.247.185.124
- 74.178.240.61
- 20.184.175.19
- 74.178.240.51
- 52.123.129.14
- 20.236.44.162
- 52.123.128.14
- 52.123.252.218
- 92.223.78.30
- 135.233.45.223
- 203.26.79.13
- 52.123.252.213
- 52.148.114.188
- 52.110.12.16
- 52.110.12.2
Registry keys
- HKLM\System\CurrentControlSet\Control\Session
- HKEY_CURRENT_USER\Software\Classes
- HKEY_LOCAL_MACHINE\Software\Classes
- hklm\software
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
- HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat
- HKEY_LOCAL_MACHINE\Software\Adobe\Adobe
- HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe
- HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Acrobat
- HKEY_USERS\[USER_SID]\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.adobe.acrobat.chrome_webcapture
- HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active
- HKEY_LOCAL_MACHINE\Software\Adobe\
- HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Installer\
- HKEY_CLASSES_ROOT\acrobat2018\DefaultIcon
- HKEY_CLASSES_ROOT\acrobat2018\shell\open\command
- HKEY_CLASSES_ROOT\acrobat2018\shell\open\ddeexec\application
- HKEY_CLASSES_ROOT\acrobat2018
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Edge\NativeMessagingHosts\com.adobe.acrobat.chrome_webcapture
- HKEY_CLASSES_ROOT\Installer\Products\68AB67CA3301FFFF7706B0F070721300\SourceList\Net
- HKEY_LOCAL_MACHINE\Software\WOW6432Node\Adobe\Acrobat
- HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Installer
- HKEY_USERS\[USER_SID]\SOFTWARE\Adobe\Adobe
File paths
- C:\jenkins\workspace\Desktop_Release_Build\src\ui\MainWindow.cpp
- C:\jenkins\workspace\Desktop_Release_Build\src\ui\ImportExportDialogProvider.cpp
- C:\jenkins\workspace\Desktop_Release_Build\src\ui\AnnotationsExportSettingsDialog.cpp
- C:\jenkins\workspace\Desktop_Release_Build\src\ui\FileListEdit.cpp
- C:\jenkins\workspace\Desktop_Release_Build\src\ui\DocumentEditor.cpp
- C:\jenkins\workspace\Desktop_Release_Build\src\ui\JSDataStore.cpp
- C:\jenkins\workspace\Desktop_Release_Build\src\ui\JSNetworkResponse.cpp
- C:\jenkins\workspace\Desktop_Release_Build\src\ui\RecommenderViewPresenter.cpp
- C:\jenkins\workspace\Desktop_Release_Build\src\ui\SearchFilterPresenter.cpp
- C:\jenkins\workspace\Desktop_Release_Build\src\ui\PeopleTextEdit.cpp
- C:\jenkins\workspace\Desktop_Release_Build\src\ui\WebEnginePage.cpp
- c:\buildslave\steam_rel_client_win32\build\src\public\tier1\utlstring.h
- c:\buildslave\steam_rel_client_win32\build\src\common\crypto_textencode.cpp
- c:\buildslave\steam_rel_client_win32\build\src\public\tier1\utlvector.h
- c:\buildslave\steam_rel_client_win32\build\src\common\keypair.cpp
- c:\buildslave\steam_rel_client_win32\build\src\common\crypto_25519_donna.cpp
- D:\SAMSUNG\DeXonPC_Extern\cryptopp_8_2_0\sha_simd.cpp
- D:\SAMSUNG\DeXonPC_Extern\cryptopp_8_2_0\rijndael_simd.cpp
- D:\a\1\s\Win32\Release\du.pdb
- C:\agent\_work\93\s\Win32\Release
- c:\src\Tcpview\Release\Tcpview.pdb
- D:\B\T\Acrobat\Viewer\win\EXEs\ViewerExe\ChromeSandboxLaunch.cpp
- D:\B\T\Imports\Open\Chrome\Chrome\src\base\win\win_util.cc
- D:\B\T\Imports\Open\Chrome\Chrome\src\base\file_version_info_win.cc
- D:\B\T\Imports\Open\Chrome\Chrome\src\base\files\file_util_win.cc
More QQpass samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report