MALICIOUS — 6fd169d4334e898fb7c6697dc4901a952ec0ae86870dae3f4dae80289b2ee480
MALICIOUS — 6fd169d4334e898fb7c6697dc4901a952ec0ae86870dae3f4dae80289b2ee480 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Upantix family. 6 of 56 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
6fd169d4334e898fb7c6697dc4901a952ec0ae86870dae3f4dae80289b2ee480 - SHA-1:
b00e93233a63007ad4bbc3f43839fbcecc1a1f26 - MD5:
a8a5665ef5a78f1c06d19827add91098 - imphash:
24b60c57cc33f3e633431b7ad497fda7 - ssdeep:
6144:5dkkkkkkuadkkkkkkuSdkkkkkkuadkkkkkkuRGbadkkkkkkuadkkkkkkuSdkkkkf:5wawSwawRGbawawSwaDW6F - TLSH:
T15251D100327A399CD7609F605524958DA12552C1897D3EEA8B03072D3CB78BBBDE8FB5 - Submitted as: 6fd169d4334e898fb7c6697dc4901a952ec0ae86870dae3f4dae80289b2ee480
- File type: pe · Size: 839227 bytes
- Verdict: malicious (99/100) · Family: Upantix
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Upantix-9886651-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:Turbo Linker
- Microsoft Defender: Trojan:Win32/Upantix.GM!MTB
- Kaspersky (KVRT): HEUR:Packed.Win32.Upantix.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Malware.Upantix-9886651-0 (rule
Win.Malware.Upantix-9886651-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Upantix.GM!MTB (rule
Trojan:Win32/Upantix.GM!MTB) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Packed.Win32.Upantix.gen (rule
HEUR:Packed.Win32.Upantix.gen) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Contacted 11 external host(s) and 9 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: UPX, high-entropy-sections:UPX1, Turbo Linker - static signal, weight 0.25, confidence 0.55
- Dropped 8 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
6871 behavior events · 1 ATT&CK techniques · 8 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- wpad
- d.1.d.1.c.4.2.1.4.9.5.2.6.e.8.b.0.0.0.0.0.0.0.0.0.0.0.0.0.8.e.f.ip6.arpa.
- 76.0.240.10.in-addr.arpa.
- 251.0.0.224.in-addr.arpa.
- 1.0.240.10.in-addr.arpa.
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 252.0.0.224.in-addr.arpa.
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- dns.msftncsi.com
- 209.52.40.23.in-addr.arpa.
- update.googleapis.com
- desktop-hsgcbep
- self.events.data.microsoft.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 1.0.240.10.in-addr.arpa
Dropped files
- C:\Windows\win32dc\Half-Life 2 + fix.exe -
10cb277d75e18254da2a3886dcb65cfd98a772bbef485e5ee7463e31519fc239 - C:\Windows\win32dc\DAoC(cdfix).exe -
1b9c0128da5250cdbe684e1bd2659eea45f040df013a9ee6fb99f2d5982af6fc - C:\Windows\win32dc\DAoC(hack).exe -
dd1e60b99a5ce49a24d47d23f513c1c1f298ef8b0aa3b1a2f9453326796e0aca - C:\Windows\win32dc\FlatOut(hack).exe -
52c503ee7320d5ae65b533f16419ddff3e117f65a53ac5046c170b35acc262e4 - C:\Windows\win32dc\Doom 3(codes).exe -
2c984e310d8856441b0aa1fdaa126255db9f3f4cf31aa1ff8b5e0d0400de10c5 - C:\Windows\win32dc\BattleField 1942(fix).exe -
65d6478bcdd621e7706b80ce07420a649024b1da53205dcd7b369d6ef09f1484 - C:\Windows\win32dc\Doom 3(trainer).exe -
49b802d1157f8580a9e2440cc72c0be7782a3f829e3b7f3fdf1b8ef96ecde9ad - C:\Windows\win32dc\UT2004 crack.exe -
a0c691b138c866fa81f47a387a7d3077584293fac0d55652b58260585964fe4c
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- us.undernet.org
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 172.172.255.216
- 40.84.85.40
- 4.150.223.111
- 4.150.223.105
- 52.148.114.188
- 40.79.167.9
- 51.116.246.106
- 72.145.35.103
- 72.145.35.97
- 72.145.35.99
- 186.233.185.155
- 203.26.79.13
- 74.178.76.44
- 52.230.60.54
- 52.110.12.46
- 4.230.171.124
- 72.145.35.96
File paths
- R:\A[f
More Upantix samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report