MALICIOUS — Quake3 nocd.exe
MALICIOUS — Quake3 nocd.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Upantix family. 5 of 55 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
741947cd7cf489b82afeb62a4eb151a3e9318457de825e28e2c867d60e31c79b - SHA-1:
b87dd86bca5ebedfd866fdda1e8b48c17dd2d830 - MD5:
f94688aceabdb4b9b88517d61103cace - imphash:
24b60c57cc33f3e633431b7ad497fda7 - ssdeep:
1536:3UUUUUUUUUUHdTD+vvvvvvvvvh+UUUUUUUC9mIkkkkkkTyhhhhhhhMSTZM+9m2O1:blN9RkkkkkkTLSBvyJF - TLSH:
T1463BD040717A388CCB345F611924994C616552C2CA7C3D9B9B030B2D3D778BBB9E8EB6 - Submitted as: Quake3 nocd.exe
- File type: pe · Size: 104556 bytes
- Verdict: malicious (99/100) · Family: Upantix
Detections (5 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Generic-9908425-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Trojan:Win32/Upantix.GM!MTB
- Kaspersky (KVRT): HEUR:Packed.Win32.Upantix.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Generic-9908425-0 (rule
Win.Trojan.Generic-9908425-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (HUILoader): BattleField 1942 cdfix.exe - dynamic signal, weight 0.62, confidence 0.90
- 1 behavioral detection(s): C2: connection to non-standard port [medium] (rule
tl-c2-rare-port) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 26 external host(s) at runtime (23 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
1518 behavior events · 0 ATT&CK techniques · 7 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- us.undernet.org
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- settings-win.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
Dropped files
- C:\Windows\win32dc\BattleField 1942 cdfix.exe -
4ad0a951ef2bf842ced0135e5e24426f4e5f80cbd42532e85b2e90b755176d6e - C:\Windows\win32dc\Doom 3_codes.exe -
25ccfeb75bd592ae62433b07bc3a7c02cbb9e34318ba3b0fb3782ec3dadf9ddb - C:\Windows\win32dc\Doom 3_patch.exe -
915daac836e2ee635c913b64aa7e35333bd42ab10f692242bc9eb0f31fa41777 - C:\Windows\win32dc\Counter-Strike serial.exe -
1330b58f5826e439efdfe32ce8a6ecd1a3d4081c86ead4894d3f09126560cf3e - C:\Windows\win32dc\Quake3 + fix.exe -
ac47dafd491b0199d3cb2f778fa1d014d6cd4f01a9a9d21199735466acb51e15 - C:\Windows\win32dc\BattleField 1942_trainer.exe -
d4505238a1f36b5ac62d5fa642594a1a478cb68a896569e61081be749a51f539 - C:\Windows\win32dc\UT2004 + codes.exe -
66e00a229adacc70a1565427746ebae581675ec53ae336a238c2bcd9aaf4e177
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787652119&P2=404&P3=2&P4=nCzxsoYKmcEWTZubQwQIsj0%2fLm%2bFPbBh%2fhaNhJlerqE2gqtdQLqVofyYhyMYkRsrUNmteuLlBFuxE3tGGyRdiw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787652154&P2=404&P3=2&P4=BYf0D76VNYH3y8OXNf9KutzejPeAG5leXysolglNfU8FKWaY76CMx0J88JYNQZ8JCpjlRHMpgfBEpOa%2fSgbSbw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- us.undernet.org
Embedded IP addresses
- 20.42.65.88
- 20.247.184.142
- 85.210.196.11
- 4.230.171.124
- 74.178.240.61
- 4.150.223.102
- 74.178.76.54
- 20.42.179.204
- 20.76.201.171
- 52.123.128.14
- 52.123.129.14
- 40.99.133.242
- 162.159.142.9
- 172.178.240.161
- 203.26.79.13
- 199.71.214.87
- 52.123.252.216
- 74.179.71.159
- 52.148.114.188
- 52.110.12.40
- 52.110.12.51
- 172.178.240.163
- 48.200.63.27
- 72.145.35.102
- 52.110.12.49
More Upantix samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report