MALICIOUS — Aurora15Connector.exe
MALICIOUS — Aurora15Connector.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Lazy family. 7 of 56 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
7bff88672ffa8864ed18d1958d04da894c87f628ab5204fa6f92ab2ad0a71a08 - SHA-1:
1097a322ec0d6780bc0899f14dc8e5e36f059fd3 - MD5:
cdff14b9171d868a13ed4c04aa5e4dea - imphash:
71415c283d04646269151399de66082d - ssdeep:
98304:efEC7eHPb39AE5IC1SM/Au0iSios4l23/exm:efd7eD39BaC1n4WA2H - TLSH:
T14E6B8DAA062F6173F1F6ED846C2CDEDD8460B09A54339B9C45039E6DC8D1037ADE16E8 - Submitted as: Aurora15Connector.exe
- File type: pe · Size: 10038272 bytes
- Verdict: malicious (100/100) · Family: Lazy
Detections (7 of 56 engines)
- capa (capabilities): capability:execution/powershell
- ClamAV (daily): Win.Malware.Lazy-10060471-0
- YARA: bartblaze: BB_Clipbanker
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Emsisoft (Emergency Kit): Gen:Variant.Yogi.46633
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Malware.Lazy-10060471-0 (rule
Win.Malware.Lazy-10060471-0) - engine signal, weight 0.90, confidence 0.95 - YARA: bartblaze flagged BB_Clipbanker (rule
BB_Clipbanker) - engine signal, weight 0.70, confidence 0.70 - Emsisoft (Emergency Kit) flagged Gen:Variant.Yogi.46633 (rule
Gen:Variant.Yogi.46633) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.50, confidence 0.70 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://ea.com/license, https://aurora15.onlyonemzy.com/, http://127.0.0.1 - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://ea.com/license
- http://www.w3.org/1999/xhtml
- http://schemas.microsoft.com/win/2004/08/events/event
- https://aurora15.onlyonemzy.com/
- https://aka.ms/GlobalizationInvariantMode
- https://go.microsoft.com/fwlink/?linkid=2233907
- http://127.0.0.1
- http://aurora15.onlyonemzy.com/fifa15/connect/releases/1.0.7/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/Aurora15Connector.ex
- http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarysi
- http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsi
- http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysi
- http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsdeviceclai
- http://schemas.microsoft.com/ws/2008/06/identity/claims/windowssubauthorit
- http://schemas.xmlsoap.org/ws/2005/05/identity/claims/denyonlysi
- http://www.w3.org/2000/xmlns
- http://www.w3.org/2001/XMLSchema#boolea
- http://www.w3.org/2001/XMLSchema#strin
- http://www.w3.org/2003/11/xpath-datatype
- https://aurora15.onlyonemzy.com
- https://aurora15.onlyonemzy.com/fifa15/connect/releases/1.0.7/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/client.zi
- https://aurora15.onlyonemzy.com/fifa15/connect/releases/1.0.8/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/Aurora15Connector.ex
- https://cdn.aurora15.onlyonemzy.com.example.invalid/fifa15/connect/releases/1.0.7/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/Aurora15Connector.ex
- https://cdn.aurora15.onlyonemzy.com/fifa15/connect/releases
- https://cdn.aurora15.onlyonemzy.com/fifa15/connect/releases/1.0.7/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/Aurora15Connector.ex
- https://cdn.aurora15.onlyonemzy.com/fifa15/connect/releases/1.0.7/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/Aurora15ConnectorClient.zi
Embedded domains
- github.com
- fesl.ea.com
- spring14.gosredirector.ea.com
- ea.com
- www.w3.org
- schemas.microsoft.com
- aurora15.onlyonemzy.com
- go.microsoft.com
- adjacent.in
- game.aurora15.onlyonemzy.co
- schemas.xmlsoap.org
- cdn.aurora15.onlyonemzy.com
- discord.gg
- missing-saved.in
- saved.in
- aka.ms
- cdn.aurora15.onlyonemzy.com.example.invalid
Embedded IP addresses
- 1.1.46.0
- 4.2.1.0
- 5.29.10.5
- 29.19.5.29
- 152.5.29.3
- 5.29.35.5
- 29.37.5.29
- 17.5.29.141
- 1.12.10.1
- 1.9.16.2
- 1.9.16.3
- 3.2.8.1
- 1.101.2.1
- 1.101.3.4
- 203.0.113.1
File paths
- C:\Users\Natha\Documents\Playground\Aurora15\tools\EA-MITM\out\EA-MITM_x64_Release.pdb
- C:\$
- o:\n
- Z:\Program
- C:\FIFA
- C:\Other
- C:\Games\FIFA
- C:\Program
- C:\Users\someone\AppData\Local\Aurora15Connector\x.tm
- D:\FIFA
More Lazy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report