MALICIOUS — 7c3d8b0e78ab44fe9e924f5b72417f42147a4c9c76904c26f4b24490b0023d7f
MALICIOUS — 7c3d8b0e78ab44fe9e924f5b72417f42147a4c9c76904c26f4b24490b0023d7f is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Prepscram family. 6 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
7c3d8b0e78ab44fe9e924f5b72417f42147a4c9c76904c26f4b24490b0023d7f - SHA-1:
5a2754503a54bae266d09c1d1dd2061d03e351df - MD5:
7fa517fc241150879359715f6a20d6ee - imphash:
f1a539a5b71ad53ac586f053145f08ec - ssdeep:
6144:ScwQ++bH4EEN+3rZR3JLN2POUl4KwPMGJ2IEI0:SvQrbH3EgmrAPL23v - TLSH:
T1B84213B1B8468B00F25BBC2546D9F72D9251761B04AA0BA15753CA08EBE9C534CF9E21 - Submitted as: 7c3d8b0e78ab44fe9e924f5b72417f42147a4c9c76904c26f4b24490b0023d7f
- File type: pe · Size: 200408 bytes
- Verdict: malicious (100/100) · Family: Prepscram
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Zusy-9957983-0
- Detect It Easy (packer/type): DIE:UPX
- Microsoft Defender: Trojan:Win32/Prepscram!pz
- Emsisoft (Emergency Kit): Gen:Variant.Rootkit.25
- Kaspersky (KVRT): Trojan.Win32.Agent.neyndy
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Malware.Zusy-9957983-0 (rule
Win.Malware.Zusy-9957983-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Prepscram): CTS.exe - dynamic signal, weight 0.62, confidence 0.90
- 1 behavioral detection(s) across 1 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged Trojan:Win32/Prepscram!pz (rule
Trojan:Win32/Prepscram!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Rootkit.25 (rule
Gen:Variant.Rootkit.25) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Agent.neyndy (rule
Trojan.Win32.Agent.neyndy) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:UPX (rule
DIE:UPX) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 - static signal, weight 0.25, confidence 0.55
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
2438 behavior events · 1 ATT&CK techniques · 21 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- www.bing.com
- assets.msn.com
- fe3cr.delivery.mp.microsoft.com
- settings-win.data.microsoft.com
- v10.events.data.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDriveUpdaterService.exe -
99cf98991b8bd3748ea4557809dfce8c2c48066391f9634d0fc2c2687aba3d09 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\OneDrive.exe -
e307b8d52c85b02bd4374032a31c10a63cee243495f6d35b8a0acc03bf672ed6 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDriveLauncher.exe -
d970216cbd9c01e73f860b9a7cc90f36a9a65ad204678d00e97fc7c902fe7d27 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDrivePatcher.exe -
3470515faa216a07ab0dd1ff727e9528e5c620a949caa1abd067e8ec22c124b2 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\FileCoAuth.exe -
cdf8a55184a2400ae3a06559a2c0a4d59538f4f15035ad004fcca258537b24df - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileCoAuth.exe -
230b2abad99f7af0e8f2826c4b433679191c76c566f9130a008bdfcc2b20acff - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\Microsoft.SharePoint.NativeMessagingClient.exe -
97d60e2b818b7f982678a9a2e4995e8671b62bb67b95e1a3b4089388430273bd - C:\Windows\CTS.exe -
b612d46644d0e4a3829c4d6715f71d979103aa487624805363b36f5b4f92b118 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileSyncHelper.exe -
ad8d499a2d08e0706a35bedcd9c34457cfa4325fb18d216358d78a27c19ba9ac - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\Microsoft.SharePoint.NativeMessagingClient.exe -
49f802fd974423836f5e2ce978e7c01419f83ac4e3fca4ac173a9a1abbdcb737 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe -
150f2ec5de7fcb9b4429d0d477a7cc0863651b456c82881602b01f0af65d60de - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileSyncConfig.exe -
f8fc470061c3847863454c9c01b048d3052b684fbab59d866ca616cce288be86 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\FileSyncConfig.exe -
214a5b5498009a0c5160bf4908938b02fa358f6db29fd2f2610132bded60fe7f - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\OneDrive.App.exe -
0004ec19313247d765b77428d00f0b448d1119c2d81284e839d1185dade4e19e - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDrive.Sync.Service.exe -
dda9ebb9c200d9a487c049a51d75c16f187eca7c8f50b780842ae8f7970ee5c8
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 4.150.223.103
- 20.247.184.142
- 52.123.252.239
- 4.230.171.124
- 20.165.94.54
- 20.42.179.192
- 20.165.94.63
- 4.150.223.104
- 40.79.167.10
- 52.178.17.234
- 52.110.12.25
- 72.154.7.109
- 52.110.12.44
- 52.148.114.188
More Prepscram samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report