MALICIOUS — Aurora15Connector.exe
MALICIOUS — Aurora15Connector.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Lazy family. 7 of 56 detection engines flagged it, exhibiting 6 ATT&CK techniques.
Identification
- SHA-256:
7d4d6f3aebf5669bb74d1956530845224f50608e8c3275399f5262015f938990 - SHA-1:
04176f1704bbc826547d6a915d0e4f4491974c32 - MD5:
fc9db92f096364633b811631364ac9fe - imphash:
71415c283d04646269151399de66082d - ssdeep:
98304:NDIN2Mnp+AnPZy9lHDXiSiTi0JEZ+tMMM:hDMnp/PZybjiqUEE - TLSH:
T1796B9CAA062F1173F1F6EC847C1CDADD8560B09A54339B9C4503AE6ED8D1037ADE16E8 - Submitted as: Aurora15Connector.exe
- File type: pe · Size: 10024448 bytes
- Verdict: malicious (100/100) · Family: Lazy
Detections (7 of 56 engines)
- capa (capabilities): capability:execution/powershell
- ClamAV (daily): Win.Malware.Lazy-10060471-0
- YARA: bartblaze: BB_Clipbanker
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Emsisoft (Emergency Kit): Gen:Variant.Yogi.46633
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 20 weighted signals:
- ClamAV (daily) flagged Win.Malware.Lazy-10060471-0 (rule
Win.Malware.Lazy-10060471-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 1 finding(s) attributed to the sample across 1 technique(s), e.g. RWX/private injected region in tsk_d7282ef9a1 (pid 8212) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - YARA: bartblaze flagged BB_Clipbanker (rule
BB_Clipbanker) - engine signal, weight 0.70, confidence 0.70 - Emsisoft (Emergency Kit) flagged Gen:Variant.Yogi.46633 (rule
Gen:Variant.Yogi.46633) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s) across 1 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.50, confidence 0.70 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 1 external host(s) and 6 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082 - dynamic signal, weight 0.40, confidence 0.75
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://ea.com/license, https://aurora15.onlyonemzy.com/, http://127.0.0 - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60 - Extracted generic config (3 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
5565 behavior events · 2 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- aurora15.onlyonemzy.com
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- www.bing.com
- assets.msn.com
- fe3cr.delivery.mp.microsoft.com
- v10.events.data.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Aurora15Connector\Aurora15Connector.ini -
97b81b72a48af808b160377e78a46b631d396d385827f569296cf4d797d61c9f - C:\Users\analyst\AppData\Local\Aurora15Connector\logs\launcher.log -
8cf5c22346002b5fc22b6521f0a383207ea132c4cbe8fd5e27c776b3480686c2
Embedded URLs
- http://ea.com/license
- http://www.w3.org/1999/xhtml
- http://schemas.microsoft.com/win/2004/08/events/event
- https://aurora15.onlyonemzy.com/
- http://www.w3.org/XML/1998/namespace
- http://www.w3.org/2000/xmlns/
- https://go.microsoft.com/fwlink/?linkid=2233907
- http://127.0.0
- http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarygroupsi
- http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlywindowsdevicegrou
- http://schemas.microsoft.com/ws/2008/06/identity/claims/primarygroupsi
- http://schemas.microsoft.com/ws/2008/06/identity/claims/rol
- http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsdevicegrou
- http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsuserclai
- http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nam
- http://www.w3.org/2001/XMLSchem
- http://www.w3.org/2001/XMLSchema#integer6
- http://www.w3.org/2001/XMLSchema#uinteger6
- http://www.w3.org/XML/1998/namespac
- https://aurora15.onlyonemzy.com/fifa15/connect/releases
- https://aurora15.onlyonemzy.com/fifa15/connect/releases/1.0.7/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/Aurora15Connector.ex
- https://aurora15.onlyonemzy.com/fifa15/connect/releases/1.0.7/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/Aurora15Connector.exe?replacement=
- https://cdn.aurora15.onlyonemzy.com/fifa15/connect/client.zi
- https://discord.gg
- https://example.invalid/fifa15/connect/releases/1.0.7/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/Aurora15Connector.ex
Embedded domains
- github.com
- fesl.ea.com
- spring14.gosredirector.ea.com
- ea.com
- www.w3.org
- schemas.microsoft.com
- aurora15.onlyonemzy.com
- go.microsoft.com
- adjacent.in
- discord.gg
- fifasetup.in
- schemas.xmlsoap.org
- cdn.aurora15.onlyonemzy.com
- missing-adjacent.in
- saved.in
- example.invalid
Embedded IP addresses
- 1.1.44.0
- 4.2.1.0
- 5.29.10.5
- 29.19.5.29
- 152.5.29.3
- 5.29.35.5
- 29.37.5.29
- 17.5.29.141
- 1.12.10.1
- 1.9.16.2
- 1.9.16.3
- 3.2.8.1
- 1.101.2.1
- 1.101.3.4
- 203.0.113.1
- 20.184.175.12
- 52.253.84.76
- 52.123.252.226
- 4.230.171.124
- 74.179.77.164
- 135.232.92.137
- 51.132.193.104
- 20.184.175.19
- 57.154.63.210
- 178.214.223.10
File paths
- C:\Users\Natha\Documents\Playground\Aurora15\tools\EA-MITM\out\EA-MITM_x64_Release.pdb
- C:\FIFA
- C:\Other
- C:\Games\FIFA
- C:\Program
- C:\Users\someone\AppData\Local\Aurora15Connector\x.tm
- D:\FIFA
- C:\Aurora\logs
More Lazy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report