MALICIOUS — 87dd0f1bd6d281e25e7f07384e074c525e7fae972507221c80eb52a628b0497b
MALICIOUS — 87dd0f1bd6d281e25e7f07384e074c525e7fae972507221c80eb52a628b0497b is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Neyndy family. 6 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
87dd0f1bd6d281e25e7f07384e074c525e7fae972507221c80eb52a628b0497b - SHA-1:
971b27b4cdb2b274ec7933cad5b499e9e308247c - MD5:
39d14a1635a812f4607c66e9f23d0051 - imphash:
f1a539a5b71ad53ac586f053145f08ec - ssdeep:
6144:SvOB3foM73V4454wI/rClm1r/bxGpoaQY6+9BKl4:SvmHrVViw181r/bm3t - TLSH:
T142452333E03C7C49D2256C5C6698E1CDD82BEE0A44CEC26B7B72958DA8749E3D8DD901 - Submitted as: 87dd0f1bd6d281e25e7f07384e074c525e7fae972507221c80eb52a628b0497b
- File type: pe · Size: 282119 bytes
- Verdict: malicious (100/100) · Family: Neyndy
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Zusy-9957983-0
- Detect It Easy (packer/type): DIE:UPX
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): Gen:Variant.Rootkit.25
- Kaspersky (KVRT): Trojan.Win32.Agent.neyndy
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Malware.Zusy-9957983-0 (rule
Win.Malware.Zusy-9957983-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Prepscram): CTS.exe - dynamic signal, weight 0.62, confidence 0.90
- 1 behavioral detection(s) across 1 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged flagged (rule
flagged) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Rootkit.25 (rule
Gen:Variant.Rootkit.25) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Agent.neyndy (rule
Trojan.Win32.Agent.neyndy) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 2 external host(s) and 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:UPX (rule
DIE:UPX) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 - static signal, weight 0.25, confidence 0.55
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
2433 behavior events · 1 ATT&CK techniques · 21 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- www.bing.com
- assets.msn.com
- licensing.mp.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- v10.events.data.microsoft.com
- slscr.update.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDriveActionHelper.exe -
a1ff76941a5fac17b5d5b5675c936ada55f73bed08a7723f43f6ee9455df15b2 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\Microsoft.SharePoint.NativeMessagingClient.exe -
ca2e62e4ceeece297979e07e50b5a2fc2443a2104245574e9941de28bbfbbbc2 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileSyncHelper.exe -
19de0154287aac549609c5cd08315ee3173a37bf06043750b9fd8f99c067ec48 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDriveFileLauncher.exe -
f89e5ce5f7c030bf1386c0ddb69ca99d6bab183b3e4921b41f08e8dd67782f3f - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\OneDrive.exe -
4d53701ea8bb52c8d930ac0396888aeb74de45e7658320ffa55bc438e6fe65df - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDriveUpdaterService.exe -
2765881fc2c8ca80a0ab2cfa5f628d3994666da3705d7ee6eb6f86b14aa77de2 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\Microsoft.SharePoint.NativeMessagingClient.exe -
cd3c61e415681b56c2480a9cad4dcd3a1b71f8e143f0c258d9911665be53d8e5 - C:\Windows\CTS.exe -
b612d46644d0e4a3829c4d6715f71d979103aa487624805363b36f5b4f92b118 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\FileSyncHelper.exe -
b1b8ad4ebb81dc1bcf82d0c5ba599ec352c5c9394ecf642e82421a095ce1416f - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDrivePatcher.exe -
000d471063367d2bea444e6c7e700f6d4c98acf0eea1176c533da63257880a12 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe -
baf79bdd016282e4cf072b11990d6f0008d4f13c91185b6f6e9f24b7189b2e99 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileCoAuth.exe -
c5ba0f4e2b3a319cd906a266fecf16efe8f39be2c5314bad3ae32f588b877055 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\FileSyncConfig.exe -
ed8d4a0ad8fa864056138ce3e48063d12f7cd30148ce734821a6acad670b0376 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\OneDrive.App.exe -
f37b80820619bac4aea6d7bc0eb9cc249d4bfd9b434471e10bb4c233abc4e6ff - C:\Users\analyst\AppData\Local\Temp\Ob9q9iSYPwEeUtR.exe -
0048bd748795de149bbda48a8139868cfb815dab761b5ecce149834acac3c250
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 52.182.143.212
- 52.123.252.227
- 4.230.171.124
- 4.144.132.114
- 135.232.92.97
- 4.150.223.99
- 74.178.240.61
- 4.150.223.109
- 20.42.179.192
- 172.66.2.5
- 52.110.12.28
- 52.110.12.19
- 72.145.35.102
- 52.148.114.188
- 52.110.12.22
More Neyndy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report