MALICIOUS — 95a8faa3ce9e162ee62fd38d84dc7be852b0975f296c0c559a9824fbd17d5195
MALICIOUS — 95a8faa3ce9e162ee62fd38d84dc7be852b0975f296c0c559a9824fbd17d5195 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Upatre family. 5 of 56 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
95a8faa3ce9e162ee62fd38d84dc7be852b0975f296c0c559a9824fbd17d5195 - SHA-1:
feef8d4cc5398ea762ba9d399ebebcccc2cab6c6 - MD5:
749551be422f71b95337b23081059fe3 - imphash:
b271bce6a1e17ebf9ac5fcd3deb5ff90 - ssdeep:
384:u2T+/jvJ7+gFrJk04OMcYyOVJ9KRqnGTq/yX9k7uaaTiOmCdIniQnS:BOZ+gr36q1y/youIMdIniQnS - TLSH:
T14A30C9DC40AD0B2BC33A18F54B36D50EA29BF0E21ADD3509591D603D95C28F3AD62E76 - Submitted as: 95a8faa3ce9e162ee62fd38d84dc7be852b0975f296c0c559a9824fbd17d5195
- File type: pe · Size: 37314 bytes
- Verdict: malicious (100/100) · Family: Upatre
Detections (5 of 56 engines)
- ClamAV (daily): Win.Malware.Upatre-9794265-0
- Microsoft Defender: Trojan:Win32/Zbot.rmwh!MTB
- Emsisoft (Emergency Kit): Trojan.Zbot.IDW
- Trellix Stinger (McAfee): Downloader-FFA!749551BE422F
- Kaspersky (KVRT): HEUR:Trojan-Downloader.Win32.Upatre.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Malware.Upatre-9794265-0 (rule
Win.Malware.Upatre-9794265-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Zbot.rmwh!MTB (rule
Trojan:Win32/Zbot.rmwh!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Zbot.IDW (rule
Trojan.Zbot.IDW) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Downloader-FFA!749551BE422F (rule
Downloader-FFA!749551BE422F) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan-Downloader.Win32.Upatre.gen (rule
HEUR:Trojan-Downloader.Win32.Upatre.gen) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s) across 1 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 1 external host(s) and 19 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
11215 behavior events · 2 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- doradoresources.com
- sportsstoreonline.in
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\comupdater.exe -
649db881115a9ca4ba4447bbe8d0198f2852452dec67a68695b0f0263f5b19c0
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://doradoresources.com/images/ie6/pdf.enc
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- doradoresources.com
- sportsstoreonline.in
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 4.150.223.110
- 52.123.252.194
- 4.230.171.124
- 40.84.97.4
- 20.247.184.142
- 74.178.240.61
- 20.184.175.19
- 135.232.92.97
- 74.178.76.128
- 104.18.33.89
- 172.215.188.232
- 52.148.114.188
- 72.153.5.133
- 3.233.30.191
- 52.110.12.45
File paths
- C:\Users\usuario\APPDATA\LOCAL\TEMP\wza518\Avis.de.Paiement.exe
- C:\KYqZUP7z.exe
- C:\2SuLQEy2.exe
- C:\hZAk8hO9.exe
- C:\uexvLykv.exe
- C:\2WLw8ZJi.exe
- C:\GCD24kMf.exe
- C:\OUpKj3Ef.exe
- C:\H8hllnTQ.exe
- C:\azItvE8p.exe
- C:\vhT4dhH1.exe
- C:\9zTUyFLo.exe
- C:\yiv_tQxy.exe
- C:\vdcGttzh.exe
- C:\MLrm7OZ1.exe
- C:\Y2ZlLuIi.exe
- C:\e9QyH9Ae.exe
- C:\d1a958f4b2adbabe6ae64baf576b1b582d89339658fc9d187715e0f5bced79f1
- C:\JSdschfm.exe
- C:\acf39aa61cfcac40f69e4e56a8f17a8af21cbc66f9312583124fe143fd8eacc1
- C:\aea7d89162c1f397f9d540cb1cc443afd929f42542685ef187a391cc977aa8f2
- C:\9471ce8fa76a5a9a1d3f3b8b3651d8cf1250cf91d5afa815c9c7ec8193ab70c7
- C:\7eb9633c2437e4602e97a132438c4a6b8d1c56c98f94e6ee18b8a66275bd46b9
- C:\baa8139fab9f061e74576255e954c1c05562f1b80bada45e7337fe48a2f0466d
- C:\1610bb01bdfd347f50eee03f57caa27c6e1921dfbf6e7e24232e6d1bfc4e19bd
More Upatre samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report