MALICIOUS — 96095bbc4f63a806f9618e9082aca49bb8ac232d44c201a318c644927b183674
MALICIOUS — 96095bbc4f63a806f9618e9082aca49bb8ac232d44c201a318c644927b183674 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the Upatre family. 7 of 52 detection engines flagged it.
Identification
- SHA-256:
96095bbc4f63a806f9618e9082aca49bb8ac232d44c201a318c644927b183674 - SHA-1:
3b94eabe4fe3707ee8655758394db1fb4dc98740 - MD5:
f1bb235a02acbd7d78fd2c067342a1cd - imphash:
5c6120aa3dfebabf5d9adde17c000faa - ssdeep:
768:LepHpvCRuviPuvvaVeRMFhMN/L+9n53W+yqxX1:qpHpvs5wvaVeR0aVL+qWh1 - TLSH:
T12431DBCD81E80F27C63615A6677ED95E9096F0F10AAC3505098D9C3E90E78A39C93E37 - Submitted as: 96095bbc4f63a806f9618e9082aca49bb8ac232d44c201a318c644927b183674
- File type: pe · Size: 41876 bytes
- Verdict: malicious (93/100) · Family: Upatre
Detections (7 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): MPRESS
- ClamAV (daily): Win.Malware.Upatre-9782798-0
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:MPRESS
- Microsoft Defender: TrojanDownloader:Win32/Upatre!pz
- Trellix Stinger (McAfee): PWSZbot-FMO!F1BB235A02AC
- Kaspersky (KVRT): HEUR:Trojan-Downloader.Win32.Upatre.gen
Why this verdict
The malicious score of 93/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Malware.Upatre-9782798-0 (rule
Win.Malware.Upatre-9782798-0) - engine signal, weight 0.90, confidence 0.95 - YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:MPRESS (rule
DIE:MPRESS) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: MPRESS - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- s:\yB3Z
- C:\Users\Lisa\Desktop\Ig6c1pgY.exe
- C:\HPVwpFAa.exe
- C:\28942685d08af5a3888bf44a5f428948e1d9a67e09dcfcc6546f7987700308ef
- C:\9ce73916095cfe1b2b5ef305f4aae418c65ed9bf47823753ae5134e168fe7096
- C:\Documents
- C:\Users\Virtual\AppData\Local\Temp\ceeaad47d4cf0a688233f2f200052f72d4ecc99d8be42e1bc09a3603f82cc6af.exe
- C:\MNmDpSsX.exe
- C:\KFvzmisn.exe
- C:\03ea647345a1c584d738c4cd1c74e48d763837ff7c74d26a333d8e7ed27ba912
- C:\9qT_0T2A.exe
- C:\426dece8b8536b09c346e34c181c65da7783b4d0dfc01d0e3da59d433ece8703
- C:\33708a8c5f744a3a602045d6af1c46d353f0f341c6128ad4581e5b4c668cd74a
- C:\WB6Sow6b.exe
- C:\6d9fc176cce375f088b5c196f435b498fddb3a5dbd08437175986f3504baa042
- C:\b1b4ebb8cc457d8c14eda290bd906d4ee95bb48e0c419defdfe140cf0ad3b7fa
- C:\cfe452ea978783e779d7002955f0a5d834aa0e42d17eb6fd6a098053ddbd0ad4
- C:\QRYIzMNr.exe
- C:\uHw4_Cn5.exe
- C:\96ced05520f0ea71856fff999b90acc910f294a0dc27150dddc7da0d7ee782b5
- C:\Users\Lisa\Desktop\itD9mE8W.exe
- C:\hDuYY7cD.exe
- C:\ad93cc8cfdb507b162304ef971584ebea60955bc67a6b7da2718ee57ce3bc3f7
- C:\d48d53b520567755e4717b939bf85d54775289a2f97903448db4139d864c5d21
- C:\e51b82967c3e60c024489b185ba1ae2a958b4e6df2c97e0fdbb1f63a7fee3279
More Upatre samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report