MALICIOUS — 9848be1181b746e1445bd9edddee3897b070fbcc7078a3792939e2f33ee72f16
MALICIOUS — 9848be1181b746e1445bd9edddee3897b070fbcc7078a3792939e2f33ee72f16 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Bublik family. 5 of 56 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
9848be1181b746e1445bd9edddee3897b070fbcc7078a3792939e2f33ee72f16 - SHA-1:
999453d48dbd39759e5b56a899b24b2120e51b96 - MD5:
c2b0076b3a3ea07ab80fceba51919199 - imphash:
1355c8b0fadb1935e414f47fa976fffa - ssdeep:
3072:IjLypu9fWWe53B3v7Z0g4V232qFs2oSYyShTGFCySUh:sI7Z0g4QGUghTGFRSUh - TLSH:
T14B40D6CA80762A17CA3BDA105531DE0EE563B0F65AFD3A0D434AD42E54E347B6C3126E - Submitted as: 9848be1181b746e1445bd9edddee3897b070fbcc7078a3792939e2f33ee72f16
- File type: pe · Size: 172114 bytes
- Verdict: malicious (100/100) · Family: Bublik
Detections (5 of 56 engines)
- ClamAV (daily): Win.Downloader.Upatre-5744087-0
- Microsoft Defender: Trojan:Win32/Zbot!pz
- Emsisoft (Emergency Kit): Trojan.Downloader.JQET
- Trellix Stinger (McAfee): Downloader-FWF!C2B0076B3A3E
- Kaspersky (KVRT): Trojan.Win32.Bublik.bkgg
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Downloader.Upatre-5744087-0 (rule
Win.Downloader.Upatre-5744087-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Zbot!pz (rule
Trojan:Win32/Zbot!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Downloader.JQET (rule
Trojan.Downloader.JQET) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Downloader-FWF!C2B0076B3A3E (rule
Downloader-FWF!C2B0076B3A3E) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Bublik.bkgg (rule
Trojan.Win32.Bublik.bkgg) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 37 external host(s) and 16 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://www.musicip.com/contrib.jsp, http://www.audiocoding.com, http://nsis.sf.net/NSIS_Error - static signal, weight 0.35, confidence 0.60
- Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (3 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
40076 behavior events · 2 ATT&CK techniques · 5 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- alibra.co.uk
- alloccasionslimousines.net
- limousineshireliverpool.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- 1.0.240.10.in-addr.arpa.
- 5.121.233.62.in-addr.arpa.
- tas02.sls.update.microsoft.com
- settings-win.data.microsoft.com
- v10.events.data.microsoft.com
- 164.142.190.20.in-addr.arpa.
- d.1.d.1.c.4.2.1.4.9.5.2.6.e.8.b.0.0.0.0.0.0.0.0.0.0.0.0.0.8.e.f.ip6.arpa.
- 210.63.154.57.in-addr.arpa.
- 63.94.165.20.in-addr.arpa.
Dropped files
- C:\Users\analyst\AppData\Local\Temp\ftc.exe -
c5774a439c0065ee20ec77e1b56428be52655e76e62eaf4cee859c513513f40e - 334a1f73a06b6dc6c7642bee3797f61402f96935de3bda9b54958d401e62288d -
334a1f73a06b6dc6c7642bee3797f61402f96935de3bda9b54958d401e62288d - 07cf5fec3117b25c1853609b6a68fe7709592bdfd2b34c74aee4be454e71cfb8 -
07cf5fec3117b25c1853609b6a68fe7709592bdfd2b34c74aee4be454e71cfb8 - d4c314dd859822ebc155b7b2dcdf299a17eec03aa30e86abf041a2a1b1d1ab6e -
d4c314dd859822ebc155b7b2dcdf299a17eec03aa30e86abf041a2a1b1d1ab6e - 20651af979fb682d5893887f3585bdea4448948e17d7ad12f69c840edd666729 -
20651af979fb682d5893887f3585bdea4448948e17d7ad12f69c840edd666729
Embedded URLs
- http://www.musicip.com/contrib.jsp
- http://www.audiocoding.com
- http://nsis.sf.net/NSIS_Error
- http://www.gnu.org/software/coreutils/
- http://www.gnu.org/gethelp/
- http://translationproject.org/team/
- http://gnu.org/licenses/gpl.html
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- www.musicip.com
- www.audiocoding.com
- nsis.sf.net
- gnu.org
- www.gnu.org
- translationproject.org
- cygwin.com
- alibra.co.uk
- alloccasionslimousines.net
- limousineshireliverpool.net
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- _ldap._tcp.dc._msdcs.workgroup
- _vlmcs._tcp
Embedded IP addresses
- 4.150.223.111
- 20.42.179.192
- 172.215.188.225
- 104.208.16.94
- 57.154.63.210
- 20.165.94.63
- 62.233.121.5
- 20.42.179.204
- 20.50.80.215
- 52.123.252.229
- 20.184.175.16
- 20.42.65.85
- 203.26.79.13
- 4.150.223.109
- 52.168.117.174
- 172.215.188.232
- 72.145.35.97
- 52.123.252.244
- 52.148.114.188
- 85.210.193.152
- 52.110.12.44
- 85.210.196.11
- 4.207.44.65
- 52.110.12.54
- 40.84.85.40
File paths
- E:\DOCUME~1\NILESH~1.SER\LOCALS~1\Temp\7zO1C0.tmp\HMRC_Message.exe
- C:\Documents
- C:\wwkVM4pG.exe
- C:\3Sq4mdhY.exe
- C:\6WzVbaZA.exe
- C:\M6jQGzhb.exe
- C:\Users\admin\Downloads\file.exe
- C:\a6645d8983c5090d5cc78fd9ee68cd81b5bfc5c0d781b86754c506294c12c1b4
- C:\Users\admin\Downloads\ftc.exe
- C:\ae8f5204a8fcc9fbebaf0a432b8828d3a1756a18352cba28e0b1cb81275ddd45
- C:\Users\Petra\AppData\Local\Temp\ftc.pe32
- C:\Users\admin\Downloads\4a5b59e4e47c0cf7_ftc.exe
- C:\Users\admin\Downloads\1d0e1b7f7765b1d4_ftc.exe
- C:\c693b9e4e16d8bdf74feeec5feb2f503768cf646e6d92dada4fe464375f62e60
- C:\17f7416c8c40ded8a1084a888796a89de152499ce26fff5670919e9b1a8b2e61
- C:\87839d1531f955c7187b3fc9b9a27878c9d863c92d08275650ef616b665c0177
- C:\4f45e8df9ef09e2fe1a6c313fee54200f68f7a3617d2637741c2b7496aec6e68
- C:\8339d16d6faffd4e9f340ffa3c5d6618ddc0417d9a7947fbabb7682861b36072
- C:\6146726391b1d3dedf878cf46f81311e0698df05903b545726c969a7e7551d1d
- C:\7abefe31ad3df42c66c67bb50fb5dc1f6a09d5a2a7e7543e8ff4e9d0004a411a
- C:\a51e2df81b678fab0c690f9b6f974d1f51fd0a402eb5534657f021d3e2055076
- C:\1d3da8e68ea4c001f711e549438c4689f0da4d6f03a8bcc862b38e59665dc314
- C:\Users\admin\Downloads\93fc554334446fce_ftc.exe
- C:\c251463f2f5a1d0c8af6eee9d54eb77f83af0c3869064ea14cd7d4807e6f636f
- C:\Users\admin\Downloads\f7dffc0c632ea864_ftc.exe
More Bublik samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report