MALICIOUS — 98e91dd26bf7f6404aa0a6f4eb193c388ca414bb5f8a35e7c26231f9a67e5a57
MALICIOUS — 98e91dd26bf7f6404aa0a6f4eb193c388ca414bb5f8a35e7c26231f9a67e5a57 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Zbot family. 7 of 56 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
98e91dd26bf7f6404aa0a6f4eb193c388ca414bb5f8a35e7c26231f9a67e5a57 - SHA-1:
94cac6a6045bc4a80888cc6774d196d2e21c5fd3 - MD5:
21ab83e338efb8d5dc0d408a36cf1d9c - imphash:
e021c9fc2c12265365fad587d43783fe - ssdeep:
768:XS5nQJ24LR1bytOOtEvwDpjNbZ7uyA36S7Mz5KA:i5nkFGMOtEvwDpjNbwQE8KA - TLSH:
T1BE33FACC81B80B2BC33A15F44676D95FA29AF0E559DC750A494DA13D90C38F3AD62E32 - Submitted as: 98e91dd26bf7f6404aa0a6f4eb193c388ca414bb5f8a35e7c26231f9a67e5a57
- File type: pe · Size: 50350 bytes
- Verdict: malicious (100/100) · Family: Zbot
Detections (7 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.MPRESS1
- ClamAV (daily): Win.Trojan.Zbot-64721
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:MPRESS
- Microsoft Defender: PWS:Win32/Zbot!pz
- Trellix Stinger (McAfee): PWSZbot-FIE!9882B90E4DE8
- Kaspersky (KVRT): HEUR:Trojan-Downloader.Win32.Upatre.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 16 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Zbot-64721 (rule
Win.Trojan.Zbot-64721) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 1 finding(s) attributed to the sample across 1 technique(s), e.g. process hollowing in misid.exe (pid 7932) (rule
windows.hollowprocesses.HollowProcesses) - memory signal, weight 0.70, confidence 0.85 - Microsoft Defender flagged PWS:Win32/Zbot!pz (rule
PWS:Win32/Zbot!pz) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PWSZbot-FIE!9882B90E4DE8 (rule
PWSZbot-FIE!9882B90E4DE8) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan-Downloader.Win32.Upatre.gen (rule
HEUR:Trojan-Downloader.Win32.Upatre.gen) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s) across 1 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 1 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:MPRESS (rule
DIE:MPRESS) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-sections:.MPRESS1 (rule
high-entropy-sections:.MPRESS1) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.30, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.MPRESS1, MPRESS - static signal, weight 0.25, confidence 0.55
- Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
11554 behavior events · 2 ATT&CK techniques · 7 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- bestccc.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- dns.msftncsi.com
- edge.microsoft.com
- settings-win.data.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\misid.exe -
df3bc64f70faa2a5ca4689ec99a6aa5b7e3ed36bc922b5b964b7aed75144520a - f8175c15d331d6a300119df7f8799b9d96ee45ce479f75431161eb54510ed887 -
f8175c15d331d6a300119df7f8799b9d96ee45ce479f75431161eb54510ed887 - 1e2c9651b06a0cd1aac662771de437124265192773b18a046c6670d45ef01b45 -
1e2c9651b06a0cd1aac662771de437124265192773b18a046c6670d45ef01b45 - a283f5615b3c659f6e854d01af69c67f80ac1a09803e56fef897bce64cb68938 -
a283f5615b3c659f6e854d01af69c67f80ac1a09803e56fef897bce64cb68938 - 7901c924d6f40a14d30ebbe8da7d8e39a20b5841a859adbba56fea965122e5bd -
7901c924d6f40a14d30ebbe8da7d8e39a20b5841a859adbba56fea965122e5bd - f84c6cf4bd041dc77a75a22c5ebe22c7350cc14bfead2bd4db1ada4f6bc57ce3 -
f84c6cf4bd041dc77a75a22c5ebe22c7350cc14bfead2bd4db1ada4f6bc57ce3 - 15e2d4b824399917027ea56b3962d367720cca10d7547794bfef73e8abd1c4f7 -
15e2d4b824399917027ea56b3962d367720cca10d7547794bfef73e8abd1c4f7
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- bestccc.com
Embedded IP addresses
- 52.182.141.63
- 20.247.185.124
- 4.230.171.124
- 52.110.12.40
- 52.110.12.49
- 57.154.63.210
- 172.178.240.162
- 57.155.101.212
- 52.148.114.188
- 52.110.12.28
- 72.153.5.133
- 52.110.12.47
File paths
- C:\7Yn74cF4.exe
- C:\w_KyqlKO.exe
- C:\lpdC2ee1.ex
- C:\Documents
- C:\54186b65b4b56b164bc283e391b61ed0b56fd4faf20b3498cf5d5c192ddb2624
- C:\c6fea76a5ca0644d587d8fc31e8408c53a5becd7c96558662274fcc48271b7d1
- C:\Users\admin\Downloads\4c9fce5dc799931ac271030a79be077cc0c7bef45f7c32e6337173b843b24c89.exe
- C:\8c73e9be458dd024b1ba0ab32ea3adf6b1453fd3e9a6e898164ae4ced8355623
- C:\64b536e73d4bee32d3a921f8891789e6e077a6d375dccdeb66bbb34c99c4b1ee
- C:\84e5525cd48c5e4059665c36f2953483802cc6296149bcdc7536c6d1c06817c8
- C:\8c2aa86717e8f9dd94178611a86f91782083877dbd3b86299f389301c8fbc323
- C:\Users\Lisa\Desktop\zUOwiqmJ.exe
- C:\042b787afb5ebe06e9205a303f29cf554a29c966d2481775bb25294a00d161b4
- C:\Users\admin\Downloads\misid.exe
- C:\Users\Virtual\AppData\Local\Temp\e4a1d4d803fe2769548d7fa377598e4c5399396e06ff92198b8d8682f7a79c62.exe
- C:\df5357bdbd87be93bb1a85bf13db13394ca1bac5d42acec6c4f575af6cfa011f
- C:\4fbc938fdca6c169ebe60193654f6117e0717215c788c0bf1959a90b1ef6c28f
- C:\1b1a4c0e8fadd81d89645b8e9e0c1e2cbc97e957c24169a781e69d2327d9aba5
- C:\Users\Lisa\Desktop\KbC7yHEA.exe
- C:\49b5d08d8906d1fca8a50268d5ede3167b3b1357251e180a923749df826472e8
- C:\Users\Petra\AppData\Local\Temp\misid.pe32
- C:\1d6527d2ed5c1c8e055193efad3d8b819116e8cbed32d9cf14d16a5435f6c73c
- C:\Users\admin\Downloads\c9ee8f799300b858c11a8977ebd2ee7ee83f35a53e3db6ed6206ee1e97251509.exe
- C:\d42b31a675252b74d30a403eed7dd7ce8f46f728b2fd489340d1ae26b72f5cb0
- C:\ICo3rjDf.exe
More Zbot samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report