MALICIOUS — a3ec7348b24016216a11a544bba0e9a397bf326dc779e4d28b43315e64060973
MALICIOUS — a3ec7348b24016216a11a544bba0e9a397bf326dc779e4d28b43315e64060973 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Upatre family. 5 of 55 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
a3ec7348b24016216a11a544bba0e9a397bf326dc779e4d28b43315e64060973 - SHA-1:
3b10100aec3aba76235e97292c578b5570373690 - MD5:
edafbb4bf70c9b5a92032b59c27dd139 - imphash:
f262c30f75af1da928aa18962955a131 - ssdeep:
384:BJBcQ3oQ/jeO6Rj2cKfbKyVtGqJ06MqktnJ:1cqoGjeO6Rjnyjohqo - TLSH:
T1382EF8ED64D90F0BC235A0B28854CA1C976B70C53F996D09CA4AC06D6EE44D3BE709B7 - Submitted as: a3ec7348b24016216a11a544bba0e9a397bf326dc779e4d28b43315e64060973
- File type: pe · Size: 31524 bytes
- Verdict: malicious (98/100) · Family: Upatre
Detections (5 of 55 engines)
- ClamAV (daily): Win.Downloader.Upatre-5744087-0
- Microsoft Defender: PWS:Win32/Zbot!atmnm
- Emsisoft (Emergency Kit): Trojan.GenericKD.1297773
- Trellix Stinger (McAfee): PWSZbot-FFA!EDAFBB4BF70C
- Kaspersky (KVRT): Trojan.Win32.Bublik.bgbm
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Downloader.Upatre-5744087-0 (rule
Win.Downloader.Upatre-5744087-0) - engine signal, weight 0.90, confidence 0.95 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s) across 1 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 28 external host(s) and 23 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
18579 behavior events · 2 ATT&CK techniques · 6 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- plug-tugs.com
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- settings-win.data.microsoft.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\herewin.exe -
23b17320f3d7eb79d4af164019029e1011fe7291f90df229875bb01b528f0e59 - b6432043e41ffd197da25e9ac1de9b7917d8e5b5c4d281e3e36b2dfe75c71da5 -
b6432043e41ffd197da25e9ac1de9b7917d8e5b5c4d281e3e36b2dfe75c71da5 - 9ef8efc0404707a55049abb32ac0a74d3e4050b5edcd77ffa0c07f2f4ac3099a -
9ef8efc0404707a55049abb32ac0a74d3e4050b5edcd77ffa0c07f2f4ac3099a - 3d278a442fcfd1b63ebd08a09c2943e09e14c38be081e6f0b23a7e2767b69d8c -
3d278a442fcfd1b63ebd08a09c2943e09e14c38be081e6f0b23a7e2767b69d8c - af433f640716f5496ff5b647b7d3adc462548866763df58b8ab96cd09bb10c9c -
af433f640716f5496ff5b647b7d3adc462548866763df58b8ab96cd09bb10c9c - df23b14b375321b1c8e43da84d9f18f2fbe688252d8ddeb477ece6b4e166e426 -
df23b14b375321b1c8e43da84d9f18f2fbe688252d8ddeb477ece6b4e166e426
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9?P1=1787949099&P2=404&P3=2&P4=EZsRaXf3VUC5FFBmaRvXfVTrA0g9ZNJVe7OVwFDc4BrERdV8FlzD2W0xoBeAkNLKuQkvKBRBSEGNQttcWobpXA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787949167&P2=404&P3=2&P4=AJ9A25B7Z7P67CSPuOaSTMpLL12eYHbIoo6nUeTmdSDp2faBX30Z%2fG54RXQLLJgwdYHzhLoCQ8xlpU4DXdct9g%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- plug-tugs.com
Embedded IP addresses
- 48.211.4.16
- 51.116.253.169
- 4.230.171.124
- 57.155.104.224
- 52.230.60.54
- 74.178.76.128
- 20.165.94.54
- 52.168.112.67
- 52.123.129.14
- 20.236.44.162
- 40.99.134.18
- 52.123.128.14
- 52.138.229.67
- 135.234.160.246
- 52.123.252.197
- 52.123.252.226
- 92.223.78.30
- 162.159.142.9
- 3.33.251.168
- 203.26.79.13
- 52.148.114.188
- 74.179.71.159
- 184.84.165.171
- 192.124.249.31
- 192.124.249.22
File paths
- C:\Users\NIVEDI~1.PKA\AppData\Local\Temp\Rar$EXa0.283\Invoice_09272013.exe
- C:\RmGKoNLI.exe
- C:\yJqKRmZ6.exe
- C:\JoLmPsIe.exe
- C:\X2028wBY.exe
- C:\7d9x6XXJ.exe
- C:\Jl36B4br.exe
- C:\7sxuHMt1.exe
- C:\IW3IGENU.exe
- C:\WyyTySlB.exe
- C:\eCQdMUbv.exe
- C:\PgDp9Hvw.exe
- C:\sample.exe
- C:\Users\george\Desktop\file000_herewin.exe
- C:\Users\Administrator\AppData\Local\Temp\QWkoA.exe
- C:\fa0c82ee9a7bd06ae6c3a420df21526b0160a093ea3322c1317a39e0051fd380
- C:\Users\george\Desktop\herewin.exe
- C:\Users\admin\Downloads\herewin.exe
- C:\t86lixPj.exe
- C:\b70eadeaed8e01e25c601070d51b16a5bdb6096a5f1ce2b546a57c38fcdc157a
- C:\1179789ab4c3b568351f11d5d9625c5d852ed837683290eb56ed2298ed7e6895
- C:\jFYYaqKt.exe
- C:\Users\admin\Downloads\b49a75ef1e45622cad3003d2143d623e.exe
- C:\Users\r.vult\AppData\Local\Temp\85f67ea40918f32a98bc1d8097c55e0c.exe
- C:\0VhLnuDa.exe
More Upatre samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report