MALICIOUS — a5a73a61a3ea3ba64f9dec7881e525ee18f545db6bad25237a60afd284974cd9
MALICIOUS — a5a73a61a3ea3ba64f9dec7881e525ee18f545db6bad25237a60afd284974cd9 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Bulz family. 6 of 56 detection engines flagged it, exhibiting 6 ATT&CK techniques.
Identification
- SHA-256:
a5a73a61a3ea3ba64f9dec7881e525ee18f545db6bad25237a60afd284974cd9 - SHA-1:
03e182eaf2d64714b7759d5cbd8c5cb8065d42a0 - MD5:
1156f2794b34ee653faeccf2df6dec3b - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
49152:GsmhnqAs9pJc0dnKh+Q0N1rs+vIUSg+6+8ohnRh1Na1OKM6nYAKhFQpSH3Oh5gx:sqXpy05Q0N1rsYSZ6BoXh1kkypSH3Oh - TLSH:
T1025E33645DB8F8EAD515841228AFCDBCB306A45D609414EC344DEA27BA213B3DCACD4F - Submitted as: a5a73a61a3ea3ba64f9dec7881e525ee18f545db6bad25237a60afd284974cd9
- File type: pe · Size: 2978304 bytes
- Verdict: malicious (100/100) · Family: Bulz
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): Win.Packed.Bulz-9853289-0
- YARA: MalwareAnalyser community pack: TL_Windows_Persistence_RunKey
- YARA: Yara-Rules community: YR_AntiVM_Sandbox
- Microsoft Defender: Trojan:MSIL/Agent.UKY!MTB
- Kaspersky (KVRT): Trojan-PSW.Win32.Disco.q
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 16 weighted signals:
- ClamAV (daily) flagged Win.Packed.Bulz-9853289-0 (rule
Win.Packed.Bulz-9853289-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:MSIL/Agent.UKY!MTB (rule
Trojan:MSIL/Agent.UKY!MTB) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-PSW.Win32.Disco.q (rule
Trojan-PSW.Win32.Disco.q) - engine signal, weight 0.55, confidence 0.85 - 2 behavioral detection(s) across 2 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.43, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 4 external host(s) and 16 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082, T1497.001, T1497, T1622 - dynamic signal, weight 0.40, confidence 0.75
- YARA: MalwareAnalyser community pack flagged TL_Windows_Persistence_RunKey (rule
TL_Windows_Persistence_RunKey) - engine signal, weight 0.40, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiVM_Sandbox (rule
YR_AntiVM_Sandbox) - engine signal, weight 0.40, confidence 0.70 - Extracted SoranoStealer config (0 C2) - engine signal, weight 0.45, confidence 0.60
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-sections:.text (rule
high-entropy-sections:.text) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - query domain / anti-analysis (rule
query domain / anti-analysis) - capa signal, weight 0.35, confidence 0.60 - Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
- Dropped 9 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
25691 behavior events · 2 ATT&CK techniques · 43 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- itroublvehacker.gq
- api64.ipify.org
- discord.com
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\costura.system.buffers.dll.compressed -
de32ddaf09b7974d58d9661b7b5934acd58256d96d3bf39f196b49277ac4cf7d - C:\Users\analyst\AppData\Local\Temp\snuvcdsm.exe -
f999357a17e672e87fbed66d14ba2bebd6fb04e058a1aae0f0fdc49a797f58fe - C:\Users\analyst\AppData\Local\Temp\compile.vbs -
abf09cb96f4c04a1d2d2bfd7184da63dd79c2109b1a768ca5dae4265def39eee - C:\Users\analyst\AppData\Local\Temp\compile.bat -
aca74cefaef4b7a32338c9c63187cffa1e808b54ab218a064007683ad1bd3a0e - C:\Users\analyst\AppData\Local\Temp\bfsvc.exe -
5e3f311ae67f046b56435067bcdd39fbf836fa0421fbc8c8b0e43e8e47524954 - C:\Users\analyst\AppData\Local\Temp\splwow64.exe -
ebff7d07efda7245192ce6ecd7767578152b515b510c887ca2880a2566071f64 - C:\Users\analyst\AppData\Local\Temp\costura.system.threading.tasks.extensions.dll.compressed -
eeef14532c25635162130e363695d8ec71ae7c6562c5d42ee545666de6121746 - C:\Users\analyst\AppData\Local\Temp\costura.discord.net.core.dll.compressed -
265850b1887f252e04c54f81ef872587b3cfd66b0d708621d2520bc6d4bbdcac - C:\Users\analyst\AppData\Local\Temp\costura.leaf.xnet.dll.compressed -
054ba51f8449070443a3f04723ae65b1c8d8d22ba0a047dcfd25e62d638d1f21 - C:\Users\analyst\AppData\Local\Temp\costura.system.interactive.async.dll.compressed -
4ee98858cf2e1a28c5381e86a832e46d8f2fb90ef118e62db33dfb4b737d4077 - C:\Users\analyst\AppData\Local\Temp\costura.costura.pdb.compressed -
59e46fb42446344107164fbafac1e5224c2731e6f8e031cc40cf02b3f599476c - C:\Users\analyst\AppData\Local\Temp\costura.microsoft.bcl.asyncinterfaces.dll.compressed -
eaafca1dcb6d03894e0d289c3ff316be8630ab8987a5885ad0da85e0aa202da1 - C:\Users\analyst\AppData\Local\Temp\bfsvc.cfg -
239a1d9844ddbd0e650f8e5de69a2a40067106a79878fa4948a8039f1573b781 - C:\Users\analyst\AppData\Local\Temp\costura.system.runtime.compilerservices.unsafe.dll.compressed -
805c6dc929a50fdcab592c8fe04d7800f1c5fdf959f6d6c1c2fd111a278d5725 - C:\Users\analyst\AppData\Local\Temp\whysosad -
1637ce704a463bd3c91a38aa02d1030107670f91ee3f0dd4fa13d07a77ba2664
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- itroublvehacker.gq
- api64.ipify.org
- discord.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 4.150.223.108
- 52.230.59.222
- 52.123.252.232
- 48.211.4.16
- 4.230.171.124
- 85.210.193.152
- 135.233.95.144
- 135.232.92.97
- 4.150.223.113
- 52.110.12.11
- 52.110.12.49
- 104.237.62.213
- 162.159.138.232
- 52.148.114.188
- 52.110.12.26
- 52.110.12.3
- 72.154.7.109
Registry keys
- HKLM\Software\Policies\Microsoft\Windows
- HKLM\System\CurrentControlSet\Control\WMI\Autologger\DefenderApiLogger
- HKLM\System\CurrentControlSet\Control\WMI\Autologger\DefenderAuditLogger
- HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run
- HKLM\Software\Microsoft\Windows\CurrentVersion\Run
- HKLM\System\CurrentControlSet\Services\WdBoot
- HKLM\System\CurrentControlSet\Services\WdFilter
- HKLM\System\CurrentControlSet\Services\WdNisDrv
- HKLM\System\CurrentControlSet\Services\WdNisSvc
- HKLM\System\CurrentControlSet\Services\WinDefend
File paths
- w:\9
- c:\Users\Justin\AppData\Local\Temp\bin_copy\obj\Debug\Obfuscated
More Bulz samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report