MALICIOUS — ae89298892c699784513f46606072f632d1c0383a06f5702a86e8583f7045392
MALICIOUS — ae89298892c699784513f46606072f632d1c0383a06f5702a86e8583f7045392 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Ulise family. 5 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
ae89298892c699784513f46606072f632d1c0383a06f5702a86e8583f7045392 - SHA-1:
4eac6f23642da8d78ecace5bb3c4bc8c2a4e461b - MD5:
9bf7ea9cd1664039439c2a252e38a82d - imphash:
80f98867f9ab468619683e8a611ea834 - ssdeep:
1536:0W+caYNZXeWK3O9UmGGLbQd9AVaOoNTfqrvrKQr36/uInfNIOajxG/n5oscys2Dd:0WeeSOFhmmVadQTEYxk5Fsd2b - TLSH:
T1CD3D5CDA8D077422F07BE9886C157AFC4892F4AD7974814DA317C90E10F397BB87126A - Submitted as: ae89298892c699784513f46606072f632d1c0383a06f5702a86e8583f7045392
- File type: pe · Size: 124426 bytes
- Verdict: malicious (100/100) · Family: Ulise
Detections (5 of 56 engines)
- ClamAV (daily): Win.Malware.Ulise-9886066-0
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- Microsoft Defender: Ransom:Win32/Multiverze!pz
- Emsisoft (Emergency Kit): Generic.Dacic.1660.5FE6AE15
- Kaspersky (KVRT): HEUR:Trojan.Win64.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Win.Malware.Ulise-9886066-0 (rule
Win.Malware.Ulise-9886066-0) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s) across 1 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged Ransom:Win32/Multiverze!pz (rule
Ransom:Win32/Multiverze!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Generic.Dacic.1660.5FE6AE15 (rule
Generic.Dacic.1660.5FE6AE15) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win64.Agent.gen (rule
HEUR:Trojan.Win64.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.50, confidence 0.70 - Contacted 9 external host(s) and 27 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://pm2pavba27wr4m34.onion/command.txt - static signal, weight 0.35, confidence 0.60
- encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60
Dynamic analysis (windows)
58 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- officeclient.microsoft.com
- www.msn.com
- odc.officeapps.live.com
- assets.msn.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- www.bing.com
- fe3cr.delivery.mp.microsoft.com
- v10.events.data.microsoft.com
Embedded URLs
- http://pm2pavba27wr4m34.onion/command.txt
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://193.23.244.244/tor/status-vote/current/consensus
- http://216.218.219.41/tor/server/fp/3887faa20af621798e92b961e220695b5b747dae
- http://193.23.244.244/tor/server/fp/347b73dda3a63e47ae517c1befba5f07965ca75c
- http://204.13.164.118/tor/server/fp/e73dde49716b28bc0d12069d369865d5a287cdd6
- http://193.23.244.244/tor/server/fp/e7467371a0c061a64a9af943f530f253d54333eb
- http://193.23.244.244/tor/server/fp/e75166cedb8397b86de512b9b79b8ca7225ecb52
- http://216.218.219.41/tor/server/fp/fa5332b984d4c6d4a8fd27a73e56b8edeb3ba594
- http://204.13.164.118/tor/server/fp/fa561e534ddde63830fa0b0a484235ed23bb27a3
- http://193.23.244.244/tor/server/fp/fa7136fd4f8a727810a22ed2096af60f872c2f41
- http://193.23.244.244/tor/server/fp/b0f688a995fecd6d77697a834c96096094b9872e
- http://204.13.164.118/tor/server/fp/776542d611661d6fe3839fe2d7afb92a435c5d81
Embedded domains
- pm2pavba27wr4m34.onion
Embedded IP addresses
- 20.42.65.90
- 4.230.171.124
- 4.247.188.233
- 52.230.59.222
- 74.178.76.54
- 20.184.175.18
- 20.165.94.63
- 51.105.71.137
- 86.59.21.38
- 154.35.175.225
- 82.94.251.203
- 193.23.244.244
- 64.65.0.56
- 216.218.219.41
- 204.13.164.118
- 185.21.217.32
- 164.90.131.37
- 72.154.7.97
- 52.148.114.188
- 52.110.12.51
- 52.110.12.56
More Ulise samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report