MALICIOUS — ceb421ceebac2c24b2d2daceff790b930f642c6b0364e47ee10255647ca3e0e0
MALICIOUS — ceb421ceebac2c24b2d2daceff790b930f642c6b0364e47ee10255647ca3e0e0 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the Upatre family. 4 of 55 detection engines flagged it.
Identification
- SHA-256:
ceb421ceebac2c24b2d2daceff790b930f642c6b0364e47ee10255647ca3e0e0 - SHA-1:
c61ed0384d14bcb858acec632bf16d3a83b7e54d - MD5:
f1685770fa9bbf0b0fa55425ec842d0e - imphash:
6bd66260e535f8a9e953afdb30bca346 - ssdeep:
384:0K5kypvP/fm5iySkMP+OijkOj0tOcOYWO6O9Ock8siUij:0KntXyDOo2lUij - TLSH:
T1A02B2FBC836F0B0AC67797E0C732D04D925EFCF81859F51E984B543902C28AFAC65A61 - Submitted as: ceb421ceebac2c24b2d2daceff790b930f642c6b0364e47ee10255647ca3e0e0
- File type: pe · Size: 23056 bytes
- Verdict: malicious (89/100) · Family: Upatre
Detections (4 of 55 engines)
- ClamAV (daily): Win.Trojan.Upatre-3418
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): Trojan.Downloader.JQMN
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
Why this verdict
The malicious score of 89/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Upatre-3418 (rule
Win.Trojan.Upatre-3418) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://notepad-plus-plus.org/contributors - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://notepad-plus-plus.org/contributors
Embedded domains
- notepad-plus-plus.org
File paths
- C:\Documents
- C:\540621abffe504fcaa46b6e25bf3871d7121de4e041e61d8ca2d8f9de55b4cc8
- C:\ef6c83217514401b99ee1ff49064a3e36201db0c0b8a23081a3077f524e3b70b
- C:\1077a175792542dd32a548eda80f99348afcc4cc4ab51b589217bfc7b7a46360
- C:\t6WCQsIb.exe
- C:\85a5199ce251586fe81d08c19c3f0e176646a0fc62fd29c392cf588e23216ce9
- C:\Users\maxine\AppData\Local\Temp\file.exe
- C:\Users\admin\Downloads\dd967acc29e4babb85fd161d18562dc8.virus.exe
- C:\Users\george\Desktop\saloon.exe
- C:\Users\admin\Downloads\saloon.exe
- C:\Users\admin\Downloads\fc392c72b75d80a555f59fc1af121e9e8ad003ba178ff2efb7bebe9b26249cb0.exe
- C:\Users\admin\Downloads\225f744ccb7224b3a5664b74f696833e7787bc9ca5d2dd10875dac2b970b65a3.exe
- C:\Users\admin\Downloads\fbffc4b66379bdc30f9574eb740df15e5ca795e87ed27e4c3d2d534a66b6696a.exe
- C:\Users\admin\Downloads\a17468524bed5ebac14fbdc670701b6802e72440883855262f1fd7f44e9a902c.exe
- C:\1cfeab155066308365df6938cdcb123d14f408cd96356c617ee463af0fb42724
- C:\RHIr_WON.exe
- C:\Users\george\Desktop\executable.exe
- C:\Users\admin\Downloads\aed1e74ea33d497f3ef84cef93716a8178e3ffad8cbbab7a8a3dac7cc26e0106.exe
- C:\Users\admin\Downloads\54e3c5ff31fdc16ce4e2c469661b1b3de3003a08fc419a0029618cebac9fb254.exe
- C:\Users\admin\Downloads\e9036f60e7aa7c3398aa36753a515ee022877487deee86f78a351dd06a4c48c5.exe
- C:\Users\admin\Downloads\13b700237d45049d7f963c528ef649a16aaa9a100acf1cec1e101bf32a981dba.exe
- C:\9f70c219b72442f0e8e4773f0fc650f956f63162eaac15b52b623c95c1b3ef13
- C:\3f634856ff7faa7798dd07f61426d0985634a449112007f5cbf656e329c24659
- C:\Users\r.vult\AppData\Local\Temp\3f30a7203421c93d03a93b799971350f.exe
- C:\6db76360fd7e3f7bd636adc06f705eba245fd44919b1596146b94e3547e35897
More Upatre samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report