MALICIOUS — d453b09dd876a45d7baab6e0c0cdebc679d81ffe7a774006c275626c4991e553
MALICIOUS — d453b09dd876a45d7baab6e0c0cdebc679d81ffe7a774006c275626c4991e553 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Prepscram family. 6 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
d453b09dd876a45d7baab6e0c0cdebc679d81ffe7a774006c275626c4991e553 - SHA-1:
6026889085ce4daa96916ca528339350e1711981 - MD5:
9966f3904cd4c19977e17c9571225aa7 - imphash:
f1a539a5b71ad53ac586f053145f08ec - ssdeep:
768:eyX3LKew369lp2z3Sd4baFXLjwP/Tgj93b8NIoy:egKcR4mjD9r82h - TLSH:
T14B2ED0B07036D34CD372FC1960CDB9AEE1236D4A089D565729A0CA0ABC9057BC6F7B25 - Submitted as: d453b09dd876a45d7baab6e0c0cdebc679d81ffe7a774006c275626c4991e553
- File type: pe · Size: 29606 bytes
- Verdict: malicious (100/100) · Family: Prepscram
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Zusy-9957983-0
- Detect It Easy (packer/type): DIE:UPX
- Microsoft Defender: Trojan:Win32/Prepscram!pz
- Emsisoft (Emergency Kit): Gen:Variant.Virus.8
- Kaspersky (KVRT): Trojan.Win32.Agent.neyndy
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Malware.Zusy-9957983-0 (rule
Win.Malware.Zusy-9957983-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Prepscram): CTS.exe - dynamic signal, weight 0.62, confidence 0.90
- 1 behavioral detection(s) across 1 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged Trojan:Win32/Prepscram!pz (rule
Trojan:Win32/Prepscram!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Virus.8 (rule
Gen:Variant.Virus.8) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Agent.neyndy (rule
Trojan.Win32.Agent.neyndy) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:UPX (rule
DIE:UPX) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 - static signal, weight 0.25, confidence 0.55
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
2445 behavior events · 1 ATT&CK techniques · 21 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- www.bing.com
- assets.msn.com
- v10.events.data.microsoft.com
- settings-win.data.microsoft.com
- edge.microsoft.com
- ctldl.windowsupdate.com
Dropped files
- C:\Users\analyst\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe -
9123589bc5a446351cb3b094cd057197ce0e94d5e51bc8838d80cd9fd32df64e - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileCoAuth.exe -
e5d8ec26e371b293ca6e7f7cc6a77c447f8f0dee7dd3e41abb3195439c4e7727 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDrive.Sync.Service.exe -
e857bcfc9508fffa9fd7de3a2c689f3e3113db4037bc4e37398bb966e905c8bc - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\OneDrive.App.exe -
54f2ce8c30e96c1e1ef658e7459a4a0e571cf46a0a1c85292a6d5d4b13a8d32b - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\OneDrive.exe -
36611bebb6f72ab1065002b19ceedde90ac50a8351112e46da7b26469311d506 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\Microsoft.SharePoint.NativeMessagingClient.exe -
86cc50c1e02d9f93572f8a48dad912cfaad1681092c25feb19eca4b22a1719d1 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\FileSyncConfig.exe -
f9a8b2468c43409801100350e69948e3ff5673f71ac486fca5e83ae2ecdd7bd3 - C:\Windows\CTS.exe -
b612d46644d0e4a3829c4d6715f71d979103aa487624805363b36f5b4f92b118 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDriveUpdaterService.exe -
0f40a576181a56a4f1411f2813dc7bbeb220d5a2c10cc802600d3e9faea45fe6 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDriveLauncher.exe -
584b2939a23ee6be952a149e305f4af52fd82bb15e78ae84d04f7e2f91878fbe - C:\Users\analyst\AppData\Local\Temp\7pX82eKoNLndmyS.exe -
c1cbddafecfd2ecd4927bbe05f68ebeacba8025507676fc5b467584dcf64e77e - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\Microsoft.SharePoint.NativeMessagingClient.exe -
79779c614347af7070b0d7f351ca812a2374de63cc10e4fbb16c63337a4f8609 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileSyncConfig.exe -
9ca60eb66ea903830903d04a59745358663377b55e0d0ecce21e3f05fac91a06 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\FileSyncHelper.exe -
7974204ce601218debaa813f4d374d342d973f63ab29a47252b8db02c052933e - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileSyncHelper.exe -
06fe5fe25faed88a0905446335e1706dc34e745d541b3c62b27bdcdaaceb3437
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 4.150.223.107
- 52.253.84.76
- 4.230.171.124
- 20.42.73.30
- 4.247.188.224
- 20.42.179.204
- 72.154.7.110
- 52.110.12.24
- 52.148.114.188
- 52.110.12.14
More Prepscram samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report