MALICIOUS — Aurora15Connector.exe
MALICIOUS — Aurora15Connector.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Lazy family. 8 of 55 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
d72650e612e3d3ac130308a7c25e8ae37b989b115163a2bc21a588851bb498e6 - SHA-1:
c29e11250857646305f011ea2922499be32af1b3 - MD5:
e13638bff185d628eba78b7a5d1e2312 - imphash:
027eac1382f09c1377726a7aad4defc6 - ssdeep:
98304:STSoTJDxNd2zKnyxmOASziLmSioZiehV3tgrpkkz5EQzI:gSoFIzKyxmOLiLmkx2rpkk3 - TLSH:
T1C36B9CAA062F1173F1F7ED846C1CCEDD8560B19A54339B9C4503AE6ED8D1037ADE12A8 - Submitted as: Aurora15Connector.exe
- File type: pe · Size: 10112000 bytes
- Verdict: malicious (100/100) · Family: Lazy
Detections (8 of 55 engines)
- capa (capabilities): capability:execution/powershell
- ClamAV (daily): Win.Malware.Lazy-10060471-0
- YARA: bartblaze: BB_Clipbanker
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Emsisoft (Emergency Kit): Gen:Variant.Yogi.74509
- Kaspersky (KVRT): UDS:DangerousObject.Multi.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 13 weighted signals:
- ClamAV (daily) flagged Win.Malware.Lazy-10060471-0 (rule
Win.Malware.Lazy-10060471-0) - engine signal, weight 0.90, confidence 0.95 - YARA: bartblaze flagged BB_Clipbanker (rule
BB_Clipbanker) - engine signal, weight 0.70, confidence 0.70 - Emsisoft (Emergency Kit) flagged Gen:Variant.Yogi.74509 (rule
Gen:Variant.Yogi.74509) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:DangerousObject.Multi.Generic (rule
UDS:DangerousObject.Multi.Generic) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.50, confidence 0.70 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://ea.com/license, https://aurora15.onlyonemzy.com/, http://127.0.0 - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.apache.org/licenses/
- http://www.apache.org/licenses/LICENSE-2.0
- http://ea.com/license
- http://www.w3.org/1999/xhtml
- https://aka.ms/nativeaot-compatibilit
- http://schemas.microsoft.com/win/2004/08/events/event
- http://www.w3.org/XML/1998/namespace
- https://aurora15.onlyonemzy.com/
- https://go.microsoft.com/fwlink/?linkid=2233907
- http://127.0.0
- http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarygroupsi
- http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlywindowsdevicegrou
- http://schemas.microsoft.com/ws/2008/06/identity/claims/primarygroupsi
- http://schemas.microsoft.com/ws/2008/06/identity/claims/rol
- http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsdevicegrou
- http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsuserclai
- http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nam
- http://www.w3.org/2001/XMLSchem
- http://www.w3.org/2001/XMLSchema#integer6
- http://www.w3.org/2001/XMLSchema#uinteger6
- http://www.w3.org/XML/1998/namespac
- https://aurora15.onlyonemzy.com/fifa15/connect/releases
- https://aurora15.onlyonemzy.com/fifa15/connect/releases/1.0.7/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/Aurora15Connector.ex
- https://aurora15.onlyonemzy.com/fifa15/connect/releases/1.0.7/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/Aurora15Connector.exe?replacement=
- https://cdn.aurora15.onlyonemzy.com/fifa15/connect/client.zi
Embedded domains
- github.com
- www.apache.org
- fesl.ea.com
- spring14.gosredirector.ea.com
- ea.com
- www.w3.org
- schemas.microsoft.com
- discord.gg
- aurora15.onlyonemzy.com
- go.microsoft.com
- fifasetup.in
- schemas.xmlsoap.org
- cdn.aurora15.onlyonemzy.com
- missing-saved.in
- aka.ms
- example.invalid
Embedded IP addresses
- 1.1.51.0
- 4.2.1.0
- 5.29.10.5
- 29.19.5.29
- 152.5.29.3
- 5.29.35.5
- 29.37.5.29
- 17.5.29.141
- 1.12.10.1
- 1.9.16.1
- 1.9.16.2
- 1.9.16.3
- 3.2.8.1
- 151.242.127.14
- 1.101.2.1
- 1.101.3.4
- 203.0.113.1
- 10.0.0.4
File paths
- C:\Users\Natha\Documents\Playground\Aurora15\tools\EA-MITM\out\EA-MITM_x64_Release.pdb
- Z:\Program
- C:\FIFA
- C:\Other
- C:\Games\FIFA
- C:\Program
- C:\Users\someone\AppData\Local\Aurora15Connector\x.tm
- D:\FIFA
- c:\\
More Lazy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report