MALICIOUS — dcdf9027655ec38126e8934afacc56f4917dccf7fe3d0599a14702ac8478161d
MALICIOUS — dcdf9027655ec38126e8934afacc56f4917dccf7fe3d0599a14702ac8478161d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Prepscram family. 6 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
dcdf9027655ec38126e8934afacc56f4917dccf7fe3d0599a14702ac8478161d - SHA-1:
58bd431ef2b1d9807d051b8640b74866efda1ea5 - MD5:
1dfc14916078ddd694b28c9e44fd4141 - imphash:
5ffb2aa7722009119a85fcb7499bf421 - ssdeep:
6144:BhXa5KSPOm3Tj5OVOEZg+SNo/c2Jy/32Hy2+vHxlE04mL:B85KSGofuOEC+uo/cVfp2+vHxt4mL - TLSH:
T12046F1ED581A6A89C779DA325F211C5DA023F06A6EAD304C7E43A47F39F312B697005C - Submitted as: dcdf9027655ec38126e8934afacc56f4917dccf7fe3d0599a14702ac8478161d
- File type: pe · Size: 306712 bytes
- Verdict: malicious (100/100) · Family: Prepscram
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Zusy-9957983-0
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Trojan:Win32/Prepscram!pz
- Emsisoft (Emergency Kit): Gen:Variant.Virus.1
- Kaspersky (KVRT): HEUR:Trojan-Dropper.Win32.Daws.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 14 weighted signals:
- ClamAV (daily) flagged Win.Malware.Zusy-9957983-0 (rule
Win.Malware.Zusy-9957983-0) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s) across 1 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Memory forensics: 1 finding(s) attributed to the sample across 1 technique(s), e.g. RWX/private injected region in bhLGvGDoB6Yzkf (pid 1432) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Win32/Prepscram!pz (rule
Trojan:Win32/Prepscram!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Virus.1 (rule
Gen:Variant.Virus.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan-Dropper.Win32.Daws.gen (rule
HEUR:Trojan-Dropper.Win32.Daws.gen) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Packing/obfuscation: UPX - static signal, weight 0.25, confidence 0.55
- Dropped 19 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
2460 behavior events · 1 ATT&CK techniques · 20 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- fe3cr.delivery.mp.microsoft.com
- settings-win.data.microsoft.com
- slscr.update.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\bhLGvGDoB6Yzkfe.exe -
b2e32b3fa44b3a9a8fdfa906627355f6f48b4821929f9bce5ded2d07894361d4 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\OneDrive.exe -
e48d07cc58de19fbe95692466fb290331a47ee3ba63367557b035c1e3a4d88ba - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDriveActionHelper.exe -
5df2205cbe183ba8e5f9ac6f94dbd27686bd9fc94c8f90e04e97f4849b2ee39b - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDriveLauncher.exe -
4b0942113b19b0100e77a0bbf11c2071b7d3b3308c2e23d059640e5b524f491d - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\FileCoAuth.exe -
ce657e91f256fe26116c55b0092fff8a4c9fa5872a6bb6d4552911c67bef8329 - C:\Windows\CTS.exe -
3293c5e8c2a49b5c7e2ba41c33e49d894137e25b672f19df5100bb9042bda402 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe -
c1bb40de79f066a9aa273f8c9038722b3c2dcff2d9773ddb38c33315185cd012 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileSyncHelper.exe -
0658369198b5c9d6a8245808868d6634a44ad9ef50d0fe74c2209222bc53c301 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\FileSyncHelper.exe -
01eab11e4accecb1798e9e10099c72b17923860b0964bdc61cdeb4e4adafa951 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileSyncConfig.exe -
64361c79e1a0b7119cefe404431579dc0613b7d20db45d4a3819827335872ef7 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDrivePatcher.exe -
b877ab382141cc486445e7bf97212107f12a685253e694de0472985ea2d3ce37 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\Microsoft.SharePoint.NativeMessagingClient.exe -
b30cca1f4616cd6b2d22ad4b7badfb07973b823d68634bec52d83cdb9eaaeff6 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\OneDrive.App.exe -
54dda11b01c90f7f029abcd85c2b938849cd6fb9854d5febff7b2c8cea7b84e0 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\FileSyncConfig.exe -
7e51a98e52d5ffa19638de5c6e15f79d99a349450fe9385fd28c8c0941cf6d4c - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\Microsoft.SharePoint.NativeMessagingClient.exe -
722f152216893ab04606894b290be9ded1c85a798e6af891dbf92cbef92e09c1
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 4.150.223.104
- 52.230.60.54
- 52.123.252.195
- 4.230.171.124
- 135.232.92.97
- 48.211.4.16
- 74.178.76.128
- 20.42.73.26
- 72.145.35.98
- 52.148.114.188
- 52.110.12.15
- 52.110.12.48
More Prepscram samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report