MALICIOUS — e922a5842b5e5576be7e6a230179449589437f21c45e235f4dbfdb02743fda8a
MALICIOUS — e922a5842b5e5576be7e6a230179449589437f21c45e235f4dbfdb02743fda8a is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the Ursu family. 5 of 52 detection engines flagged it, exhibiting 6 ATT&CK techniques.
Identification
- SHA-256:
e922a5842b5e5576be7e6a230179449589437f21c45e235f4dbfdb02743fda8a - SHA-1:
4d20b20c1f275638c046ace57c8c148f52ad8ae4 - MD5:
e7f16d4c843c31a565b0e71c59effd7c - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
1536:+I7IN9hVQMxuh42ZusVGFd3rsZEmpVxi3jrQ9ahGkx1FEi9w:+0vuipEmpVxi3jU9ahGkvFEiq - TLSH:
T1823808CC0A7E0711E533DA26E7C4A5EE5769B896F8B17B1C0A0546363090C2BFC762E5 - Submitted as: e922a5842b5e5576be7e6a230179449589437f21c45e235f4dbfdb02743fda8a
- File type: pe · Size: 80384 bytes
- Verdict: malicious (95/100) · Family: Ursu
Detections (5 of 52 engines)
- capa (capabilities): capability:credential-access
- ClamAV (daily): Win.Malware.Ursu-9794593-0
- Microsoft Defender: Trojan:MSIL/Zilla.BAA!MTB
- Emsisoft (Emergency Kit): Gen:Heur.Ransom.Imps.3
- Kaspersky (KVRT): HEUR:Trojan-PSW.MSIL.Stealer.gen
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Malware.Ursu-9794593-0 (rule
Win.Malware.Ursu-9794593-0) - engine signal, weight 0.90, confidence 0.95 - access stored credentials (rule
access stored credentials) - capa signal, weight 0.50, confidence 0.80 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - query domain / anti-analysis (rule
query domain / anti-analysis) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: https://discord.com/api/webhooks/905264369879900200/Ir1NWdyrZtD7PY0dcpgzg6vlqXDQMzZI5zYx6FIpK-GOFNmFfQhRj4LODc94NKueHLny - static signal, weight 0.35, confidence 0.60
- encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://github.com/LimerBoy/StormKitty
- https://discord.com/api/webhooks/905264369879900200/Ir1NWdyrZtD7PY0dcpgzg6vlqXDQMzZI5zYx6FIpK-GOFNmFfQhRj4LODc94NKueHLny
Embedded domains
- github.com
- discord.com
- www.youtube.com
- www.google.com
- www.facebook.com
- www.malwarebytes.com
- www.instagram.com
- www.reddit.com
- www.avast.com
- www.tiktok.com
More Ursu samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report