MALICIOUS — f3b7d305bfdc2ac9c0558e32e46b279bf93d8fe8c495a6a438809ef6ff8dea51
MALICIOUS — f3b7d305bfdc2ac9c0558e32e46b279bf93d8fe8c495a6a438809ef6ff8dea51 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Prepscram family. 6 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
f3b7d305bfdc2ac9c0558e32e46b279bf93d8fe8c495a6a438809ef6ff8dea51 - SHA-1:
41c6be34baf710b18b2f27d4d736cd6ede74bea8 - MD5:
c97c671162f6b55310eb4da51ea90862 - imphash:
f1a539a5b71ad53ac586f053145f08ec - ssdeep:
768:eyX3LKew369lp2z3Sd4baFXLjwP/Tgj93b8NIoIo:egKcR4mjD9r823o - TLSH:
T1592ED1707466E388E336FD1870CDE9AEA5131C8B099946971AA0DA0DFC6047BC6E7B14 - Submitted as: f3b7d305bfdc2ac9c0558e32e46b279bf93d8fe8c495a6a438809ef6ff8dea51
- File type: pe · Size: 30259 bytes
- Verdict: malicious (100/100) · Family: Prepscram
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Zusy-9957983-0
- Detect It Easy (packer/type): DIE:UPX
- Microsoft Defender: Trojan:Win32/Prepscram!pz
- Emsisoft (Emergency Kit): Gen:Variant.Virus.8
- Kaspersky (KVRT): Trojan.Win32.Agent.neyndy
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Malware.Zusy-9957983-0 (rule
Win.Malware.Zusy-9957983-0) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Prepscram): CTS.exe - dynamic signal, weight 0.62, confidence 0.90
- 1 behavioral detection(s) across 1 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged Trojan:Win32/Prepscram!pz (rule
Trojan:Win32/Prepscram!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Virus.8 (rule
Gen:Variant.Virus.8) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Agent.neyndy (rule
Trojan.Win32.Agent.neyndy) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 2 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:UPX (rule
DIE:UPX) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 - static signal, weight 0.25, confidence 0.55
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
2429 behavior events · 1 ATT&CK techniques · 21 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- www.bing.com
- assets.msn.com
- edge.microsoft.com
- time.windows.com
- settings-win.data.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Microsoft\OneDrive\OneDrive.exe -
2f9dfdbfcb503fa0addea81ff71f346468a3fc43b21b390612743a66cde72610 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDriveFileLauncher.exe -
72a82d841f91f6c00746f093343bfd38d56abd995aeb84b0798d54d36bcf662a - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDrive.Sync.Service.exe -
52912a76756ffc7dec97419b37d8844d95854cb46c2f84f544580d7b17efe477 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe -
2208b57cea6feeda7e4237b0e5218970f39d1293ece18510f693e9f3df322a90 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\FileSyncHelper.exe -
f4cc3df401aab0a3431782d0d08b36fd0493f9196cf4fe44678beee84a1604f3 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDriveActionHelper.exe -
51f535d7a9630d67e0d1605f14f5124e444743fcc656678cc530f333ffcf60d2 - C:\Windows\CTS.exe -
b612d46644d0e4a3829c4d6715f71d979103aa487624805363b36f5b4f92b118 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDriveUpdaterService.exe -
ffd11add8e976ba572143fe35ac33e6b89bbc1535abf83df3df6dad8f30e4758 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\FileCoAuth.exe -
f652d5a9d3c0691f6645245122bd277906e1035f827be215a0c6aa2efb4f99dd - C:\Users\analyst\AppData\Local\Temp\5PAip6TcCF1ooDs.exe -
898e27be311342d78c490aa606da32028713818bc33cc5931d2878ed2418b3aa - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\Microsoft.SharePoint.NativeMessagingClient.exe -
c09eee38939620ef429119836ef2137d4c9ac506b170ef3e7f1b621f917da8bf - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDriveLauncher.exe -
f66ddccf3bb94970319bc76686f500f8105ce55788d9b0aad8dcbd5c9335c387 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileSyncHelper.exe -
39e793c5859f3038c504f1ab8d57d5c35c937eae60493fd4cc37836b40447fd7 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileSyncConfig.exe -
9574a019e813f225c56eb4ba75b88f3bd9f29a30debba0d5682090d5f76a860f - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\Microsoft.SharePoint.NativeMessagingClient.exe -
967e01e7fc1570c8c3be2e1a3a4773a01942d3f3b11be00cbec75920044edc1d
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 40.74.98.199
- 20.247.185.124
- 4.230.171.124
- 52.110.12.44
- 52.110.12.32
- 4.247.188.233
- 72.145.35.111
- 52.148.114.188
- 52.110.12.24
- 52.110.12.52
More Prepscram samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report