MALICIOUS — fecd9bcf38e7fac401fc58d6738a436dfeeb4a39d9613b16e829001915214bf9
MALICIOUS — fecd9bcf38e7fac401fc58d6738a436dfeeb4a39d9613b16e829001915214bf9 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100), attributed to the Upatre family. 3 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fecd9bcf38e7fac401fc58d6738a436dfeeb4a39d9613b16e829001915214bf9 - SHA-1:
4422246d04de64a78cee00ec38c92e0d9f5c83cc - MD5:
c2078f75a5c342d0c4857a681ee7d34e - imphash:
e836076a09dba03e4d6faa46dda0fefc - ssdeep:
192:RBVfonwR21BA/WjOIut72DbURpF7twhec0r0C2vXH6ClWkukk12O+ZhSFb+C:xfonwR21BFjABJVr1gXlWr+QX - TLSH:
T1B13019CE81A81BA7C33714E61632D91FA197B0E209DD72191D9DE03D90C2CE39D52E7A - Submitted as: fecd9bcf38e7fac401fc58d6738a436dfeeb4a39d9613b16e829001915214bf9
- File type: pe · Size: 38130 bytes
- Verdict: malicious (88/100) · Family: Upatre
Detections (3 of 52 engines)
- ClamAV (daily): Win.Malware.Upatre-6803700-0
- Microsoft Defender: Trojan:Win32/Upatre.ME!MTB
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 88/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Malware.Upatre-6803700-0 (rule
Win.Malware.Upatre-6803700-0) - engine signal, weight 0.90, confidence 0.95 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- varunmaira.com
- go-quicky.com
File paths
- C:\205fab5dc6f8e91a4ed94d6e175208f361417fbc42e3ae8ada9b7841a521e06a
- C:\691d851f62dc9a402c249df6c0bf8d82ca8d813fc43a7b9f40c6f5730624f79a
- C:\806cff156f045bdab5f4e41adbcbd3b3feee5b38f0abac9299b915876d5eb21b
- C:\634ec952735785fbd866a1679ed6fb7a2eb487fcc242bee7dec5e75d66d3a238
- C:\b7ed98801b68f373cff9e1d07269be005b28aa97107e9b60b1676a9cdde2668f
- C:\UXSiu_0B.exe
- C:\eFkECEIN.exe
- C:\iAuUue2X.exe
- C:\cRxS5pIA.exe
- C:\QZZXmLCN.exe
- C:\s9TvkU6c.exe
- C:\LzxQVGe1.exe
- C:\qo3JqdHa.exe
- C:\ef3a4e38b1a9f6782b0552a3f9e1698ff0ab75ce5b8c178b244388ddc6d45d76
- C:\bf4e41b0e15075183a39e639c6a826ff555261db96faa211cef7e62877a02089
- C:\259dcf030008f4a26c5f703a7760d8906b36cff8fd90c77584fb91fa585a9841
- C:\f47460bc4718d261de6d00c60e784920d2bb2819d9300e11d33728c436c9b4a0
- C:\bvCRlFIr.exe
- C:\PxWkaNQl.exe
- C:\TS9vBxfQ.exe
- C:\926kJpMN.exe
- C:\K54y3USX.exe
- C:\qqg_ZX1z.exe
- C:\lZ83R3K9.exe
- C:\gPkfHwAL.exe
More Upatre samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report