MALICIOUS — 6100631b0b7a472628e62325d107dc24ba600d7976553ef4e7d543a353781569
MALICIOUS — 6100631b0b7a472628e62325d107dc24ba600d7976553ef4e7d543a353781569 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Zusy family. 6 of 52 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
6100631b0b7a472628e62325d107dc24ba600d7976553ef4e7d543a353781569 - SHA-1:
ee92b6f1b14ed85b6e722de51e338dc8b30c09cd - MD5:
cd2c21c3e0f7b2b126e7cdebefb85cc7 - imphash:
f1a539a5b71ad53ac586f053145f08ec - File type: pe · Size: 3656104 bytes
- Verdict: malicious (100/100) · Family: Zusy
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Zusy-9957983-0
- Detect It Easy (packer/type): DIE:UPX
- Kaspersky (KVRT): Trojan.Win32.Agent.neyndy
- Microsoft Defender: Trojan:Win32/Prepscram!pz
- Emsisoft (Emergency Kit): Gen:Variant.Rootkit.25
MITRE ATT&CK
Dynamic analysis (windows)
49170 behavior events · 2 ATT&CK techniques · 27 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- msedge.api.cdp.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- officeclient.microsoft.com
- www.msn.com
- odc.officeapps.live.com
- geo.prod.do.dsp.mp.microsoft.com
- settings-win.data.microsoft.com
- assets.msn.com
- kv801.prod.do.dsp.mp.microsoft.com
- cp801.prod.do.dsp.mp.microsoft.com
- msedge.b.tlu.dl.delivery.mp.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/13495/files/660f59fe3fc0a61ff9a46bf91bcf97ae91140bbf38cb1f42cd2cc3d6e05f52f9 —
660f59fe3fc0a61ff9a46bf91bcf97ae91140bbf38cb1f42cd2cc3d6e05f52f9 - /opt/CAPEv2/storage/analyses/13495/files/17df8721368efb6faa5d98d9fa52df0e97c35c84277191405182259546c362f1 —
17df8721368efb6faa5d98d9fa52df0e97c35c84277191405182259546c362f1 - /opt/CAPEv2/storage/analyses/13495/files/faa0555cf4bc2b238ccea8020dfa0305626a0d628cdf73312d9d126870231aa9 —
faa0555cf4bc2b238ccea8020dfa0305626a0d628cdf73312d9d126870231aa9 - /opt/CAPEv2/storage/analyses/13495/files/6ac1ca3c09b08699e018c240cf850dd8536f8599ed4f4477fc35348b329208d8 —
6ac1ca3c09b08699e018c240cf850dd8536f8599ed4f4477fc35348b329208d8 - /opt/CAPEv2/storage/analyses/13495/files/df28d90ac78ee76a21882fe73f8c3537a3a20f620a0a8492b5414fbc0c773372 —
df28d90ac78ee76a21882fe73f8c3537a3a20f620a0a8492b5414fbc0c773372 - /opt/CAPEv2/storage/analyses/13495/files/2fccf9cb6c19cfaa31950ce9c1283ab083279c1dd833ed75b5700f7d1dc0f78f —
2fccf9cb6c19cfaa31950ce9c1283ab083279c1dd833ed75b5700f7d1dc0f78f - /opt/CAPEv2/storage/analyses/13495/files/b612d46644d0e4a3829c4d6715f71d979103aa487624805363b36f5b4f92b118 —
b612d46644d0e4a3829c4d6715f71d979103aa487624805363b36f5b4f92b118 - /opt/CAPEv2/storage/analyses/13495/files/3143c1224e5f3cc3bbaea3a970e7ae8a5ec02656121e5d7ade4917f449cb19af —
3143c1224e5f3cc3bbaea3a970e7ae8a5ec02656121e5d7ade4917f449cb19af - /opt/CAPEv2/storage/analyses/13495/files/c7fd0b509ebc8a1362023cb82f9a36443128db714388920f4890b3f535eb2e45 —
c7fd0b509ebc8a1362023cb82f9a36443128db714388920f4890b3f535eb2e45 - /opt/CAPEv2/storage/analyses/13495/files/c712d6c7a60f170a0c6c5ec768d962c58b1f59a2d417e98c7c528a037c427ab6 —
c712d6c7a60f170a0c6c5ec768d962c58b1f59a2d417e98c7c528a037c427ab6 - /opt/CAPEv2/storage/analyses/13495/files/7c463800bc649ace581d6e212c3b0d5a0e06a0bbd178380dbe0bcdffc0ff4f69 —
7c463800bc649ace581d6e212c3b0d5a0e06a0bbd178380dbe0bcdffc0ff4f69 - /opt/CAPEv2/storage/analyses/13495/files/6a76566509f97c406e4d84fc65edc146a814b2600925d946f5a3ec03001f30b9 —
6a76566509f97c406e4d84fc65edc146a814b2600925d946f5a3ec03001f30b9 - /opt/CAPEv2/storage/analyses/13495/files/4efe8326ef1f1ac648916fa2b72fa18fd7e70ce1d858fc06e97945ecd0ce95a6 —
4efe8326ef1f1ac648916fa2b72fa18fd7e70ce1d858fc06e97945ecd0ce95a6 - /opt/CAPEv2/storage/analyses/13495/files/7db230b038dd01cbb133d98e6686b9e08cb6beecf3393ce3a7be6fc5d0bf4d1e —
7db230b038dd01cbb133d98e6686b9e08cb6beecf3393ce3a7be6fc5d0bf4d1e - /opt/CAPEv2/storage/analyses/13495/files/410d693e48cee09f945e01b11f48462124d08983da425f42cb6c4c87fd5609c4 —
410d693e48cee09f945e01b11f48462124d08983da425f42cb6c4c87fd5609c4
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786549222&P2=404&P3=2&P4=fQX2wIwZeBnDKbTBivvA9SJbkD8RmcULqXCZ3UXEuS8jS7Bx4yGH30zOwr3PDftnuQDYg6KQ9PuGQcqSqOUwEg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786549255&P2=404&P3=2&P4=fLkiD8peacNspFYIP3MKCmg8eGKtrFb0FcjA%2b1AoBpmnqzsk%2ffqJV8HSNvAz7ADbUNH8tUtaDTsNJOz7mwI8eQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- jmk.br
- 0.se
- u.me
Embedded IP addresses
- 203.26.79.13
- 52.182.141.63
- 52.123.252.238
- 4.230.171.124
- 20.42.179.192
- 52.230.59.222
- 52.123.252.213
- 74.179.71.159
- 135.233.95.144
- 135.233.95.135
- 52.182.143.212
- 20.184.175.17
- 172.178.240.161
- 172.178.240.162
- 72.145.35.116
- 20.184.175.10
- 52.110.12.11
- 52.110.12.54
- 52.148.114.188
- 52.110.12.2
- 52.110.12.55
File paths
- w:\R
- J:\k
More Zusy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report