MALICIOUS — 8b13e64ec2056c81b0702dde857144e90ee1ca634b68bb2ee1b13475cf75eb39
MALICIOUS — 8b13e64ec2056c81b0702dde857144e90ee1ca634b68bb2ee1b13475cf75eb39 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Zusy family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
8b13e64ec2056c81b0702dde857144e90ee1ca634b68bb2ee1b13475cf75eb39 - SHA-1:
06284b302923fce6b3b5b43fde77e57c2004d214 - MD5:
2695752b787ff24e4eefba4cd234bf90 - imphash:
f1a539a5b71ad53ac586f053145f08ec - File type: pe · Size: 2415528 bytes
- Verdict: malicious (98/100) · Family: Zusy
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Zusy-9957983-0
- Detect It Easy (packer/type): DIE:UPX
- Microsoft Defender: Trojan:Win32/Prepscram!pz
- Emsisoft (Emergency Kit): Gen:Variant.Rootkit.25
- Kaspersky (KVRT): Trojan.Win32.Agent.neyndy
MITRE ATT&CK
Dynamic analysis (windows)
2353 behavior events · 1 ATT&CK techniques · 17 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- settings-win.data.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- tas02.sls.update.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- slscr.update.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/12919/files/5ac9b069a33855fe3086172e13cf9a907d49456036b7eb83ea0d67b4879987c7 —
5ac9b069a33855fe3086172e13cf9a907d49456036b7eb83ea0d67b4879987c7 - /opt/CAPEv2/storage/analyses/12919/files/9d3454b3184e8a2601387af45d3c5fa1591de461a7d6518f174d196a746b46ce —
9d3454b3184e8a2601387af45d3c5fa1591de461a7d6518f174d196a746b46ce - /opt/CAPEv2/storage/analyses/12919/files/b612d46644d0e4a3829c4d6715f71d979103aa487624805363b36f5b4f92b118 —
b612d46644d0e4a3829c4d6715f71d979103aa487624805363b36f5b4f92b118 - /opt/CAPEv2/storage/analyses/12919/files/94b4296183a4de890ff7b13c1ceaf779cfda91ba90e03cd3a85020f3a809edc6 —
94b4296183a4de890ff7b13c1ceaf779cfda91ba90e03cd3a85020f3a809edc6 - /opt/CAPEv2/storage/analyses/12919/files/ae6cbcd69fce363dc30a4a18a38499914c6d831ccf410c64ad0664dc5b3ca7b6 —
ae6cbcd69fce363dc30a4a18a38499914c6d831ccf410c64ad0664dc5b3ca7b6 - /opt/CAPEv2/storage/analyses/12919/files/20367d2a6f0a2d356511bf522a629729afe001f0d5102da722ce310ee7f1300e —
20367d2a6f0a2d356511bf522a629729afe001f0d5102da722ce310ee7f1300e - /opt/CAPEv2/storage/analyses/12919/files/19ae1db31009a819f32a907226d807dda57d30791b9de7f87d9cfacdc3b6e946 —
19ae1db31009a819f32a907226d807dda57d30791b9de7f87d9cfacdc3b6e946 - /opt/CAPEv2/storage/analyses/12919/files/f964e9cfd12c457ee3b423dac1cef8239cec32ebaf33bbfefe86f0b4a54565c3 —
f964e9cfd12c457ee3b423dac1cef8239cec32ebaf33bbfefe86f0b4a54565c3 - /opt/CAPEv2/storage/analyses/12919/files/77218ac3e230f059cdfbe40252412b2cffa692543cc8d228b44bbfb5886a4acf —
77218ac3e230f059cdfbe40252412b2cffa692543cc8d228b44bbfb5886a4acf - /opt/CAPEv2/storage/analyses/12919/files/e2d16b5113d45d6987f90663d2c878a808c83e782e0031b5f0dd6de2f8c50655 —
e2d16b5113d45d6987f90663d2c878a808c83e782e0031b5f0dd6de2f8c50655 - /opt/CAPEv2/storage/analyses/12919/files/a3d7343303e1907bbb00745e335574de40fc2be35224c0ed1c5d8aa56ce2f4ef —
a3d7343303e1907bbb00745e335574de40fc2be35224c0ed1c5d8aa56ce2f4ef - /opt/CAPEv2/storage/analyses/12919/files/1dd4e7d5dee0141c4e3388b4b261a5d2dc80b4909242d525e2cd3779fb7080b2 —
1dd4e7d5dee0141c4e3388b4b261a5d2dc80b4909242d525e2cd3779fb7080b2 - /opt/CAPEv2/storage/analyses/12919/files/eca587d6da29c604dadca2c4e1ed064c89617095c49cb6a9d16432ffea9513da —
eca587d6da29c604dadca2c4e1ed064c89617095c49cb6a9d16432ffea9513da - /opt/CAPEv2/storage/analyses/12919/files/4f29d1c3fdd6479fe3b316a8b41804c33e36a5a9f642b1fc0d89cc696fb67a27 —
4f29d1c3fdd6479fe3b316a8b41804c33e36a5a9f642b1fc0d89cc696fb67a27 - /opt/CAPEv2/storage/analyses/12919/files/5d561f782c66e10a192b91a9353190a914260de1a42ebf73ee56a28f95316887 —
5d561f782c66e10a192b91a9353190a914260de1a42ebf73ee56a28f95316887
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786534702&P2=404&P3=2&P4=AjUlaZHUw0G%2bLmOJCmQdRFVSSQAG1CrHNxt5SOgpkwW7d0IflX59arQkiR6DnyCVWxPuTca7nfAoYVrSJt%2f6%2bQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786534758&P2=404&P3=2&P4=CtJ4FBIfhLlVGwAHvqsO6I6Nq7f5W0epfiS2Hi%2f0oHRb8v1AzhUqHQAvLQfb%2f7aJAuH55HFkVhEsYaxZJ2fetA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 52.168.117.171
- 52.123.252.223
- 4.144.132.114
- 52.230.60.54
- 40.84.85.40
- 4.230.171.124
- 57.155.101.212
- 20.165.94.63
- 135.233.95.135
- 135.233.45.223
- 52.110.12.45
- 52.110.12.14
- 203.26.79.13
- 74.178.76.44
- 92.223.78.30
- 72.145.35.99
- 52.148.114.188
- 52.110.12.56
- 52.110.12.52
File paths
- S:\za
More Zusy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report