MALICIOUS — 8d9837b0134fc6ff69d761b29a752a9acf6643867295eb59481cf795dc921d04
MALICIOUS — 8d9837b0134fc6ff69d761b29a752a9acf6643867295eb59481cf795dc921d04 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Zusy family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
8d9837b0134fc6ff69d761b29a752a9acf6643867295eb59481cf795dc921d04 - SHA-1:
7be1eff97e12329390dd68a892c20d16e58ab9ea - MD5:
7d3df3d064c9138975c8488e5df2f6c0 - imphash:
f1a539a5b71ad53ac586f053145f08ec - File type: pe · Size: 877952 bytes
- Verdict: malicious (98/100) · Family: Zusy
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Zusy-9957983-0
- Detect It Easy (packer/type): DIE:UPX
- Kaspersky (KVRT): Trojan.Win32.Agent.neyndy
- Microsoft Defender: Trojan:Win32/Prepscram!pz
- Emsisoft (Emergency Kit): Gen:Variant.Rootkit.25
MITRE ATT&CK
Dynamic analysis (windows)
2356 behavior events · 1 ATT&CK techniques · 17 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- settings-win.data.microsoft.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- licensing.mp.microsoft.com
- assets.msn.com
- www.bing.com
- tas02.sls.update.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- v10.events.data.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/12775/files/9ffa65c2eee243f4001e780c99d11699d51ab9713211dfd74833ceb5342b1b40 —
9ffa65c2eee243f4001e780c99d11699d51ab9713211dfd74833ceb5342b1b40 - /opt/CAPEv2/storage/analyses/12775/files/3489f20685677342dd695da79dd738d31496209ac0a2e633b3edf61f83981bfc —
3489f20685677342dd695da79dd738d31496209ac0a2e633b3edf61f83981bfc - /opt/CAPEv2/storage/analyses/12775/files/8bb985ebbc970eb62dfd8ee8457c03447a211c60f287f6eb6510c012816b6585 —
8bb985ebbc970eb62dfd8ee8457c03447a211c60f287f6eb6510c012816b6585 - /opt/CAPEv2/storage/analyses/12775/files/b612d46644d0e4a3829c4d6715f71d979103aa487624805363b36f5b4f92b118 —
b612d46644d0e4a3829c4d6715f71d979103aa487624805363b36f5b4f92b118 - /opt/CAPEv2/storage/analyses/12775/files/113db5dd30cd53a0d8354dcfed27ce7d045661ef94d004f55bf57cc91fbb69b5 —
113db5dd30cd53a0d8354dcfed27ce7d045661ef94d004f55bf57cc91fbb69b5 - /opt/CAPEv2/storage/analyses/12775/files/c2fb7b2edb4081e936a079ff865ee7a8663f2b1bdd08f298cfb3323229e3ee95 —
c2fb7b2edb4081e936a079ff865ee7a8663f2b1bdd08f298cfb3323229e3ee95 - /opt/CAPEv2/storage/analyses/12775/files/6ec2bb133afa7314deaa7e2fafddad9f3c8cae83f698f0735ea72f2f6e0513ee —
6ec2bb133afa7314deaa7e2fafddad9f3c8cae83f698f0735ea72f2f6e0513ee - /opt/CAPEv2/storage/analyses/12775/files/0cef93faedd86c5f4acf9008f321a0c29f939da97e5548cc5c2d2b33cd078f52 —
0cef93faedd86c5f4acf9008f321a0c29f939da97e5548cc5c2d2b33cd078f52 - /opt/CAPEv2/storage/analyses/12775/files/1195b2e285ed4590045789b1bacd5e7c010139e67d27f51fdc42f9c80c4ea3c9 —
1195b2e285ed4590045789b1bacd5e7c010139e67d27f51fdc42f9c80c4ea3c9 - /opt/CAPEv2/storage/analyses/12775/files/918b1d434b41e90316399a4a92a8a146dfa07598d2f3ccccc67cbc2f89d6dd2a —
918b1d434b41e90316399a4a92a8a146dfa07598d2f3ccccc67cbc2f89d6dd2a - /opt/CAPEv2/storage/analyses/12775/files/5fdd5a647f4af365f9781139950dfa7af0fe219aad4b8da3bcf546dab42aa085 —
5fdd5a647f4af365f9781139950dfa7af0fe219aad4b8da3bcf546dab42aa085 - /opt/CAPEv2/storage/analyses/12775/files/5917440b9ad97a0a2fccdc630ff3cdab1bd514baf5f1bfe022d1c62520454194 —
5917440b9ad97a0a2fccdc630ff3cdab1bd514baf5f1bfe022d1c62520454194 - /opt/CAPEv2/storage/analyses/12775/files/15781f85fbcca9a83118e801d31934932ed3501118a6c739d6546085b5b0e36f —
15781f85fbcca9a83118e801d31934932ed3501118a6c739d6546085b5b0e36f - /opt/CAPEv2/storage/analyses/12775/files/73976171dcfe4fb28922a769ef4aed17451e7c268cb26ba0e780f81f270f1bed —
73976171dcfe4fb28922a769ef4aed17451e7c268cb26ba0e780f81f270f1bed - /opt/CAPEv2/storage/analyses/12775/files/97899c24e958c4e277045949af1fbb3804373a52f263dce5b9aa9518e6bf0dfd —
97899c24e958c4e277045949af1fbb3804373a52f263dce5b9aa9518e6bf0dfd
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786531118&P2=404&P3=2&P4=XhUR0Ml7vVEI13hGK4jJBP%2b%2f9EGowtwUv4md4jBGTkSIopcXVHcCU6a7IC3SHdkJL7EG%2bO64D4hpb5T5zFyHYg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786531183&P2=404&P3=2&P4=elOOrT%2fzY4tcueih9sgdVC0WhoZfgQkHEZvx4xEUZ%2bhNX5842uCjAAMiQa6WPs%2bs5qb7duXgFENasY47MT1tig%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 135.233.95.80
- 20.42.73.31
- 52.123.252.245
- 172.215.188.232
- 4.230.171.124
- 20.247.184.197
- 74.179.77.204
- 74.178.240.51
- 4.150.223.113
- 135.233.45.222
- 203.26.79.13
- 52.123.252.226
- 74.179.71.159
- 52.123.252.194
- 52.182.141.63
- 4.150.223.98
- 72.145.35.105
- 52.148.114.188
- 52.110.12.1
- 52.110.12.2
File paths
- a:\,
- X:\5+
More Zusy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report