MALICIOUS — 9259216ca6a16d6f063b2c1e9c844941218a59452133337136bdfca277a8d543
MALICIOUS — 9259216ca6a16d6f063b2c1e9c844941218a59452133337136bdfca277a8d543 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Prepscram family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
9259216ca6a16d6f063b2c1e9c844941218a59452133337136bdfca277a8d543 - SHA-1:
fe0b00a2b22cb70cdf1c827a1232c2437ccaae7b - MD5:
059dc1d5b1724aec37d538f8497f1815 - imphash:
f1a539a5b71ad53ac586f053145f08ec - File type: pe · Size: 83880 bytes
- Verdict: malicious (100/100) · Family: Prepscram
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Zusy-9957983-0
- Detect It Easy (packer/type): DIE:UPX
- Microsoft Defender: Trojan:Win32/Prepscram!pz
- Emsisoft (Emergency Kit): Gen:Variant.Rootkit.25
- Kaspersky (KVRT): Trojan.Win32.Agent.neyndy
MITRE ATT&CK
Dynamic analysis (windows)
2357 behavior events · 1 ATT&CK techniques · 17 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- settings-win.data.microsoft.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- msedge.api.cdp.microsoft.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- geo.prod.do.dsp.mp.microsoft.com
- licensing.mp.microsoft.com
- assets.msn.com
- kv801.prod.do.dsp.mp.microsoft.com
- cp801.prod.do.dsp.mp.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/12944/files/d7db560f5182550f909ca87bd1d84612f6e90d944bbf0ca77163e9f7e323c963 —
d7db560f5182550f909ca87bd1d84612f6e90d944bbf0ca77163e9f7e323c963 - /opt/CAPEv2/storage/analyses/12944/files/1388a8c0d53322284f44a8992dc83e35df68ab7bfdd71c2c3413e51567e1fc52 —
1388a8c0d53322284f44a8992dc83e35df68ab7bfdd71c2c3413e51567e1fc52 - /opt/CAPEv2/storage/analyses/12944/files/d8120b89115fd182124a674f41164873e00d798807ad0f0249620e64bf9d1b5a —
d8120b89115fd182124a674f41164873e00d798807ad0f0249620e64bf9d1b5a - /opt/CAPEv2/storage/analyses/12944/files/abd673957d43d23326904bfa2d1f8b73f59737d422e5ac7ecbd8a328d22c6996 —
abd673957d43d23326904bfa2d1f8b73f59737d422e5ac7ecbd8a328d22c6996 - /opt/CAPEv2/storage/analyses/12944/files/b612d46644d0e4a3829c4d6715f71d979103aa487624805363b36f5b4f92b118 —
b612d46644d0e4a3829c4d6715f71d979103aa487624805363b36f5b4f92b118 - /opt/CAPEv2/storage/analyses/12944/files/b012515886a5381b8ef6ef8a0257b68d913959329000f61c78519070907e6cdc —
b012515886a5381b8ef6ef8a0257b68d913959329000f61c78519070907e6cdc - /opt/CAPEv2/storage/analyses/12944/files/d8a0ab12177aa46c399f7d29bcdee4691eaa4e65f69f9460f580f1643a7dd734 —
d8a0ab12177aa46c399f7d29bcdee4691eaa4e65f69f9460f580f1643a7dd734 - /opt/CAPEv2/storage/analyses/12944/files/ece7c40f7d43bda2ebb5840788bab761af8a27cebdc047fa355d0c2aae531844 —
ece7c40f7d43bda2ebb5840788bab761af8a27cebdc047fa355d0c2aae531844 - /opt/CAPEv2/storage/analyses/12944/files/fb078e3015ab1893ce71a97bba7b8565d91dffce968be138e917dfbe623388c1 —
fb078e3015ab1893ce71a97bba7b8565d91dffce968be138e917dfbe623388c1 - /opt/CAPEv2/storage/analyses/12944/files/be65cfeba84a759cff37de53209de582ce617e94b5c5a66cbffaeea07ad58ac5 —
be65cfeba84a759cff37de53209de582ce617e94b5c5a66cbffaeea07ad58ac5 - /opt/CAPEv2/storage/analyses/12944/files/b507c81bc89fb5d0168a2998bdf451d59f5104444190e0fd29d45e5ad8669ab5 —
b507c81bc89fb5d0168a2998bdf451d59f5104444190e0fd29d45e5ad8669ab5 - /opt/CAPEv2/storage/analyses/12944/files/dc8fe72fa2dd24cbb8dc0af80c1a967ebe85c5f188759452b88656b31ced6f3b —
dc8fe72fa2dd24cbb8dc0af80c1a967ebe85c5f188759452b88656b31ced6f3b - /opt/CAPEv2/storage/analyses/12944/files/d42c5333215a29597452dbbf5e36730c82f7021569baabaa3b2374ae54b3bdd9 —
d42c5333215a29597452dbbf5e36730c82f7021569baabaa3b2374ae54b3bdd9 - /opt/CAPEv2/storage/analyses/12944/files/a160f8f98c08f39553367f28676bac4749e24dd61eca79b9c2aecb313256d110 —
a160f8f98c08f39553367f28676bac4749e24dd61eca79b9c2aecb313256d110 - /opt/CAPEv2/storage/analyses/12944/files/e6c8561d2a567b477d230045e24f5786ef391dcff268ab58bb17d135e9982658 —
e6c8561d2a567b477d230045e24f5786ef391dcff268ab58bb17d135e9982658
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786535255&P2=404&P3=2&P4=KNc9BGmv0Ai3WyyPCNEvMFg9Tei1mAuQiv5UziKj4Ta8ZsugFtivrHAb%2b6zT7N5%2f%2fxSpGOYf2YSYPx3ajuB1ig%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786535314&P2=404&P3=2&P4=eLFNVaR7Ukv81rXpgjqve0P0AxknQDlfks0gKl8RCaR5rCMMvs8Ez2nGLWB5MSdAa%2f1pJ8TTnwwZGUQ%2fJg%2bFhQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 20.42.179.192
- 20.184.175.9
- 52.123.252.215
- 4.230.171.124
- 20.247.184.197
- 52.123.252.224
- 74.178.76.128
- 74.178.76.44
- 74.178.76.54
- 20.184.175.23
- 52.123.252.203
- 203.26.79.13
- 4.150.223.110
- 172.178.240.161
- 4.150.223.115
- 92.223.78.30
- 52.110.12.49
- 72.145.35.114
- 52.148.114.188
- 135.233.95.80
- 52.110.12.15
- 52.110.12.1
More Prepscram samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report