MALICIOUS — 9613d2f4bf20494728f3d48d9bddcb61820a99cd347287f100ab7f20fd390e8a
MALICIOUS — 9613d2f4bf20494728f3d48d9bddcb61820a99cd347287f100ab7f20fd390e8a is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Zusy family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
9613d2f4bf20494728f3d48d9bddcb61820a99cd347287f100ab7f20fd390e8a - SHA-1:
17d53d1e09523477fdff5648ac51ef12afa1ffe4 - MD5:
8a480edf32fa826857d338aeb2eef5ad - imphash:
f1a539a5b71ad53ac586f053145f08ec - File type: pe · Size: 877952 bytes
- Verdict: malicious (98/100) · Family: Zusy
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Zusy-9957983-0
- Detect It Easy (packer/type): DIE:UPX
- Microsoft Defender: Trojan:Win32/Prepscram!pz
- Emsisoft (Emergency Kit): Gen:Variant.Rootkit.25
- Kaspersky (KVRT): Trojan.Win32.Agent.neyndy
MITRE ATT&CK
Dynamic analysis (windows)
2354 behavior events · 1 ATT&CK techniques · 17 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
- licensing.mp.microsoft.com
- www.bing.com
- msedge.api.cdp.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
- kv801.prod.do.dsp.mp.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/12677/files/3ceab1f25ef4ae9f00c543b60b25dfac8c34c60bcad2688578136bc4985d39a2 —
3ceab1f25ef4ae9f00c543b60b25dfac8c34c60bcad2688578136bc4985d39a2 - /opt/CAPEv2/storage/analyses/12677/files/03c70d65862ab9df54af526979dbcf6a44406d3f2d043ef9cf69b5a1ccf4d35e —
03c70d65862ab9df54af526979dbcf6a44406d3f2d043ef9cf69b5a1ccf4d35e - /opt/CAPEv2/storage/analyses/12677/files/80064fa58e4174f16de8c877738083eabbb6dffcbd5209a5503686d2024e4d65 —
80064fa58e4174f16de8c877738083eabbb6dffcbd5209a5503686d2024e4d65 - /opt/CAPEv2/storage/analyses/12677/files/f477519f4a7dfa5b1675213ac93c0eff43dd0c978b9be3194e2d984049f9c072 —
f477519f4a7dfa5b1675213ac93c0eff43dd0c978b9be3194e2d984049f9c072 - /opt/CAPEv2/storage/analyses/12677/files/e1f0e99738edd0253e253629671734e599acbe8cd54cbaf1f62b8013a092bcad —
e1f0e99738edd0253e253629671734e599acbe8cd54cbaf1f62b8013a092bcad - /opt/CAPEv2/storage/analyses/12677/files/e070458f91c53d8852c1504282776249054faf92793c93854597922de48b1e76 —
e070458f91c53d8852c1504282776249054faf92793c93854597922de48b1e76 - /opt/CAPEv2/storage/analyses/12677/files/b612d46644d0e4a3829c4d6715f71d979103aa487624805363b36f5b4f92b118 —
b612d46644d0e4a3829c4d6715f71d979103aa487624805363b36f5b4f92b118 - /opt/CAPEv2/storage/analyses/12677/files/b2a4bdfa5752137d04d847bd9679aaf467e10102b5494a8b80f3a085a5ce4445 —
b2a4bdfa5752137d04d847bd9679aaf467e10102b5494a8b80f3a085a5ce4445 - /opt/CAPEv2/storage/analyses/12677/files/7a5876a25c8f912a3a4038672cac6c8e9fe30f7c739840571d118fd8e2fe00ef —
7a5876a25c8f912a3a4038672cac6c8e9fe30f7c739840571d118fd8e2fe00ef - /opt/CAPEv2/storage/analyses/12677/files/3146c0db90517d6881bdae6bf6ff867767802a91ee856665a4ab95fa56b876cc —
3146c0db90517d6881bdae6bf6ff867767802a91ee856665a4ab95fa56b876cc - /opt/CAPEv2/storage/analyses/12677/files/a908f1b05b719feebc6e02cba92cda0a812e0f572478f294a1e400fc4070bec4 —
a908f1b05b719feebc6e02cba92cda0a812e0f572478f294a1e400fc4070bec4 - /opt/CAPEv2/storage/analyses/12677/files/14251ef713c5f46b790df8c77edfc2a72e3ac92106c3b8afd5f8f25e6c157037 —
14251ef713c5f46b790df8c77edfc2a72e3ac92106c3b8afd5f8f25e6c157037 - /opt/CAPEv2/storage/analyses/12677/files/f877738db95bc309afa7742fa271f87b381a5f081bc2134fd6fd1c6c2e91d31d —
f877738db95bc309afa7742fa271f87b381a5f081bc2134fd6fd1c6c2e91d31d - /opt/CAPEv2/storage/analyses/12677/files/0b251866101e348eed7c01ba60602e67cafc29c2e7000a871b4e0a23029edc1d —
0b251866101e348eed7c01ba60602e67cafc29c2e7000a871b4e0a23029edc1d - /opt/CAPEv2/storage/analyses/12677/files/4cab4e2863e5cd0f8e6c1dcf19925591d802b04f95ea464dc316bdab3b21f91f —
4cab4e2863e5cd0f8e6c1dcf19925591d802b04f95ea464dc316bdab3b21f91f
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786528633&P2=404&P3=2&P4=PglL8%2f%2fs8jsrmXNtPA14smFPPLCJL3xnbUYU4ow7ctDjxBN1z949RVdI7sWZvN9tx%2bOHs8B4H4MbZNc4Ls5mbg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786528668&P2=404&P3=2&P4=MARmodqJE83IZocp47jlD40LrIbNWyomrnpVe34EKMCsi2uweW6fSL5vbNLHphZS3cSz4qboByeXD1LmHyLThw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- w.de
- 6tz0.ru
Embedded IP addresses
- 20.184.175.15
- 57.155.101.212
- 4.230.171.124
- 4.144.132.223
- 135.233.95.144
- 74.178.240.51
- 74.178.76.44
- 51.11.192.48
- 203.26.79.13
- 135.233.45.223
- 92.223.78.30
- 13.89.179.12
- 52.168.117.175
- 172.66.2.5
- 52.110.12.16
- 52.110.12.55
- 72.154.7.104
- 52.148.114.188
- 52.110.12.4
- 52.110.12.25
More Zusy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report