MALICIOUS — 96fcbfcfc387d601a143dd88d27778484894c8baf414b931683e9314afc5b708
MALICIOUS — 96fcbfcfc387d601a143dd88d27778484894c8baf414b931683e9314afc5b708 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Prepscram family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
96fcbfcfc387d601a143dd88d27778484894c8baf414b931683e9314afc5b708 - SHA-1:
b9c3cad57d1e0cda2c6340247d9f1cbf7396aa80 - MD5:
1d64642ffe5df72f2a10ad2d1b131730 - imphash:
f1a539a5b71ad53ac586f053145f08ec - File type: pe · Size: 877952 bytes
- Verdict: malicious (98/100) · Family: Prepscram
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Zusy-9957983-0
- Detect It Easy (packer/type): DIE:UPX
- Microsoft Defender: Trojan:Win32/Prepscram!pz
- Emsisoft (Emergency Kit): Gen:Variant.Rootkit.25
- Kaspersky (KVRT): Trojan.Win32.Agent.neyndy
MITRE ATT&CK
Dynamic analysis (windows)
2353 behavior events · 1 ATT&CK techniques · 17 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- msedge.api.cdp.microsoft.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
- assets.msn.com
- kv801.prod.do.dsp.mp.microsoft.com
- cp801.prod.do.dsp.mp.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/12843/files/f1149f2c9eeb0fee7e28ddd032c419499205b51f9dcd8da67aae841064ea6da9 —
f1149f2c9eeb0fee7e28ddd032c419499205b51f9dcd8da67aae841064ea6da9 - /opt/CAPEv2/storage/analyses/12843/files/3a9919756e32a53bfa1cbfe4f6d138688d0ac1fcb962a7b6db3686544e5da061 —
3a9919756e32a53bfa1cbfe4f6d138688d0ac1fcb962a7b6db3686544e5da061 - /opt/CAPEv2/storage/analyses/12843/files/99b435c211dd04040347f248b79a6d1165f51418496688332f9485bd86a9d758 —
99b435c211dd04040347f248b79a6d1165f51418496688332f9485bd86a9d758 - /opt/CAPEv2/storage/analyses/12843/files/d4c61af23c3a067fad7b92603b8398d7b943713addb7e787bceded1183aeed2c —
d4c61af23c3a067fad7b92603b8398d7b943713addb7e787bceded1183aeed2c - /opt/CAPEv2/storage/analyses/12843/files/a8d40e8c8e5e8c0752237135804f611b9a34da69e01d496e2a1f7ed52510ce0c —
a8d40e8c8e5e8c0752237135804f611b9a34da69e01d496e2a1f7ed52510ce0c - /opt/CAPEv2/storage/analyses/12843/files/dd6e3c8a3108fc430b443eb6b00796a9db078c0d81d7416fa153a421b772a448 —
dd6e3c8a3108fc430b443eb6b00796a9db078c0d81d7416fa153a421b772a448 - /opt/CAPEv2/storage/analyses/12843/files/d5f3ce4d4b16144493a6579f02afbf07a8a3ef4eba6a60983ef3ae11e2a22c4f —
d5f3ce4d4b16144493a6579f02afbf07a8a3ef4eba6a60983ef3ae11e2a22c4f - /opt/CAPEv2/storage/analyses/12843/files/b612d46644d0e4a3829c4d6715f71d979103aa487624805363b36f5b4f92b118 —
b612d46644d0e4a3829c4d6715f71d979103aa487624805363b36f5b4f92b118 - /opt/CAPEv2/storage/analyses/12843/files/252594fd406fc82862b7ce219fe1d05d5b6fa3dd183db9b5922c7008afd48f36 —
252594fd406fc82862b7ce219fe1d05d5b6fa3dd183db9b5922c7008afd48f36 - /opt/CAPEv2/storage/analyses/12843/files/966b30bbca4d31937a58209a67d445ac554349d77422f30e703eb202fe0563a4 —
966b30bbca4d31937a58209a67d445ac554349d77422f30e703eb202fe0563a4 - /opt/CAPEv2/storage/analyses/12843/files/d5944fb94a11dde0b5bb5c06332eb9946795b1d0ad70d9aa5bcd3084f3225310 —
d5944fb94a11dde0b5bb5c06332eb9946795b1d0ad70d9aa5bcd3084f3225310 - /opt/CAPEv2/storage/analyses/12843/files/bd8760574c32d5b803b71616d23ba25166e2631bbb0ca522d4b8b730d824027e —
bd8760574c32d5b803b71616d23ba25166e2631bbb0ca522d4b8b730d824027e - /opt/CAPEv2/storage/analyses/12843/files/0095fe40f55392c5044477f73100fe0a5297307ab4a506ce64ccdacb084d21b1 —
0095fe40f55392c5044477f73100fe0a5297307ab4a506ce64ccdacb084d21b1 - /opt/CAPEv2/storage/analyses/12843/files/7fa343b3baa409d1d59f854c9efd779361c0a9ac5f7350bb1e020c1ffe734e16 —
7fa343b3baa409d1d59f854c9efd779361c0a9ac5f7350bb1e020c1ffe734e16 - /opt/CAPEv2/storage/analyses/12843/files/a61e112a56ac95a98a45cea11a6d22eb94e59b93ae34818ddd6db0d2dbc078ec —
a61e112a56ac95a98a45cea11a6d22eb94e59b93ae34818ddd6db0d2dbc078ec
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786532773&P2=404&P3=2&P4=ZNOtI%2bkmhenh0xLcTJKz2%2byHda5KiasWE6hP0GIILxKWAIs1QAnhG62qXkp%2fNanWU0%2fuNYScqlb8M5hSoHB5Gw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786532812&P2=404&P3=2&P4=ld%2f4f4DVo%2booykl3Gcnra6sNWe3vcfgjH9A8YUlb2eMTGaMrNYueQTIQuI%2f6ZCABpYDsQknqYop%2f1MI35%2ffrjQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 40.79.150.120
- 52.123.252.198
- 4.230.171.124
- 4.144.132.223
- 20.42.179.204
- 4.247.188.233
- 74.179.77.204
- 104.46.162.229
- 135.233.95.135
- 52.123.252.193
- 135.232.92.34
- 203.26.79.13
- 52.123.252.204
- 52.110.12.2
- 135.233.45.223
- 52.110.12.56
- 40.79.163.155
- 20.184.175.2
- 52.123.252.241
- 72.145.35.96
- 52.123.252.233
- 52.148.114.188
- 52.110.12.18
- 52.110.12.14
More Prepscram samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report