MALICIOUS — a9b897887cee17d575f3b11f7df70c982e26f9dce57c3727d29bec942256bdb2
MALICIOUS — a9b897887cee17d575f3b11f7df70c982e26f9dce57c3727d29bec942256bdb2 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Zusy family. 6 of 52 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
a9b897887cee17d575f3b11f7df70c982e26f9dce57c3727d29bec942256bdb2 - SHA-1:
a380044228b0cb19a687ebc81d124b4995d99bb7 - MD5:
a88bc6ea7dcc825c69b45f9c4ff832ff - imphash:
f1a539a5b71ad53ac586f053145f08ec - File type: pe · Size: 991616 bytes
- Verdict: malicious (100/100) · Family: Zusy
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Zusy-9957983-0
- Detect It Easy (packer/type): DIE:UPX
- Kaspersky (KVRT): Trojan.Win32.Agent.neyndy
- Microsoft Defender: Trojan:Win32/Prepscram!pz
- Emsisoft (Emergency Kit): Gen:Variant.Virus.8
MITRE ATT&CK
Dynamic analysis (windows)
11608 behavior events · 2 ATT&CK techniques · 65 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- msedge.api.cdp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
- licensing.mp.microsoft.com
- assets.msn.com
- kv801.prod.do.dsp.mp.microsoft.com
- cp801.prod.do.dsp.mp.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/12811/files/545cb9cd3f8f47849e24bfbe5f25d821f1ffa8e62628040763bd7f04a05599f4 —
545cb9cd3f8f47849e24bfbe5f25d821f1ffa8e62628040763bd7f04a05599f4 - /opt/CAPEv2/storage/analyses/12811/files/7368e77d0f547797579bad68d017d51499afdaaff0b7f99365029d244cddccb7 —
7368e77d0f547797579bad68d017d51499afdaaff0b7f99365029d244cddccb7 - /opt/CAPEv2/storage/analyses/12811/files/3b9b6ba4d479c7daf025d40eb6ac4fb806838d14d979b4fc79c721f3c514d1e2 —
3b9b6ba4d479c7daf025d40eb6ac4fb806838d14d979b4fc79c721f3c514d1e2 - /opt/CAPEv2/storage/analyses/12811/files/1ac9785462b0e86303d612861b4ed1bb06116d6e8b095a615e724a1427fba7f4 —
1ac9785462b0e86303d612861b4ed1bb06116d6e8b095a615e724a1427fba7f4 - /opt/CAPEv2/storage/analyses/12811/files/03f121d49cb0bf1851f19da32deb92b140fd79383bfae33b7e78a8f1d597d414 —
03f121d49cb0bf1851f19da32deb92b140fd79383bfae33b7e78a8f1d597d414 - /opt/CAPEv2/storage/analyses/12811/files/499982c4537a37ac3e23aa1276b87b81667f3305074bb9ba21cacf635dd10ba4 —
499982c4537a37ac3e23aa1276b87b81667f3305074bb9ba21cacf635dd10ba4 - /opt/CAPEv2/storage/analyses/12811/files/df27d984f554f9a4eb9463c0a4d529e598ecfc5c6c7843f0f112475aafe7140d —
df27d984f554f9a4eb9463c0a4d529e598ecfc5c6c7843f0f112475aafe7140d - /opt/CAPEv2/storage/analyses/12811/files/9d90d3bd96d9b338aaa9466f91e32f26fb695dd478683e493d50ce31cb3b5b4d —
9d90d3bd96d9b338aaa9466f91e32f26fb695dd478683e493d50ce31cb3b5b4d - /opt/CAPEv2/storage/analyses/12811/files/5e32a41d517102e7235f495ef18374abc03667d887d88914def237176f3dffc8 —
5e32a41d517102e7235f495ef18374abc03667d887d88914def237176f3dffc8 - /opt/CAPEv2/storage/analyses/12811/files/842944fe0f5716cdcc8c6011062d6309c80f7dffa032e407cbcaf61129dd8a1a —
842944fe0f5716cdcc8c6011062d6309c80f7dffa032e407cbcaf61129dd8a1a - /opt/CAPEv2/storage/analyses/12811/files/69108c86e91eb56c6a95e69eafffc56ee9385d0506b5609498e65c504d97457d —
69108c86e91eb56c6a95e69eafffc56ee9385d0506b5609498e65c504d97457d - /opt/CAPEv2/storage/analyses/12811/files/d533c56acfd927b691ac5e63781da9e528be7403099e1569bd562deeff5c53ce —
d533c56acfd927b691ac5e63781da9e528be7403099e1569bd562deeff5c53ce - /opt/CAPEv2/storage/analyses/12811/files/a8fbf1423d4ba44cf58f4400f2d928f07a82b49c31922e48236c8e90fa70f0c7 —
a8fbf1423d4ba44cf58f4400f2d928f07a82b49c31922e48236c8e90fa70f0c7 - /opt/CAPEv2/storage/analyses/12811/files/47c65594cccfead7828369c6fff2489e5e352a7fd32b010e3a8d6534252afdb1 —
47c65594cccfead7828369c6fff2489e5e352a7fd32b010e3a8d6534252afdb1 - /opt/CAPEv2/storage/analyses/12811/files/c0cc7094360a1a7580df1348099ecdd0c968e2f63c5044084daa5e3727b78db7 —
c0cc7094360a1a7580df1348099ecdd0c968e2f63c5044084daa5e3727b78db7
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786531982&P2=404&P3=2&P4=jvVIjtscUg7KU7Yb9btfXeDaQIx0xsjyy2%2fU48Xlfne9o%2fwBMgxt6RY20RsXz3acA7Mb8jiYmABQWxTHk2pk%2fw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786532056&P2=404&P3=2&P4=TwuProbDgCkcPNyY82LYVlNFLWfxu4wTcPuhSvZezyvqjNm4IC9t%2biYJcXtFN44bg24m5GGfL%2f8KVx0fWLHvMg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 13.89.179.15
- 52.123.252.233
- 4.230.171.124
- 40.84.97.4
- 4.144.132.114
- 48.211.4.16
- 74.179.77.204
- 20.165.94.54
- 52.123.252.234
- 74.178.76.44
- 104.46.162.231
- 203.26.79.13
- 135.234.160.246
- 92.223.78.30
- 52.110.12.51
- 52.110.12.25
- 172.178.240.161
- 72.153.5.61
- 52.168.117.171
- 51.11.192.51
- 52.148.114.188
- 20.184.175.14
- 52.110.12.19
- 52.110.12.8
More Zusy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report