MALICIOUS — b5150dc5bd89c12dc13d70fca48349a42967917b6ff6c3518a4df497c76e7223
MALICIOUS — b5150dc5bd89c12dc13d70fca48349a42967917b6ff6c3518a4df497c76e7223 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Neyndy family. 6 of 52 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
b5150dc5bd89c12dc13d70fca48349a42967917b6ff6c3518a4df497c76e7223 - SHA-1:
24ce1b9b9d1ec4e6fad6aae76105e791fc8ab881 - MD5:
1bc5bd13e9bcf011619d2395dea94477 - imphash:
f1a539a5b71ad53ac586f053145f08ec - File type: pe · Size: 991616 bytes
- Verdict: malicious (100/100) · Family: Neyndy
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Zusy-9957983-0
- Detect It Easy (packer/type): DIE:UPX
- Kaspersky (KVRT): Trojan.Win32.Agent.neyndy
- Microsoft Defender: Trojan:Win32/Prepscram!pz
- Emsisoft (Emergency Kit): Gen:Variant.Virus.8
MITRE ATT&CK
Dynamic analysis (windows)
13574 behavior events · 2 ATT&CK techniques · 65 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- licensing.mp.microsoft.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
- tas02.sls.update.microsoft.com
- www.bing.com
- fe3cr.delivery.mp.microsoft.com
- v10.events.data.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/13482/files/da22b54956129881347576e5908dd9ead015139c0a291098fcc5186cd0612f18 —
da22b54956129881347576e5908dd9ead015139c0a291098fcc5186cd0612f18 - /opt/CAPEv2/storage/analyses/13482/files/c0a31efcb817452adcb443a57dbd331276339c528a4b94aac4fe3589426647fb —
c0a31efcb817452adcb443a57dbd331276339c528a4b94aac4fe3589426647fb - /opt/CAPEv2/storage/analyses/13482/files/7368e77d0f547797579bad68d017d51499afdaaff0b7f99365029d244cddccb7 —
7368e77d0f547797579bad68d017d51499afdaaff0b7f99365029d244cddccb7 - /opt/CAPEv2/storage/analyses/13482/files/275b098ee3fa8c033deb1bbac41725a074a582cdaca33d0e8121786290407dea —
275b098ee3fa8c033deb1bbac41725a074a582cdaca33d0e8121786290407dea - /opt/CAPEv2/storage/analyses/13482/files/7519cf4b13e77134d5a9759a555a903c909a5140410a0c5fc93c02d103cf7bb2 —
7519cf4b13e77134d5a9759a555a903c909a5140410a0c5fc93c02d103cf7bb2 - /opt/CAPEv2/storage/analyses/13482/files/332793482f299aae6634f4de895693dd4cec04490568b3ae0a6a608d6caa79ce —
332793482f299aae6634f4de895693dd4cec04490568b3ae0a6a608d6caa79ce - /opt/CAPEv2/storage/analyses/13482/files/1ac9785462b0e86303d612861b4ed1bb06116d6e8b095a615e724a1427fba7f4 —
1ac9785462b0e86303d612861b4ed1bb06116d6e8b095a615e724a1427fba7f4 - /opt/CAPEv2/storage/analyses/13482/files/7090b4e5d447a7f7de06463228f58070027e768ae4ada76d2ccb345a33cec793 —
7090b4e5d447a7f7de06463228f58070027e768ae4ada76d2ccb345a33cec793 - /opt/CAPEv2/storage/analyses/13482/files/16425befe59b437056b2efd9b4297997a6a9afd9970e671c15c918cd1dbd188b —
16425befe59b437056b2efd9b4297997a6a9afd9970e671c15c918cd1dbd188b - /opt/CAPEv2/storage/analyses/13482/files/196b2474b950a621c81a8732c95f3378302decf1ee96da531a17fc6b2387ea48 —
196b2474b950a621c81a8732c95f3378302decf1ee96da531a17fc6b2387ea48 - /opt/CAPEv2/storage/analyses/13482/files/c338fde7bc459c0bbffc91aa8710f0701a9c8a22e34742dde0cdd324db42681e —
c338fde7bc459c0bbffc91aa8710f0701a9c8a22e34742dde0cdd324db42681e - /opt/CAPEv2/storage/analyses/13482/files/69108c86e91eb56c6a95e69eafffc56ee9385d0506b5609498e65c504d97457d —
69108c86e91eb56c6a95e69eafffc56ee9385d0506b5609498e65c504d97457d - /opt/CAPEv2/storage/analyses/13482/files/6e19fa020d03c03a5ce561735184715baf375eec32414cb3642c0db09670b025 —
6e19fa020d03c03a5ce561735184715baf375eec32414cb3642c0db09670b025 - /opt/CAPEv2/storage/analyses/13482/files/7cc53faaaa011140fb91d1fcfdeee1313ff4a8ca1ab08845c715a9f70d377904 —
7cc53faaaa011140fb91d1fcfdeee1313ff4a8ca1ab08845c715a9f70d377904 - /opt/CAPEv2/storage/analyses/13482/files/182f4592fdf43e2ee7dec0ebc944dc4868723c5499e927033105b4cc49d9d5b5 —
182f4592fdf43e2ee7dec0ebc944dc4868723c5499e927033105b4cc49d9d5b5
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786548969&P2=404&P3=2&P4=faFJTETl1gz9hfaxq5HwQXd2bgVQEIT5cU3xI%2fZXQ5euRtEPwU3z3NRBpWOKVoM9kavP5EYalDooFqFgyswaog%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786549004&P2=404&P3=2&P4=J0gjY8SXzcBnQlK%2b0XcXnGkGt9zwFs09%2fgphZ4hEsL%2bdY8hP1jnzSvhG%2f87c17SvPXU8BhEfY7PNY4ZUuf25Bg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 52.182.143.212
- 52.123.252.222
- 20.247.185.124
- 4.230.171.124
- 85.210.196.11
- 74.178.76.128
- 20.184.175.3
- 74.178.240.51
- 135.232.92.137
- 172.178.240.161
- 135.233.45.221
- 203.26.79.13
- 135.232.92.34
- 4.150.223.109
- 52.110.12.53
- 52.110.12.15
- 40.79.167.10
- 52.148.114.188
- 72.145.35.106
- 52.110.12.52
- 52.110.12.14
More Neyndy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report