MALICIOUS — 0c488c86e283765f1dc55bb16d5fd2170fb436fa3f94552bcdd13a128f24d5b4
MALICIOUS — 0c488c86e283765f1dc55bb16d5fd2170fb436fa3f94552bcdd13a128f24d5b4 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Maldoc family. 6 of 52 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
0c488c86e283765f1dc55bb16d5fd2170fb436fa3f94552bcdd13a128f24d5b4 - SHA-1:
2282073ac119b126f7d68639f3a15df725bf5465 - MD5:
79a9582b9ad99557c3e21a4d6338cb8c - imphash:
f0d4d888365525da27840d92b16e9939 - ssdeep:
24576:9qmTCEKKYJkwrsrIZmDrlSa10PliA5wW96H06:9qCYYcMo4mlirrHb - TLSH:
T19E57288FF31E5317C53C8B2869887D9DD19575D41D7EF688BEC3943A04AE827E82102A - Submitted as: 0c488c86e283765f1dc55bb16d5fd2170fb436fa3f94552bcdd13a128f24d5b4
- File type: pe · Size: 1491607 bytes
- Verdict: malicious (97/100) · Family: Maldoc
Detections (6 of 52 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Trojan.Agent-1367175
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Kaspersky (KVRT): HEUR:Worm.Win32.AutoRun.gen
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Agent-1367175 (rule
Win.Trojan.Agent-1367175) - engine signal, weight 0.90, confidence 0.95 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: delivr.to detections flagged DLV_Maldoc_VBA_AutoExec (rule
DLV_Maldoc_VBA_AutoExec) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: 3.0.3.0 - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://crl.thawte.com/ThawtePremiumServerCA.crl0
- http://crl.verisign.com/tss-ca.crl0
- http://crl.thawte.com/ThawteCodeSigningCA.crl02
- https://www.verisign.com/rpa
- https://www.verisign.com/rpa01
- http://crl.verisign.com/pca3.crl0
- http://CSC3-2004-crl.verisign.com/CSC3-2004.crl0D
- https://www.verisign.com/rpa0
- http://www.microsoft.com/pki/certs/tspca.crt0
- http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl0O
- http://office.microsoft.com
- http://go.microsoft.com/fwlink?LinkId=83
- http://www.microsoft.com/windows/ie/
Embedded domains
- crl.thawte.com
- crl.verisign.com
- msn.com
- microsoft.com
- www.verisign.com
- crl.microsoft.com
- www.microsoft.com
- office.microsoft.com
- go.microsoft.com
- watson.microsoft.com
- csc3-2004-crl.verisign.com
Embedded IP addresses
- 3.0.3.0
Registry keys
- HKLM\Software\Microsoft\Internet
- HKCU\Software
- HKCU\Software\Policies
- HKLM\Software
- HKLM\Software\Policies
File paths
- e:\fx19rel\WINNT_5.2_Depend\mozilla\obj-fx-trunk\toolkit\crashreporter\client\crashreporter.pdb
- f:\dd\vsproject\xmake\XMakeCommandLine\objr\i386\MSBuild.pdb
- f:\dd\tools\devdiv\FinalPublicKey.snk
- C:\Loggers\MyLogger.dll;OutputAsHTML
- C:\My.dll
- C:\Logger.dll
- f:\rtm\vctools\vc7libs\ship\atlmfc\include\afxwin2.inl
- f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cpp
- f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp
- g:\acro_root_at\acrobat\installers\bootstrapexe_small\release\Setup.pdb
- g:\Acro_root_at\Acrobat\Viewer\Win\output\acrobat\AcroRd32Exe.pdb
- g:\acro_root_at\acrobat\viewer\win\output\acrobat\AcroRd32Info.pdb
- c:\video_ts\video_ts.ifo
More Maldoc samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report