MALICIOUS — 0e7d26591de84ea7b5c1be04dd92a37a05f0df4592b0064ce498de4bf95a4178
MALICIOUS — 0e7d26591de84ea7b5c1be04dd92a37a05f0df4592b0064ce498de4bf95a4178 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (82/100), attributed to the Maldoc family. 5 of 52 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
0e7d26591de84ea7b5c1be04dd92a37a05f0df4592b0064ce498de4bf95a4178 - SHA-1:
61e8f5043450fdf67150b31399f601fa970f80fb - MD5:
94bcc50ac7be6003fe8c8e8b43e6c9a0 - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
24576:mvpQrniqe1eamEdx56F/ur1aYWzpcXYxBd2R5oWWylGl/PM7:sp0K1JwbEgzElWylGVPM7 - TLSH:
T183559D9E61499306EA728F68E5D04F4E1017F0E9A4B5188C6EE7D19D33FCCCBD861292 - Submitted as: 0e7d26591de84ea7b5c1be04dd92a37a05f0df4592b0064ce498de4bf95a4178
- File type: pe · Size: 1288192 bytes
- Verdict: malicious (82/100) · Family: Maldoc
Detections (5 of 52 engines)
- capa (capabilities): capability:credential-access
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: ReversingLabs: RL_Formbook_XLoader
- Microsoft Defender: Trojan:Win32/Wacatac.B!ml
MITRE ATT&CK
Why this verdict
The malicious score of 82/100 is the fusion of 7 weighted signals:
- access stored credentials (rule
access stored credentials) - capa signal, weight 0.50, confidence 0.80 - YARA: delivr.to detections flagged DLV_Maldoc_VBA_AutoExec (rule
DLV_Maldoc_VBA_AutoExec) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: ReversingLabs flagged RL_Formbook_XLoader (rule
RL_Formbook_XLoader) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://www.ctcodeinfo.com/favicon.ico, http://ngdatas.pw/, https://www.listincode.com/ - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://www.ctcodeinfo.com/favicon.ico
- http://ngdatas.pw/
- https://www.listincode.com/
- http://www.iyiqian.com/
- http://www.hbgents.top/
- http://www.rsnzhy.com/
- http://www.channelinfo.pw/index.php/Home/Index/getExe
- https://iplogger.org/1rDMq7
- https://iplogger.org/1rd8N6
- https://iplogger.org/1spuy7
- https://iplogger.org/1uS4i7
- https://iplogger.org/1uW6i7
- https://iplogger.org/1TW3i7
- https://iplogger.org/1q6Jt7
- https://iplogger.org/1DE477
- https://iplogger.org/14Qju7
- https://iplogger.org/14ePy7
- https://iplogger.org/1UKG97
- https://iplogger.org/1O2BH
- https://iplogger.org/1OZVH
- https://iplogger.org/1OXFG
- https://iplogger.org/1wnqn7
- https://iplogger.org/1aaVp7
- https://iplogger.org/1OhAG
- https://iplogger.org/16ajh7
Embedded domains
- ctcodeinfo.com
- www.ctcodeinfo.com
- ngdatas.pw
- www.listincode.com
- www.iyiqian.com
- www.hbgents.top
- www.rsnzhy.com
- www.channelinfo.pw
- iplogger.org
- prntscr.com
- www.google.com
- www.bing.com
- www.aol.com
- m.facebook.com
- graph.facebook.com
- www.facebook.com
- facebook.com
- www.amazon.com
- amazon.com
- amazon.co.uk
- www.eceinfos.top
- sm.ms
More Maldoc samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report