MALICIOUS — 1cf26c9e96b1669b9dd847da8a64afc5ae2aa51c994eaef351eac5dd719b7f7a
MALICIOUS — 1cf26c9e96b1669b9dd847da8a64afc5ae2aa51c994eaef351eac5dd719b7f7a is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Delf family. 5 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
1cf26c9e96b1669b9dd847da8a64afc5ae2aa51c994eaef351eac5dd719b7f7a - SHA-1:
25e687b0a7e60cd15a54dcb878887a61c1743deb - MD5:
801e14b021040ac53bdad167c8a6eb7d - imphash:
9973fdd4b86d866b3faa39fa66cf7e0a - ssdeep:
6144:fj2jfIz+T7qadEZj+EmjBcTCqoGLI/j8aSIlAXESdPL/EGzKEjrFi:6H7qFSNjBcCqX9Hz/BO+E - TLSH:
T16F4A9EE2D309B30BE1D2DB68794E8E4E10A7E4EEE1BE3BCC9647105925B6493640F4C5 - Submitted as: 1cf26c9e96b1669b9dd847da8a64afc5ae2aa51c994eaef351eac5dd719b7f7a
- File type: pe · Size: 458012 bytes
- Verdict: malicious (99/100) · Family: Delf
Detections (5 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Delf-6737076-0
- Detect It Easy (packer/type): DIE:Turbo Linker
- Microsoft Defender: Worm:Win32/Xolxo.A
- Kaspersky (KVRT): P2P-Worm.Win32.Delf.aj
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Win.Malware.Delf-6737076-0 (rule
Win.Malware.Delf-6737076-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Worm:Win32/Xolxo.A (rule
Worm:Win32/Xolxo.A) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged P2P-Worm.Win32.Delf.aj (rule
P2P-Worm.Win32.Delf.aj) - engine signal, weight 0.55, confidence 0.85 - Contacted 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - 1 behavioral detection(s) across 1 rule(s): Discovery: enumerates installed security software [low] (rule
tl-security-software-discovery) - dynamic signal, weight 0.20, confidence 0.90 - Packing/obfuscation: UPX, Turbo Linker - static signal, weight 0.25, confidence 0.55
- Dropped 48 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
37976 behavior events · 0 ATT&CK techniques · 50 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- th.bing.com
- fe3cr.delivery.mp.microsoft.com
- settings-win.data.microsoft.com
- v10.events.data.microsoft.com
Dropped files
- C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe -
eb9f9422781a013f31bcc46f6ffb485a3fac1a899b396510969992d7ee36aa2f - C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe -
b8a9d5807917687ab25ef2c5759f7f1520fda63f734924b93c86e5524d0e7f68 - bf4d8736fe60410f0845563df7aa427002ceb383f977634bf08ce773474084a3 -
bf4d8736fe60410f0845563df7aa427002ceb383f977634bf08ce773474084a3 - C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe -
377693e2ca6eefba36f61373194f572541a409cb10808b8c71d52897a6df3e8f - C:\Program Files\7-Zip\Uninstall.exe -
0d6090787b81419b6c3ecf0becd174f74ed881462b5607da4d27093b15a77813 - bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 -
bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 - C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe -
72599da51a54609cda164a4aeab0a38a6a9b15913f6f02d65bf3cd28b815a4ca - C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe -
ef1ff47c0e0b5e35574e9b94c5ca1cb6b7805dff6c8fb2421dbf5dce4ca421a8 - C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe -
46b59eae439080d58ddef9cb6ee84e6743f8bde1a82d08d4af097303bae502de - C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe -
79671bf6759f645dfeb021e3fcece87abe20b7c6be7ee7bf9c362603056a23ee - C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe -
783613fb9fcf9a6beaaebb3366834ed0d3fa5a69a0a59fcfbdd39115b7e7f06c - C:\Program Files\7-Zip\7z.exe -
01d21000ff482bc7fa789252114a9c098120775e58fb9467c4368a07e746d537 - C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe -
7ab807b2f85d1de86a4ddbdc9efffe045c74d75668f9e7428999e863a062507b - C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe -
5d9205ab6363d7c958af63208dd6218da9a1db3c3cb45a3df24d346f7acc7054 - C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe -
c82577476eb3c66d0e8e4e1c57c1cb88e453d988bd7cbc41abd5faa1449b30ca
Embedded URLs
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-cs-g1.crl05
- http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- cacerts.digicert.com
- crl4.digicert.com
- crl3.digicert.com
- www.digicert.com
Embedded IP addresses
- 51.132.193.105
- 20.247.185.124
- 4.230.171.124
- 104.18.33.89
- 74.178.240.51
- 85.210.196.11
- 20.184.175.5
- 74.178.240.61
- 40.84.97.4
- 52.148.114.188
- 52.110.12.51
- 52.110.12.33
- 72.154.7.111
File paths
- C:\My
- C:\Windows\SoftwareDistribution\Download\467d4844b1a06f896633937df86f641f\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.18715_none_6e38b8da126
- C:\Windows\SysWOW64\ntoskrnl.exe
- C:\Program
- c:\jenkins\workspace\8-2-build-windows-amd64-cygwin\jdk8u281\880\build\windows-amd64\jdk\objs\kinit_objs\kinit.pdb
- C:\Windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe
- f:\dd\Tools\devdiv\FinalPublicKey.snk
More Delf samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report