MALICIOUS — 1faf77591670aceef43e14dc007363212e53f07cc6a19053e4b4c5f162d9c5c6
MALICIOUS — 1faf77591670aceef43e14dc007363212e53f07cc6a19053e4b4c5f162d9c5c6 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Gavir family. 6 of 56 detection engines flagged it, exhibiting 6 ATT&CK techniques.
Identification
- SHA-256:
1faf77591670aceef43e14dc007363212e53f07cc6a19053e4b4c5f162d9c5c6 - SHA-1:
b75f9937d7a982204fe6c334bcdb6930ed168fb5 - MD5:
ea37d0b526cd33a7efb614a4963b03ed - imphash:
87bed5a7cba00c7e1f4015f1bdae2183 - ssdeep:
768:pG1ODKAaDMG8H92RwZNQSwcfymNBg+g61GoLjLITs69DiBZ:pgfgLdQAQfcfymNHY99DSZ - TLSH:
T10F31BFC06F36FA00CD52F76B5660CC4D35526C26B72E1D8AB012A23751365B7EB2928F - Submitted as: 1faf77591670aceef43e14dc007363212e53f07cc6a19053e4b4c5f162d9c5c6
- File type: pe · Size: 43079 bytes
- Verdict: malicious (100/100) · Family: Gavir
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): Borland Delphi
- ClamAV (daily): Win.Worm.Gavir-1
- Detect It Easy (packer/type): DIE:Borland Delphi
- Microsoft Defender: Virus:Win32/Viking.H
- Emsisoft (Emergency Kit): Win32.Worm.Viking.NDL
- Kaspersky (KVRT): Worm.Win32.Viking.j
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 13 weighted signals:
- ClamAV (daily) flagged Win.Worm.Gavir-1 (rule
Win.Worm.Gavir-1) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Virus:Win32/Viking.H (rule
Virus:Win32/Viking.H) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Worm.Viking.NDL (rule
Win32.Worm.Viking.NDL) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Worm.Win32.Viking.j (rule
Worm.Win32.Viking.j) - engine signal, weight 0.55, confidence 0.85 - 2 behavioral detection(s) across 2 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.43, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 2 external host(s) and 17 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:Borland Delphi (rule
DIE:Borland Delphi) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged Borland Delphi (rule
Borland Delphi) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Borland Delphi - static signal, weight 0.25, confidence 0.55
- Dropped 5 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
48047 behavior events · 2 ATT&CK techniques · 9 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
Dropped files
- bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 -
bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 - C:\Users\analyst\AppData\Local\Temp\$$a5E6.bat -
0f78b283d71cfa2bb8e2a97feb42c63aff7c4d81d92dec0a908c51df46b4a73b - C:\PerfLogs\_desktop.ini -
fb408e5fa0ab18d1eb2e68798f51b7e97cab3dd592fe12830d5e40b56c131991 - C:\Sysmon64.exe -
da7840c35d69eeea6f90cd34b2ef5f3905c2a71e678e3e64bee1d9ca184cfe5d - C:\Users\analyst\AppData\Local\Temp\tsk_4df2a138b8944dcc.exe.exe -
0d387e0f7d3cbca9cd3e02df603ebf13b383180b4a53365e4b27e626ae4c37cf - C:\Windows\vDll.dll -
1a3c72de9c30a8d33a7bb0a93acc682716d7d1f966ea71cc14783780edb8640e - C:\Windows\Logo1_.exe -
8bdd637937dc3c3c7fd31061dc047d55622028f81770c26bf045daeda67ed3c4 - 72462d146ae2a597a021f3f7484921506065db7cf8a84b51f667c4f554655beb -
72462d146ae2a597a021f3f7484921506065db7cf8a84b51f667c4f554655beb - 9b1bc0d9b55f579debc7b4f89674ce708a4689d856891445098563254c657537 -
9b1bc0d9b55f579debc7b4f89674ce708a4689d856891445098563254c657537
Embedded URLs
- http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://office.microsoft.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- crl.microsoft.com
- www.microsoft.com
- office.microsoft.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 20.42.73.28
- 4.230.171.124
- 57.155.104.224
- 20.165.94.54
- 135.233.95.144
- 52.253.84.76
- 20.42.73.30
- 40.79.167.9
- 104.18.33.89
- 74.179.77.204
- 48.211.4.16
- 52.110.12.5
- 52.110.12.52
- 104.46.162.230
- 52.168.117.175
- 72.154.7.112
- 52.148.114.188
- 52.110.12.46
- 52.110.12.37
File paths
- P:\Target\x86\ship\mso\x-none\smarttaginstall.pdb
More Gavir samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report