MALICIOUS — 20e3815ae02027bf4c5ac2385b34d689d87b25616f807a77798cf2ffc90f3332
MALICIOUS — 20e3815ae02027bf4c5ac2385b34d689d87b25616f807a77798cf2ffc90f3332 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Sivis family. 7 of 56 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
20e3815ae02027bf4c5ac2385b34d689d87b25616f807a77798cf2ffc90f3332 - SHA-1:
96488c7be74f9a4f5d08e8ca79fe7390835ab195 - MD5:
92633c28e3f8e698311fa33e1c4b6b77 - imphash:
b10d16eedb1085ef7262dfc4ab03be6f - ssdeep:
1536:KEq3GcOK+LOBk8admB2BmqEkSOPX/cNPHs7cFBBM/MXUde5lwlM0VAeF8ChZeGz3:KEqpaabNHH02eua2Jxmt - TLSH:
T1283DD7E42728F83DDDA5AECB0124746DEF47786D2F81718F998092DA90ACC13A437794 - Submitted as: 20e3815ae02027bf4c5ac2385b34d689d87b25616f807a77798cf2ffc90f3332
- File type: pe · Size: 125064 bytes
- Verdict: malicious (100/100) · Family: Sivis
Detections (7 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Ausiv-9881309-1
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:UPX
- Microsoft Defender: Virus:Win32/Sivis.A
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Kaspersky (KVRT): Virus.Win32.Agent.es
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 13 weighted signals:
- ClamAV (daily) flagged Win.Malware.Ausiv-9881309-1 (rule
Win.Malware.Ausiv-9881309-1) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Virus:Win32/Sivis.A (rule
Virus:Win32/Sivis.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Sivis.A (rule
Win32.Sivis.A) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.Agent.es (rule
Virus.Win32.Agent.es) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Contacted 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:UPX (rule
DIE:UPX) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://d.symcb.com/rpa0, http://s.symcb.com/universal-root.crl0, https://d.symcb.com/rpa0@ - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: UPX, high-entropy-sections:UPX1 - static signal, weight 0.25, confidence 0.55
- Dropped 10 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
15629 behavior events · 0 ATT&CK techniques · 98 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- odc.officeapps.live.com
- www.msn.com
- assets.msn.com
- www.bing.com
- v10.events.data.microsoft.com
- watson.events.data.microsoft.com
- edge.microsoft.com
- http://www.msftconnecttest.com/connecttest.txt
Dropped files
- C:\p.ps1 -
21fa654213cda7593777a025b0d1222617d1b7091e4a6e7b4c644cfed69aa052 - C:\Program Files\7-Zip\Lang\it.txt -
39c68f14f668195b4ec3e374f12209095aee27c09bd62e267fc56acb9dc04eef - C:\Program Files\7-Zip\Lang\hu.txt -
2e90fc33a243040533ce6d3960fe6480fe8e5b19fecc5693cd3bee50c1d0aaa6 - C:\Program Files\7-Zip\Lang\mk.txt -
b81e7665dc0a2722920931e3c3df994a8d5ce42dc44447c44777645e002bd275 - C:\Program Files\7-Zip\Lang\pt-br.txt -
7b5640a7e7e37c8a6f3af36ea628156f97d4de8468d8cfdd94eac6a037a10e6e - C:\Program Files\7-Zip\Lang\io.txt -
9ac1f0e82c7f0ded2825a516d805d69422e10b97d01d6596c34d9aafc7b3857f - C:\Program Files\7-Zip\7-zip32.dll -
03d4975fac498f4d192ffbb77edc120b395f3512329361a58e2d12b13b2c764f - C:\Program Files\7-Zip\Lang\co.txt -
3d9eb62bc1da7fa123d1765a1aef4ea9009f9980ade091cbf446c794aeb76180 - C:\Program Files\7-Zip\Lang\cs.txt -
ef49ef29b78075dc0d0c2fe6f5a83305aa34e1aebd901caaff00451140b760f2 - C:\Program Files\7-Zip\Lang\an.txt -
d4038932283141f8d9145ddd372c28d327fcb409a1e20897d7411e22bdc5f1c4 - C:\Program Files\7-Zip\Lang\ku-ckb.txt -
37f7b47dc590216791f27416e45a2b3c4e993ad4121fb0fa22b94d31d80a366d - C:\$WinREAgent\RollbackInfo.ini -
5a89de38e7c586c95c5a1292f0379bcbc8c67a790861f422df62f8ca74283158 - C:\Program Files\7-Zip\Lang\et.txt -
f8f54fc6cfe42623bee44d4217f34401f692631f77f9828e1bc6eb806a5a0c4c - C:\Program Files\7-Zip\Lang\bg.txt -
469c246f9c1ad88ab3d79c236d52d8efc6e8ad93a24ea2d464867f89a9f6ace7 - C:\office-config.ps1 -
b1065622c47477cdedeea416fa5c6484819d407beda8283c975ffd9704b6d052
Embedded URLs
- http://www.adobe.com/go/reader_system_reqs_ua.UnmoveFiles
- http://www.adobe.com/go/reader_system_reqs_ua
- https://www.digicert.com/CPS0
- http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
- http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
- http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
- http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
- http://www.digicert.com/ssl-cps-repository.htm0
- https://d.symcb.com/rpa0
- http://s.symcb.com/universal-root.crl0
- https://d.symcb.com/rpa0@
- http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
- http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- www.adobe.com
- helpx.adobe.com
- www.microsoft.com
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- cacerts.digicert.com
- d.symcb.com
- s.symcb.com
- ts-crl.ws.symantec.com
- ts-aia.ws.symantec.com
Embedded IP addresses
- 52.168.112.67
- 52.230.59.222
- 52.123.252.216
- 4.230.171.124
- 135.234.160.245
- 20.42.73.24
- 40.79.141.154
- 52.110.12.1
- 52.110.12.3
File paths
- C:\Windows.old\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim]
- C:\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim][gle=0x00000020]
- C:\Windows.old\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.1120_none_c3e
- C:\Windows.old\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.1_none_eedfed
- X:\SysResetTrace-Tel-Merge.etl,
- C:\$WINDOWS.~BT\Sources\Panther\SysResetTrace-Tel-Merge.etl)
- X:\windows\system32\sysreset.exe
- C:\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim]
More Sivis samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report