MALICIOUS — Instructions.iso
MALICIOUS — Instructions.iso is a unknown sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Container family. 3 of 47 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
21a0b617431850a9ea2698515c277cbd95de4e59c493d0d8f194f3808eb16354 - SHA-1:
2a0478a22d27f7af98786e873b6c85c4ae2e3b2e - MD5:
67a6774fbc01eb838db364d4aa946a98 - ssdeep:
3072:CUEmC94lAhNLdHZS/Y1s7kNf4RqWs4e32pIYNxHaaBzpodfOYFdUq20vP0X6/q:Es/YPNfEqWKG2kHaaB2kwUq20v - TLSH:
T1C9555BE1119321A2DEF1BE04643D8F8DB49330A556318F8D8103A71F969A2B3BDF58B5 - Submitted as: Instructions.iso
- File type: unknown · Size: 1245184 bytes
- Verdict: malicious (99/100) · Family: Container
Detections (3 of 47 engines)
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Cyble Vision: Cyble Vision: Malware
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- Cyble Vision flagged Cyble Vision: Malware (rule
Cyble Vision: Malware) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s): Download-and-execute dropper (wget/curl + chmod) [high] (rule
tl-linux-download-exec) - dynamic signal, weight 0.60, confidence 0.90 - 1 behavioral detection(s): Download-and-execute dropper (wget/curl + chmod) [high] (rule
tl-linux-download-exec) - dynamic signal, weight 0.60, confidence 0.90 - Embedded executable payload carved at offset 952320 - static signal, weight 0.40, confidence 0.70
- YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Contacted 10 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Contacted 10 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
926 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- entropy.ubuntu.com
- desktop-hsgcbep
- 250.255.255.239.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- desktop-hsgcbep._dosvc._tcp.local
- _dosvc._tcp.local
- ntp.ubuntu.com
- 185.125.189.53:443
- 20.165.94.46
- ff02::1:3
- 224.0.0.252
- 10.240.0.1
- 224.0.0.251
- ff02::fb
- 10.240.0.255
- ff02::16
- 239.255.255.250
Dropped files
- tmp_tmp.AO2Q8MVPTl -
07fa8c00991e01ba7d4cfc0604e69d38d5676f7f23ae58b8d9d87fe047f2fc5c
Embedded IP addresses
- 20.165.94.46
- 40.126.14.164
- 4.247.188.233
- 85.210.193.152
More Container samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report