SUSPICIOUS — {3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000017.db
SUSPICIOUS — {3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000017.db is a unknown sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (43/100), attributed to the Container family. 2 of 53 detection engines flagged it.
Identification
- SHA-256:
2971162034c1b9e087ee20c14e8395ee10badb33361e194ca8e3bbafb59cbc43 - SHA-1:
41cfecd0fa28f872a2d1b649eefb35e1496029f7 - MD5:
776e05ad1386953f9a56dc3906379ff8 - ssdeep:
768:5k2GQLZZpvEzDsfmQylEmLmBxKLMTLf3u34J3Km9WTn:5kV+xlTLf3u3q3xyn - TLSH:
T1AC360FCD4A9A4336CB3B49395C68B8AD01C2B09115AD660C6F0FA17E34E38EBDCB1575 - Submitted as: {3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000017.db
- File type: unknown · Size: 68320 bytes
- Verdict: suspicious (43/100) · Family: Container
Detections (2 of 53 engines)
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
Why this verdict
The suspicious score of 43/100 is the fusion of 2 weighted signals:
- YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.35, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70
File paths
- C:\WINDOWS\system32\control.exe
- C:\WINDOWS\system32
- C:\Users\analyst\AppData\Local\Microsoft\OneDrive\OneDrive.App.exe
- C:\Users\analyst\AppData\Local\Microsoft\OneDrive
- C:\Users\analyst\AppData\Local\Microsoft\OneDrive\OneDrive.exe
- C:\WINDOWS\system32\LiveCaptions.exe
- C:\WINDOWS\system32\magnify.exe
- C:\WINDOWS\system32\narrator.exe
- C:\WINDOWS\system32\osk.exe
- C:\WINDOWS\system32\voiceaccess.exe
- C:\WINDOWS\system32\cmd.exe
- C:\WINDOWS\syswow64\WindowsPowerShell\v1.0\powershell.exe
- C:\WINDOWS\syswow64\WindowsPowerShell\v1.0
- C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe
- C:\WINDOWS\system32\WindowsPowerShell\v1.0
- C:\Program
- C:\WINDOWS\system32\mstsc.exe,-4000
- C:\WINDOWS\system32\mstsc.exe
- C:\WINDOWS\system32\psr.exe,-1701
- C:\WINDOWS\system32\psr.exe
- C:\WINDOWS\syswow64\wmploc.dll,-102
- C:\WINDOWS\system32\charmap.exe
- C:\WINDOWS\system32\comres.dll,-3410
- C:\WINDOWS\system32\comexp.msc
- C:\WINDOWS\system32\mycomput.dll,-300
More Container samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report