MALICIOUS — 3a3f9620d8c14ec52e392a1f200cfafb200fbc7c44fbea83e7a8d5921f01d4b5
MALICIOUS — 3a3f9620d8c14ec52e392a1f200cfafb200fbc7c44fbea83e7a8d5921f01d4b5 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Revell family. 10 of 56 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
3a3f9620d8c14ec52e392a1f200cfafb200fbc7c44fbea83e7a8d5921f01d4b5 - SHA-1:
c6592144412c7d7882448c201649d2af8abff598 - MD5:
e5c9c1b3704659ab08b04d9ca2fc9fa4 - imphash:
5b01e567be64bb329759f46243f37e13 - ssdeep:
24576:Kj9Lw63ct04QFzY1ji40L2pe5hVyCqnstLyUktHIiLy4R:Kj9LxcO4Q5Y1ji+pG7qnstLet3LyA - TLSH:
T19955B4DD2104AB11FEA18DE09E1F799D41A1B4B413FF263C4A52413A92D2CBFF876069 - Submitted as: 3a3f9620d8c14ec52e392a1f200cfafb200fbc7c44fbea83e7a8d5921f01d4b5
- File type: pe · Size: 1286355 bytes
- Verdict: malicious (100/100) · Family: Revell
Detections (10 of 56 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Revell-1
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Worm:Win32/Bloored.E
- Emsisoft (Emergency Kit): Gen:Trojan.AV-Killer.orZ@aGGD4zm
- Kaspersky (KVRT): Email-Worm.Win32.Bloored.e
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 100/100 is the fusion of 19 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Revell-1 (rule
Win.Trojan.Revell-1) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - 2 behavioral detection(s) across 2 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.63, confidence 0.90 - Microsoft Defender flagged Worm:Win32/Bloored.E (rule
Worm:Win32/Bloored.E) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Trojan.AV-Killer.orZ@aGGD4zm (rule
Gen:Trojan.AV-Killer.orZ@aGGD4zm) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Email-Worm.Win32.Bloored.e (rule
Email-Worm.Win32.Bloored.e) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.55, confidence 0.70 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.50, confidence 0.70 - Contacted 17 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser built-in flagged Windows_Injection_Api_Combo (rule
Windows_Injection_Api_Combo) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.gnu.org/software/coreutils/, http://translationproject.org/team/, http://gnu.org/licenses/gpl.html - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: UPX - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Dropped 66 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
27886 behavior events · 1 ATT&CK techniques · 68 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
Dropped files
- C:\Program Files\7-Zip\7z.exe -
9f3e128929663a633b19ffde225bf8494cb48522ff2ae84581525b34bdc42ec9 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\javaw.exe -
5d80916c98b6d9aaf795e3ea33e1ab8eddd38e4f1aeb228f8860a63df6da7790 - C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe -
fbeb8897d2ef81c32209cae21ef7a68a53cb2afc850234c70503039343b60978 - C:\Program Files\LibreOffice\program\odbcconfig.exe -
a067cb6a70d6681203accc79a94116e2231c4a27d87ceeb4ed2cefc32ec958f8 - C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe -
e988c80bfee46ae47ce07e5965dc825193e118d72c885868f4da5e13118e6884 - C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe -
b3234e719236639781b7b7c32ce2b44aec7563871dfcbee10a297a430370ca6d - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe -
35a47e84ed2c1e8d1ea006c669eaa209539dfb8fd727c37aaa736f06aaac7d35 - C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe -
33ee1f462f336fcfae4a913fa2e5364093921c71b9e2c96b3c20505295c15e0d - C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe -
16a8dfd514a9c40f24706629cc26f5e8058dfa0f6505858d8044801a91dab676 - C:\Program Files\Google\Chrome\Application\151.0.7922.174\elevated_tracing_service.exe -
0cce4a4ff87ad6c19011927b11ceadd758134e2e5d422ccfa109ac61c7a9c64e - C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe -
91583c2132f2615349cad23733c011051abf85f70b74c5bab548bc64fe7ebaf3 - C:\Program Files\LibreOffice\program\python-core-3.12.13\lib\pip\_vendor\distlib\t64.exe -
c7c0798c76486cd6ffee074fcdd2b1bdf7901aa524d93377eefc92617ced6086 - C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe -
583b3b8b766b952901c9db4327632c0eccdcfcb5cbbd68bd38230470782eb6de - C:\Program Files\LibreOffice\program\mar.exe -
271814a3ceeb594e76b31618389438a174d2137904ea9d8611fc2e202a197960 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\ktab.exe -
bbbbc8d4c42a5c0af228039aaab61e3cf46ba72300b142bae4e79eff368d9bf8
Embedded URLs
- http://schemas.microsoft.com/2003/10/Serialization/Arrays
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi
- http://schemas.datacontract.org/2004/07/Microsoft.Office.LicensingService
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetEntitlementsForOlsIdentityResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetEntitlementsForOlsIdentityRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/CheckMachineStatusResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/CheckMachineStatusRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetKeyResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetKeyRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetEntitlementForMachineKeyResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetEntitlementForMachineKeyRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetLicenseInfoForMachineKeyResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetLicenseInfoForMachineKeyRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetLicenseResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetLicenseRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetSessionTokenResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetSessionTokenRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetOlsLicenseResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetOlsLicenseRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetWpkBindingResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetWpkBindingRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetTokenResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/GetTokenRequest
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/IOlsClient/ReportActivationResponse
- http://schemas.microsoft.com/office/licensingservice/API/2012/01/ClientApi/ReportActivationRequest
Embedded domains
- www.norton.com
- norton.com
- yahoo.com
- www.yahoo.com
- microsoft.com
- www.microsoft.com
- windowsupdate.com
- www.windowsupdate.com
- www.mcafee.com
- mcafee.com
- www.nai.com
- nai.com
- www.ca.com
- ca.com
- liveupdate.symantec.com
- www.sophos.com
- www.google.com
- rohitab.com
- www.rohitab.com
- securityresponse.symantec.com
- www.google.ca
- www.crackedmindstechnologies.com
- sf.net
- schemas.microsoft.com
- schemas.datacontract.org
Embedded IP addresses
- 192.168.0.30
- 192.168.8.1
- 20.42.65.94
- 52.123.252.242
- 4.230.171.124
- 20.42.179.192
- 57.155.101.212
- 20.247.184.142
- 74.179.77.204
- 135.233.95.135
- 4.150.223.111
- 135.233.95.144
- 52.182.141.63
- 104.18.33.89
- 92.223.78.30
- 52.148.114.188
- 40.84.97.4
- 172.178.240.162
- 72.153.5.97
- 52.110.12.56
- 52.110.12.15
Registry keys
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\MIME\audio/x-aiff]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\MIME\audio/aiff]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.aiff]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.aifc]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.aif]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\MIME\video/quicktime]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.qt]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.mov]
File paths
- d:\dbs\el\oc\target\x86\ship\postc2r\x-none\olicenseheartbeat.pdb
- X:\:`:d:h:l:p:t:x:
- P:\:`:l:p:
- H:\:d:h:p:
- T:\:d:l:t:
More Revell samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report