MALICIOUS — 3afbb6f7a05e56ba886889d5290bf89cb6c902a86f69e882b15098a63b2dd4ac
MALICIOUS — 3afbb6f7a05e56ba886889d5290bf89cb6c902a86f69e882b15098a63b2dd4ac is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Delf family. 6 of 56 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
3afbb6f7a05e56ba886889d5290bf89cb6c902a86f69e882b15098a63b2dd4ac - SHA-1:
d8bd5b8630a23d2077742ac61baa08f36e30d721 - MD5:
e82b5f0a52ef543889e0351273b79e19 - imphash:
31d1c48ee7d8e07a5706e963146db875 - ssdeep:
1536:p4q8Q1xZtffrb8sjPFNhTYsFFrzckH2fmitE4at/KfvgUf/:qKtfDwsjPThTYszDH2fSl/yvz - TLSH:
T133389F295B2B3B87EB77D7620451BB0D0462F9B9607A04895323C17F67F5C236A7411C - Submitted as: 3afbb6f7a05e56ba886889d5290bf89cb6c902a86f69e882b15098a63b2dd4ac
- File type: pe · Size: 79528 bytes
- Verdict: malicious (100/100) · Family: Delf
Detections (6 of 56 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- ClamAV (daily): Win.Trojan.Delf-1564
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Virus:Win32/Viking.MS
- Emsisoft (Emergency Kit): Trojan.Agent.FPMF
- Kaspersky (KVRT): Virus.Win32.Lamer.xe
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 100/100 is the fusion of 13 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Delf-1564 (rule
Win.Trojan.Delf-1564) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - Dropped a malicious payload (GameThief): virDll.dll - dynamic signal, weight 0.62, confidence 0.90
- Microsoft Defender flagged Virus:Win32/Viking.MS (rule
Virus:Win32/Viking.MS) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Agent.FPMF (rule
Trojan.Agent.FPMF) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.Lamer.xe (rule
Virus.Win32.Lamer.xe) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Contacted 1 external host(s) and 18 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- YARA: MalwareAnalyser built-in flagged Windows_Injection_Api_Combo (rule
Windows_Injection_Api_Combo) - engine signal, weight 0.35, confidence 0.70 - 1 behavioral detection(s) across 1 rule(s): Discovery: enumerates installed security software [low] (rule
tl-security-software-discovery) - dynamic signal, weight 0.20, confidence 0.90 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
57977 behavior events · 1 ATT&CK techniques · 101 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
Dropped files
- C:\Program Files\LibreOffice\program\gengal.exe -
a67728d4f3c02cc4b198c5aafd9822370e178e724679b153572fbd6ce2f29a0c - C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe -
50ced46c6294dada82911b24973b71f9e924e3c87bd55ea6ddb157c9a80bb35c - C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe -
30a2aaab78d408f69a8888e5d3217ac3cfc5b696c58afc4a917c5e05c0ca511e - C:\Program Files\Google\Chrome\Application\151.0.7922.174\elevated_tracing_service.exe -
28f4733f92610c5fb9eef725bb15f0a8ee35c247088075593949008cb1913d37 - C:\Program Files\LibreOffice\program\opencltest.exe -
6f4e1762da94639ddc42219c02294b092d27418a3a46dc576712f4179536fd74 - C:\Program Files\LibreOffice\program\mar.exe -
a0ce739f64c65001ea6ef2c59be2e92a86b9149904c030adb94ec5938de7b897 - C:\Program Files\LibreOffice\program\python-core-3.12.13\lib\setuptools\gui-64.exe -
a3429a6abe83864613741893f370a0440c0573e6e3ee034a4f46ef7890755bf8 - bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 -
bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 - C:\Program Files\Adobe\Acrobat DC\Acrobat\OSSLLibs\AdobeFips.exe -
3abf348a9f16d850eae5d9a68be955b96a58df0c20857c84ec6cca436ebfdb9c - C:\Program Files\LibreOffice\program\swriter.exe -
fb83bc60a23e16c41e5e00334a9155041d427cd40969fc515feaf6ead1fef420 - C:\Program Files\LibreOffice\program\python-core-3.12.13\lib\pip\_vendor\distlib\t64.exe -
437a5ccd9a6ae6a01586498dbf6e1de2c094b23abea45088f7739bf105055398 - C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe -
cb729c721da4b481ca38ea07f6e2b5df7e5ae0f5e2a79a144a5e829026141428 - C:\Program Files\Google\Chrome\Application\151.0.7922.174\elevation_service.exe -
b528ad62b37276d0516db535da6f1f09c38cf4b2d145dc24b34b6314dcab0695 - C:\Windows\Logo1_.exe -
19e3b2ef34169cc00cf0f5389a785ead638fb84d048e82de176096253229c466 - C:\Program Files\LibreOffice\program\python-core-3.12.13\lib\pip\_vendor\distlib\w64.exe -
4a76907f1f11c8d35cc16357f34ebf3ccb97cd824a669701faf045d9fcf4c6b3
Embedded URLs
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-cs-g1.crl05
- http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- cacerts.digicert.com
- crl4.digicert.com
- crl3.digicert.com
- www.digicert.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 192.168.0.30
- 192.168.8.1
- 51.104.15.252
- 4.230.171.124
- 20.247.184.197
- 85.210.193.152
- 48.211.4.16
- 135.233.95.144
- 135.232.92.97
- 74.179.77.204
- 20.42.73.27
- 172.64.154.167
- 20.247.185.124
- 52.110.12.31
- 52.110.12.50
- 104.208.16.94
- 4.150.223.97
- 172.215.188.225
- 52.110.12.52
- 72.145.35.111
- 52.110.12.48
- 52.148.114.188
File paths
- c:\jenkins\workspace\8-2-build-windows-i586-cygwin\jdk8u281\880\build\windows-i586\jdk\objs\policytool_objs\policytool.pdb
More Delf samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report