MALICIOUS — 3d81893ea51c83f1883c4b0e4d5dfc44de4c528675677c1909783c4486078f8d
MALICIOUS — 3d81893ea51c83f1883c4b0e4d5dfc44de4c528675677c1909783c4486078f8d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the Sivis family. 4 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3d81893ea51c83f1883c4b0e4d5dfc44de4c528675677c1909783c4486078f8d - SHA-1:
516ef80690b88c7636b73d9edfcca344301efe56 - MD5:
9de6e3d953580f2ae39280d42f8ad36a - imphash:
38aa7c2ff6ef0e48a9520d6702d08df4 - ssdeep:
768:+1uAkERoZd51OmikiQav1EFMFn1+aSuiVlpuCUtblll2:+0nERoZdnOmikiQmEFMFnM+iVlwl2 - TLSH:
T1AD340AA83310653FC9D148BB086CED3D84D366EA1961809257C4E7B088B8D77B63F796 - Submitted as: 3d81893ea51c83f1883c4b0e4d5dfc44de4c528675677c1909783c4486078f8d
- File type: pe · Size: 53214 bytes
- Verdict: malicious (95/100) · Family: Sivis
Detections (4 of 55 engines)
- ClamAV (daily): Win.Trojan.Agent-6943819-1
- Microsoft Defender: Virus:Win32/Sivis.A
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Kaspersky (KVRT): Virus.Win32.Agent.es
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Agent-6943819-1 (rule
Win.Trojan.Agent-6943819-1) - engine signal, weight 0.90, confidence 0.95 - Contacted 31 external host(s) and 24 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- Embedded network infrastructure: http://creativecommons.org/publicdomain/zero/1.0/, http://www.gnu.org/licenses/ - static signal, weight 0.35, confidence 0.60
- Dropped 83 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
25608 behavior events · 0 ATT&CK techniques · 97 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- c.pki.goog
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Dropped files
- C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-memory-l1-1-0.dll -
f1160fbadb8c690d3b0253e6b5d9cff0106a6ddb0776b722c49a615dbd11af28 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-crt-utility-l1-1-0.dll -
7831f3b8a127b510cb4b852de0c0a8b8e98a1185d7886f96153ed2da800c9192 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-crt-environment-l1-1-0.dll -
ef9243b7f3f64065228c68e9e1b4526540a5bede9cca9df6e61c0d788be7e859 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jwebserver.exe -
86cfcf73ed593b2fd99728714b9d664111fd23292f532d751b534c7013c25b34 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-crt-filesystem-l1-1-0.dll -
abb062ea954128031eac3d37f6557c50a752702b6a8c64e26c0be47870d6cc03 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\mlib_image.dll -
81cc0fa6fa5ed68db029c6e46442e39df83634be5b1b1c5ce23b3d5aa9e839f6 - cf5cf06df130ae251cea32717f561f9dcc3aa1dc5bbdc16a908bf28a96c4d672 -
cf5cf06df130ae251cea32717f561f9dcc3aa1dc5bbdc16a908bf28a96c4d672 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-crt-conio-l1-1-0.dll -
994ace62d4a7c47ae965a8b559d372e070cbdea5e2b8d4f90778d75df44f0def - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\fontmanager.dll -
88ad02bb235e304a5f52cdc7d89811e08fdd73340711ea23fe1189b92a6ed315 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-fibers-l1-1-0.dll -
66c6b716f19a0cb79f96bb1b1deb7680b947eb6b30e07be8952852cf038c3c4e - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\klist.exe -
bf637669b2aabf115a34ef9b30b9d06c207716eaee6d59f2bd59b4fbf42735cd - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\msvcp140.dll -
99196502f687b374f544f483227e4279339756cdcdaabb87a6f762bc03ad245d - 80edeaea92dbab18d41dc48791c6ba0da35fe25091cb02e006c6bf3ac22237c6 -
80edeaea92dbab18d41dc48791c6ba0da35fe25091cb02e006c6bf3ac22237c6 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\awt.dll -
83c04e6846b08d0ca5d2ff1f7c47c282951f414717d94881b6bd3435e07b1b52 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\management_agent.dll -
8c74b5944a5bb6ebcca2bcc03742f50e36174483e606e313b38fec6a2232b3cb
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- http://www.gnu.org/licenses/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9?P1=1787947896&P2=404&P3=2&P4=jG0qPLQOPd%2bt5RinRVmitqLzchxQxYxqeQHNUVSS1xqyyBIv6qwjGpW%2bp9oocbff1YwxFxmhQ5lL%2femS4NaNTQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787947929&P2=404&P3=2&P4=h2bLye3mx1Frb9X77uBK%2fgLe4ESg4OWq8MhrELrRjLJf3N%2bYR4Sa4IX8GjAAI%2ftlOSZ7lnTk%2ftcwZheB23l8Fw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://c.pki.goog/r/gsr1.crl
- http://c.pki.goog/r/r4.crl
Embedded domains
- creativecommons.org
- geocities.com
- cwru.edu
- gnu.org
- www.gnu.org
Embedded IP addresses
- 4.150.223.113
- 52.123.252.197
- 57.155.101.212
- 52.253.84.76
- 4.230.171.124
- 74.178.240.61
- 20.42.73.24
- 74.178.76.54
- 52.123.128.14
- 20.112.250.133
- 52.123.129.14
- 40.74.98.196
- 52.123.252.194
- 172.178.240.162
- 52.123.252.230
- 74.178.232.29
- 203.26.79.13
- 52.123.252.195
- 52.148.114.188
- 52.110.12.52
- 52.110.12.18
- 172.178.240.161
- 52.168.117.171
- 40.84.85.40
- 72.145.35.104
File paths
- X:\windows\system32\sysreset.exe
- C:\Windows.old\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim]
- C:\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim]
- C:\Windows.old\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.1120_none_c3e
- C:\Windows.old\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.1_none_eedfed
- X:\SysResetTrace-Tel-Merge.etl,
- C:\$WINDOWS.~BT\Sources\Panther\SysResetTrace-Tel-Merge.etl)
More Sivis samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report