MALICIOUS — 40fd6ccb1d3ec74773909b287b09e6eeb3baf1d28428f66fab3d4ea26a346573
MALICIOUS — 40fd6ccb1d3ec74773909b287b09e6eeb3baf1d28428f66fab3d4ea26a346573 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Delf family. 6 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
40fd6ccb1d3ec74773909b287b09e6eeb3baf1d28428f66fab3d4ea26a346573 - SHA-1:
c3c857b88eac2d7ceca03eec72ee614a7a0497f9 - MD5:
fb070d4296948866924fab133ba6a7b4 - imphash:
500ff1538958cc73738bf0c262a1773f - ssdeep:
196608:FA3n9TAn9Tin9Tin9TFn9TBfUefU1n9Tin9Tin9TBfU1n9TBfUefU1n9T:4CccrzFmcczmzFm - TLSH:
T15569D0C0622261F1DE92CEA40DD07E0F11A1B34625FC7D8D4682597E37E92EBA04F69D - Submitted as: 40fd6ccb1d3ec74773909b287b09e6eeb3baf1d28428f66fab3d4ea26a346573
- File type: pe · Size: 8972328 bytes
- Verdict: malicious (97/100) · Family: Delf
Detections (6 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.dafixer,.dafixer,.dafixer,.dafixer,.dafixer
- ClamAV (daily): Win.Virus.Delf-9955432-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:Turbo Linker
- Microsoft Defender: Trojan:Win32/Vindor!pz
- Emsisoft (Emergency Kit): Trojan.Generic.33849684
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Virus.Delf-9955432-0 (rule
Win.Virus.Delf-9955432-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 33 external host(s) at runtime (23 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: high-entropy-sections:.dafixer,.dafixer,.dafixer,.dafixer,.dafixer, Turbo Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
845 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- searchapp.bundleassets.example
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
Embedded URLs
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-cs-g1.crl05
- http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
- http://www.digicert.com/ssl-cps-repository.htm0
- http://crl.thawte.com/ThawteTimestampingCA.crl0
- http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
- http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
- http://appsyndication.org/2006/appsyn
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787770097&P2=404&P3=2&P4=JEIUlOV%2fqYZSToigUcwZGcBsl3V%2f8zrZ2GaibMqNsiDvYHJJUZR087MNgriihaEUGSPS9PxCAFn4hAOcjyG%2bXQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787770177&P2=404&P3=2&P4=feqZ9r2OB3Ipktctu%2fLNVcU%2bo%2btMjwMq9p4NvQhuXaAZKHgoghRiZZnR31Gnl%2fKkDQ5Em%2bi%2fju9sN%2be3Aufhww%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- mb.fi
- www.microsoft.com
- crl.microsoft.com
- schemas.microsoft.com
- cacerts.digicert.com
- crl4.digicert.com
- crl3.digicert.com
- www.digicert.com
- crl.thawte.com
- ts-aia.ws.symantec.com
- ts-crl.ws.symantec.com
- appsyndication.org
- oneclient.sfx.ms
Embedded IP addresses
- 72.154.7.114
- 74.178.76.44
- 52.110.12.22
- 20.42.65.94
- 52.110.12.45
- 52.123.252.235
- 20.247.184.197
- 172.215.188.225
- 4.230.171.124
- 52.123.252.244
- 40.84.97.4
- 74.178.240.61
- 4.150.223.104
- 74.178.76.54
- 203.26.79.13
- 52.123.252.203
- 135.234.160.244
- 4.207.44.70
- 20.184.175.0
- 52.148.114.188
- 20.231.239.246
- 52.123.128.14
- 52.123.129.14
- 57.154.63.210
- 20.184.175.15
File paths
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System\37a1d51f35918dd36a0d4e34cc91732e\System.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wad78daf4#\8f73bd36654fa77803c3167f39ead17e\Microsoft.Windows.Diagnosis.SDHost.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wed3937f9#\3dae65a1b718d3a083094b67e1413e9a\Microsoft.Windows.Diagnosis.SDCommon.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\89bc329e8c65a9e13067c9776d925d78\System.Core.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\f02732d562721457afde5c189a906d17\System.Management.Automation.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.W0bb5dac4#\4c396dcf426dbba8eddd04adc0b562fe\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.W69ef49d2#\9dcd27fe1c298162f13c6bdb7c0cfe88\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wd518ee0d#\e9bd08c5c1a8c5fdef45c7025b262edc\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.W708fc392#\3c226a9afdce13116b1fdfa9e92b4152\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.W79a81d80#\2efe3e39ab8a210a684558961ff266d2\Microsoft.Windows.Diagnosis.Commands.WriteDiagTelemetry.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.P1706cafe#\16ab851088227b0798b233d026a1019e\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Confe64a9051#\29c26981c4b4347ca371002934f6f2ac\System.Configuration.Install.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Pb378ec07#\dac77e2bdc0040a1a2a446cbf77b6bae\Microsoft.PowerShell.ConsoleHost.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.P521220ea#\29b929ef5de7ccdae8f74f1083a729c8\Microsoft.PowerShell.Commands.Utility.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Pae3498d9#\a78370d535d159d2691edea0727e654d\Microsoft.PowerShell.Commands.Management.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.P6f792626#\4b6994043bbc39d9e47433716afb9e98\Microsoft.PowerShell.Security.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.We0722664#\a2e162c411e7960d3320a700179232fc\Microsoft.WSMan.Management.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data\dcffb1d4b51a427f7c054b15597ef269\System.Data.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\1fb6db2ce6d2887fe6f8f620cb092343\System.Xml.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Management\dee95ca75ccebe1cc18b31dca334cd53\System.Management.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Dired13b18a9#\4ac88f62ef161467f8e9dd4985837e51\System.DirectoryServices.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\b5152c3c02957bbe4459505a39afde20\System.Configuration.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Transactions\0935f5dce0a38689b9507cb1938fe436\System.Transactions.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Numerics\568282207f7c6c41d18e9e38637dbe77\System.Numerics.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System\08f69c55e9284eaab92075159503c897\System.ni.dll
More Delf samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report