MALICIOUS — 5b6e45b78e3ec7042d523d8e2247f28f4e2a1c99d4c014cbc356a003e3bbe349
MALICIOUS — 5b6e45b78e3ec7042d523d8e2247f28f4e2a1c99d4c014cbc356a003e3bbe349 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Sivis family. 4 of 56 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5b6e45b78e3ec7042d523d8e2247f28f4e2a1c99d4c014cbc356a003e3bbe349 - SHA-1:
e0cc51dbbe23f2d3602357209dc07cd7490efb5e - MD5:
9cd77e3cc447df514a3c431b7ebabd41 - imphash:
38aa7c2ff6ef0e48a9520d6702d08df4 - ssdeep:
768:+1uAkERoZd51OmiuUiUxav1EFMFn1+aSD:+0nERoZdnOmiuUiUxmEFMFnMT - TLSH:
T131304C603360117FC7A689BB0AE4CE2D90B131E971AA45F192C6C534A8F4C77F43529B - Submitted as: 5b6e45b78e3ec7042d523d8e2247f28f4e2a1c99d4c014cbc356a003e3bbe349
- File type: pe · Size: 37023 bytes
- Verdict: malicious (99/100) · Family: Sivis
Detections (4 of 56 engines)
- ClamAV (daily): Win.Trojan.Agent-6943819-1
- Microsoft Defender: Virus:Win32/Sivis.A
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Kaspersky (KVRT): Virus.Win32.Agent.es
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Agent-6943819-1 (rule
Win.Trojan.Agent-6943819-1) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Virus:Win32/Sivis.A (rule
Virus:Win32/Sivis.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Sivis.A (rule
Win32.Sivis.A) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.Agent.es (rule
Virus.Win32.Agent.es) - engine signal, weight 0.55, confidence 0.85 - Contacted 1 external host(s) and 4 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- Embedded network infrastructure: http://creativecommons.org/publicdomain/zero/1.0/, http://www.gnu.org/licenses/ - static signal, weight 0.35, confidence 0.60
- Dropped 10 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
17471 behavior events · 0 ATT&CK techniques · 97 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- licensing.mp.microsoft.com
- assets.msn.com
- www.bing.com
- settings-win.data.microsoft.com
- watson.events.data.microsoft.com
- weus2watcab01.blob.core.windows.net
- oneocsp.microsoft.com
Dropped files
- C:\Program Files\7-Zip\Lang\ca.txt -
18d51c017ca18295a2b70dd6135b4fc7d2ed2ef032eab3be1f6a0193375adaa6 - C:\Program Files\7-Zip\Lang\hr.txt -
396fc3a8b321af4d17849457313d6bb5417e2782952b8c7212462af0967b5917 - b78744635d5c620a9644297a1b567bbb9e482e6f5ded16baf4a564831eed6d4f -
b78744635d5c620a9644297a1b567bbb9e482e6f5ded16baf4a564831eed6d4f - C:\Program Files\7-Zip\Lang\mng2.txt -
f1d95ce6146d906ff372b4869eefeb558f9e357d91996ff002f62dd11f551bcc - 5e4a608e42582e69a9cd3a5df875c1f53a4576931b913d69a812f7e961527212 -
5e4a608e42582e69a9cd3a5df875c1f53a4576931b913d69a812f7e961527212 - C:\Program Files\7-Zip\Lang\en.ttt -
d1205692de3f1d0943c28d81e7563b3a4922ab2ad386c6d81bace422ac4f366f - C:\Program Files\7-Zip\Lang\it.txt -
331d903c1eff4d4873b1b286b94dce0de2a2b3656d18b7675aa4afd4799e64e2 - C:\Program Files\7-Zip\Lang\ms.txt -
b7af4f78145b521c5c6706ed57114019d84936a02d74f035a62ad8dc1050c032 - C:\Program Files\7-Zip\Lang\ne.txt -
d2beeb41185e0185aa2ac375426fcde96dcfd02bee1dc4b85c1cda3e2c48ab58 - C:\Program Files\7-Zip\Lang\bn.txt -
f23f46763c6d893fde625645d15ba722a533d58ed0e983abcd16a74e95bc26dd - C:\Program Files\7-Zip\Lang\de.txt -
b227c467a34127ccd53e0b119e656b77a9bf1b2ce578853dfc7e2bc998a3f324 - C:\Program Files\7-Zip\Lang\af.txt -
06f24eafdf4dd2246b2fce0c667afa8412948723da06ff1603094aaa327f41b8 - C:\Program Files\7-Zip\Lang\ko.txt -
d6ccec8b4257765d99a4d51b5237a80a9f9620aad69f9969b2157204064818d0 - C:\Program Files\7-Zip\Lang\eo.txt -
320c97919c9e9eac7a64dbcf6e7a17fc4ccc9822ea74c351714f9ab84f6ec111 - C:\Program Files\7-Zip\Lang\da.txt -
b5f3599cc170a8f8601ae92ccfe569e3337967244205de828102e16cc23c9185
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- http://www.gnu.org/licenses/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- creativecommons.org
- cwru.edu
- gnu.org
- www.gnu.org
Embedded IP addresses
- 4.150.223.100
- 52.253.84.76
- 4.230.171.124
- 85.210.193.152
- 162.159.142.9
- 172.178.240.161
- 172.178.240.162
- 20.209.154.161
- 52.110.12.2
- 52.110.12.42
File paths
- C:\Users\a.monaldo\AppData\Local\Microsoft\Windows\WebCache\
More Sivis samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report