MALICIOUS — 5c25f03ca0a606bb7a16fc30fc1f260162697cf78b009df4a637ebe0d2f8c5eb
MALICIOUS — 5c25f03ca0a606bb7a16fc30fc1f260162697cf78b009df4a637ebe0d2f8c5eb is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Sivis family. 7 of 56 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5c25f03ca0a606bb7a16fc30fc1f260162697cf78b009df4a637ebe0d2f8c5eb - SHA-1:
6b9118b65475dcf4b77b69c66f90eed61a787435 - MD5:
ff4d097f4ed9112b14d63ff36f1757fb - imphash:
b10d16eedb1085ef7262dfc4ab03be6f - ssdeep:
3072:KEq5BM+BjhOlXwNhokSTCV2M6kD31Q0ameVR6b9/zrapvIXnEYosoxg0BO:KEp+DNhHyVM6Y3+V0b972pvQos - TLSH:
T1BC4417DD016D6712D237C8382668CAED8485B4D0B57A3F9D1E058B370066933FDBA1AE - Submitted as: 5c25f03ca0a606bb7a16fc30fc1f260162697cf78b009df4a637ebe0d2f8c5eb
- File type: pe · Size: 246098 bytes
- Verdict: malicious (100/100) · Family: Sivis
Detections (7 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Genpack-9877674-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:UPX
- Microsoft Defender: Virus:Win32/Sivis.A
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Kaspersky (KVRT): Virus.Win32.Agent.es
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 14 weighted signals:
- ClamAV (daily) flagged Win.Malware.Genpack-9877674-0 (rule
Win.Malware.Genpack-9877674-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Virus:Win32/Sivis.A (rule
Virus:Win32/Sivis.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Sivis.A (rule
Win32.Sivis.A) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.Agent.es (rule
Virus.Win32.Agent.es) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Contacted 2 external host(s) and 16 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:UPX (rule
DIE:UPX) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.gnu.org/software/coreutils/, http://translationproject.org/team/, http://gnu.org/licenses/gpl.html - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: UPX, high-entropy-sections:UPX1 - static signal, weight 0.25, confidence 0.55
- Dropped 10 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 4 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
16085 behavior events · 0 ATT&CK techniques · 98 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
Dropped files
- C:\Program Files\7-Zip\7zG.exe -
ef20ba9e6447b159befec01849c54bd02241a038f93bf72f12a931d7d1437812 - C:\Program Files\7-Zip\Lang\be.txt -
f15a70d2be0395d5075a4cce8b4b2f660cd2668c3a17d5f7c74f6d27f9ccbe34 - C:\Program Files\7-Zip\Lang\fur.txt -
c2a3e2a9e537f32d30ee420a6b82853a4327e13fe47f5543239642785b5b94a3 - C:\Program Files\7-Zip\Lang\fa.txt -
3092a79d0278d8f04a1dd78d2eceb0d66437f032815629e6287c0f73ae5ae48d - C:\Program Files\7-Zip\Lang\et.txt -
3949052122c1452ab771a126a9bab9c5a91c386b5a723a8d1b0eba257f9f648a - C:\Program Files\7-Zip\Lang\an.txt -
0b56e7a9cf1d6754821982d743f0cde038da1d072472bddf5fa47da55c259e92 - C:\Program Files\7-Zip\Lang\lv.txt -
ada67f5968950a88ff61ee49e7c6cd9e4dd4e5b2b776c95781ae3ef58df846a7 - C:\$Recycle.Bin\S-1-5-21-976637724-599762485-334819845-1001\desktop.ini -
0997497ca4f424d062a7caebc67fbbcd14ad506561dcc854bccd1dc86f8df85c - C:\Program Files\7-Zip\Lang\bg.txt -
a747665408b44b726763e4eb9964fa68968bb4536a4c04f13e7f9ead3e08c0ff - C:\Program Files\7-Zip\Lang\fr.txt -
a631518a32aec2471a4d6aa0afc4a2670a3aa6559ec6961ff5ceb73a1e4a5190 - C:\Program Files\7-Zip\7z.dll -
1453bcc2905a8299c2e022789be68570d759b063c2de7e6fd1560abac4654a33 - C:\$WinREAgent\RollbackInfo.ini -
6a32ce10215fc43ecfaecdaf2f31b1ace9592fab82353ff319ab64cbe0a54369 - C:\Program Files\7-Zip\Lang\he.txt -
07f5f1edb775322e0b1b20904e46a9a70c977d6ad9b285c278c0888815b6f91b - d4de5cd3ffe1052443a836a964c9ef6fb2aafe33063ec8e5196bda2c46e130e4 -
d4de5cd3ffe1052443a836a964c9ef6fb2aafe33063ec8e5196bda2c46e130e4 - C:\$WinREAgent\Backup\ReAgent.xml -
6a8fce95356c1e2665d8a51e1144c8db37d3fd63473c43470e4b846d46c31179
Embedded URLs
- http://www.gnu.org/software/coreutils/
- http://translationproject.org/team/
- http://gnu.org/licenses/gpl.html
- http://www.gnu.org/gethelp/
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://www.microsoft.com/windows0
- http://www.microsoft.com/pki/certs/MicCodSigPCA_2010-07-06.crt0
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
- http://office.microsoft.com/0
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- www.gnu.org
- translationproject.org
- gnu.org
- cygwin.com
- crl.microsoft.com
- www.microsoft.com
- office.microsoft.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 52.168.117.171
- 4.230.171.124
- 85.210.193.152
- 135.232.92.97
- 4.144.132.114
- 20.42.73.26
- 135.233.95.144
- 172.178.240.163
- 52.110.12.50
- 52.110.12.21
- 52.110.12.48
- 52.110.12.33
File paths
- P:\Target\x86\ship\osfclient\x-none\minsbproxy.pdb
- C:\Python27\lib\atexit.pyt
- C:\Python27\lib\atexit.pyR
- p:\Target\x86\ship\setuptools\x-none\Microsoft.Tools.BinaryStore.pdb
- C:\Users\r.vult\AppData\Local\Temp\gen_py
More Sivis samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report