MALICIOUS — 5e569aca0902f3796c4d90ccbbba1979685eac772623396d034da3879c0b0ac6
MALICIOUS — 5e569aca0902f3796c4d90ccbbba1979685eac772623396d034da3879c0b0ac6 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Delf family. 6 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
5e569aca0902f3796c4d90ccbbba1979685eac772623396d034da3879c0b0ac6 - SHA-1:
8600f454d02eb23d380aedda5786e6c6d1487209 - MD5:
51d41051e5e5cc87148c491a0042d5db - imphash:
500ff1538958cc73738bf0c262a1773f - ssdeep:
196608:FA3n9TAn9Tin9Tin9TFn9TBfUefU1n9Tin9Tin9TBfU1n9TBfUefU1n9Tin9Tin:4CccrzFmcczmzFmcc - TLSH:
T15C6AE0C1622261F1DE92CEA40DD07E0F11A1B34625FC7D8D4282597E37E92EBB04F699 - Submitted as: 5e569aca0902f3796c4d90ccbbba1979685eac772623396d034da3879c0b0ac6
- File type: pe · Size: 9640192 bytes
- Verdict: malicious (99/100) · Family: Delf
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.dafixer,.dafixer,.dafixer,.dafixer,.dafixer
- ClamAV (daily): Win.Virus.Delf-9955432-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:Turbo Linker
- Microsoft Defender: Trojan:Win32/Vindor!pz
- Emsisoft (Emergency Kit): Trojan.Generic.33849684
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Win.Virus.Delf-9955432-0 (rule
Win.Virus.Delf-9955432-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Vindor!pz (rule
Trojan:Win32/Vindor!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Generic.33849684 (rule
Trojan.Generic.33849684) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Contacted 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-sections:.dafixer,.dafixer,.dafixer,.dafixer,.dafixer (rule
high-entropy-sections:.dafixer,.dafixer,.dafixer,.dafixer,.dafixer) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: high-entropy-sections:.dafixer,.dafixer,.dafixer,.dafixer,.dafixer, Turbo Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
844 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- edge.microsoft.com
- time.windows.com
- settings-win.data.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
Embedded URLs
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-cs-g1.crl05
- http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
- http://www.digicert.com/ssl-cps-repository.htm0
- http://crl.thawte.com/ThawteTimestampingCA.crl0
- http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
- http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
- http://appsyndication.org/2006/appsyn
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- mb.fi
- www.microsoft.com
- crl.microsoft.com
- schemas.microsoft.com
- cacerts.digicert.com
- crl4.digicert.com
- crl3.digicert.com
- www.digicert.com
- crl.thawte.com
- ts-aia.ws.symantec.com
- ts-crl.ws.symantec.com
- appsyndication.org
Embedded IP addresses
- 20.184.175.23
- 52.253.84.76
- 52.123.252.239
- 4.230.171.124
- 4.144.132.223
- 85.210.196.11
- 40.84.85.40
- 72.154.7.103
- 52.148.114.188
- 52.110.12.11
- 52.110.12.42
File paths
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System\37a1d51f35918dd36a0d4e34cc91732e\System.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wad78daf4#\8f73bd36654fa77803c3167f39ead17e\Microsoft.Windows.Diagnosis.SDHost.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wed3937f9#\3dae65a1b718d3a083094b67e1413e9a\Microsoft.Windows.Diagnosis.SDCommon.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\89bc329e8c65a9e13067c9776d925d78\System.Core.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\f02732d562721457afde5c189a906d17\System.Management.Automation.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.W0bb5dac4#\4c396dcf426dbba8eddd04adc0b562fe\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.W69ef49d2#\9dcd27fe1c298162f13c6bdb7c0cfe88\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wd518ee0d#\e9bd08c5c1a8c5fdef45c7025b262edc\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.W708fc392#\3c226a9afdce13116b1fdfa9e92b4152\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.W79a81d80#\2efe3e39ab8a210a684558961ff266d2\Microsoft.Windows.Diagnosis.Commands.WriteDiagTelemetry.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.P1706cafe#\16ab851088227b0798b233d026a1019e\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Confe64a9051#\29c26981c4b4347ca371002934f6f2ac\System.Configuration.Install.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Pb378ec07#\dac77e2bdc0040a1a2a446cbf77b6bae\Microsoft.PowerShell.ConsoleHost.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.P521220ea#\29b929ef5de7ccdae8f74f1083a729c8\Microsoft.PowerShell.Commands.Utility.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Pae3498d9#\a78370d535d159d2691edea0727e654d\Microsoft.PowerShell.Commands.Management.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.P6f792626#\4b6994043bbc39d9e47433716afb9e98\Microsoft.PowerShell.Security.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.We0722664#\a2e162c411e7960d3320a700179232fc\Microsoft.WSMan.Management.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data\dcffb1d4b51a427f7c054b15597ef269\System.Data.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\1fb6db2ce6d2887fe6f8f620cb092343\System.Xml.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Management\dee95ca75ccebe1cc18b31dca334cd53\System.Management.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Dired13b18a9#\4ac88f62ef161467f8e9dd4985837e51\System.DirectoryServices.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\b5152c3c02957bbe4459505a39afde20\System.Configuration.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Transactions\0935f5dce0a38689b9507cb1938fe436\System.Transactions.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Numerics\568282207f7c6c41d18e9e38637dbe77\System.Numerics.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System\08f69c55e9284eaab92075159503c897\System.ni.dll
More Delf samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report