SUSPICIOUS — 5e953834d1637235ffa877449bb8567af8e4d4a4f49ecad8289f7e0e40f724d2
SUSPICIOUS — 5e953834d1637235ffa877449bb8567af8e4d4a4f49ecad8289f7e0e40f724d2 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (64/100), attributed to the Maldoc family. 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5e953834d1637235ffa877449bb8567af8e4d4a4f49ecad8289f7e0e40f724d2 - SHA-1:
66489e1070376d80bf6a56232d2c35428ee0a1eb - MD5:
a2558e1a58d9b14d2649182c26fd6a68 - ssdeep:
96:lLhx5nj45nb5ekURRcD567tosE2X5u50A6F6YpUNZeA+bVx5Ve2wD60vnQFQUutu:lSt+R2efEGFR - TLSH:
T17C2D3FD7BCD0235FC5ACFB01C61A48B112121BD4AA3ABE991D8DA940E10F9B3D436F61 - Submitted as: 5e953834d1637235ffa877449bb8567af8e4d4a4f49ecad8289f7e0e40f724d2
- File type: script · Size: 27673 bytes
- Verdict: suspicious (64/100) · Family: Maldoc
Detections (3 of 53 engines)
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
- Microsoft Defender: flagged
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 64/100 is the fusion of 3 weighted signals:
- Obfuscated vbscript script: download (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - YARA: delivr.to detections flagged DLV_Maldoc_VBA_AutoExec (rule
DLV_Maldoc_VBA_AutoExec) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Maldoc samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report