MALICIOUS — 644545f174841d2b92166b6e69dcf6b965634f0fe4d0c8a861091434e83d5078
MALICIOUS — 644545f174841d2b92166b6e69dcf6b965634f0fe4d0c8a861091434e83d5078 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Sivis family. 4 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
644545f174841d2b92166b6e69dcf6b965634f0fe4d0c8a861091434e83d5078 - SHA-1:
371997ffed77456bcd681e1cf0b5a2db468f0413 - MD5:
800ffb45a819ca19a7afdc7366abf454 - imphash:
38aa7c2ff6ef0e48a9520d6702d08df4 - ssdeep:
6144:5viki+iUSMsiwXgsMvApOmyHGAQOT5y59ssgEV0wMsatS6imLc9hlwCacIT51oXh:hxFMhQvAFmsdKbkwlcIT5kyFhNGpWTa - TLSH:
T11B4AC70673694079C1E748BB28AD5E2FD490269E301164F285D59BD07AB48F3BC1E3BB - Submitted as: 644545f174841d2b92166b6e69dcf6b965634f0fe4d0c8a861091434e83d5078
- File type: pe · Size: 431705 bytes
- Verdict: malicious (98/100) · Family: Sivis
Detections (4 of 55 engines)
- ClamAV (daily): Win.Trojan.Agent-6943819-1
- Microsoft Defender: Virus:Win32/Sivis.A
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Kaspersky (KVRT): Virus.Win32.Agent.es
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Agent-6943819-1 (rule
Win.Trojan.Agent-6943819-1) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 4 finding(s), e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.55, confidence 0.85 - Contacted 30 external host(s) at runtime (22 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- Embedded network infrastructure: http://creativecommons.org/publicdomain/zero/1.0/, http://pubs.opengroup.org/onlinepubs/9699919799/, http://tiswww.case.edu/~chet/bash/POSIX - static signal, weight 0.35, confidence 0.60
- Dropped 83 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Extracted generic config (3 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
25519 behavior events · 0 ATT&CK techniques · 97 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- settings-win.data.microsoft.com
Dropped files
- C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-file-l1-1-0.dll -
c643b505bd0f9b4d864fe472628ceca8e3515905ef634b3744b0e41119ea9f9e - C:\$WinREAgent\Backup\boot.sdi -
78efa15aa422d6cb00d4d726a2ff7d209b455b70886525158b5a1a67eadb5d8c - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\awt.dll -
19bd594f715d5cc0d18451c7e307f649c4b45d0dc2eef7038481d2841a3cb6aa - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-crt-filesystem-l1-1-0.dll -
90f34d14e8d6caab886c0d98b75e22fd674361fb1af428e1be29fdd379cd7176 - C:\$WinREAgent\Rollback.xml -
ac9026b33a3b8c1830e6695c8335dca8c7595a355f6d068ef2332d9df7da716c - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-synch-l1-2-0.dll -
6ae85c9912cc44126f47412348e93f28f7b055a97a62ecb5e431e5ecdd6404f1 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-crt-multibyte-l1-1-0.dll -
1821921ae6bc38228385ef50bb3acb5c16cb907d5d73bec067a06d1240e58ee7 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-crt-string-l1-1-0.dll -
fbdba3568e78652c8df29239a9e7505f2fa8cf788ba40b19b1941b80a0dd0f5c - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\kinit.exe -
574a675ee94acdb4316b0a5fb62ddabff8e98dac0b18257a819c729e3cf58e69 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-namedpipe-l1-1-0.dll -
1883016506bf3e93b7a2058d08449a6f45fbc54160722c857b5b466e6bba8a3d - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-memory-l1-1-0.dll -
3217cfcb61bde9734a28a820a4f61ccb123dcb03ed1a1e2ce276a2737d297316 - C:\792.ini -
9384526b5b69329d706988ddad061a45020ff21da219fb8f3767ac218789b321 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\dt_socket.dll -
fc564b8b51161d3e7d811bef803ffd77f2dde50215ded88f23d5dd7d94d99d0e - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jaas.dll -
7fa6fbe0a0d96685c8acd1cf7beb545162ad7d9ef961414e4f9db69f36aa5c72 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-debug-l1-1-0.dll -
486b9cad3fb2b8cf47be2a8c062ff6370db810ecacba9e1fdfffb4e838f31d97
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- http://pubs.opengroup.org/onlinepubs/9699919799/
- http://tiswww.case.edu/~chet/bash/POSIX
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787897766&P2=404&P3=2&P4=W8Im%2fNb%2fArPkN4c0lJfHZHSYSRTaIcWwzhd7%2fX4f5hm6j8CXigBd5oc9pGPtf3GPoiVanyn%2fuFrI4Q0w4C6GmA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787897845&P2=404&P3=2&P4=Bk%2fSkKDgMf%2b8%2bV5c77wLLtxpsucmWJIjgysF2FuMdGwcpRPPLgeyxje%2brL7%2fwPXNzg687BpQsa5XTRIkOUEYfg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- creativecommons.org
- geocities.com
- 1.sh
- pubs.opengroup.org
- tiswww.case.edu
- gnu.org
- case.edu
- ftp.gnu.org
Embedded IP addresses
- 4.150.223.105
- 172.215.188.232
- 4.230.171.124
- 20.247.184.142
- 135.232.92.137
- 40.79.167.9
- 74.178.240.51
- 135.233.95.144
- 52.178.17.2
- 40.104.4.2
- 20.76.201.171
- 52.123.128.14
- 40.99.134.2
- 52.123.129.14
- 135.234.160.246
- 203.26.79.13
- 74.178.232.29
- 172.66.2.5
- 52.123.252.243
- 52.148.114.188
- 135.234.160.245
- 52.110.12.14
- 52.110.12.16
- 20.184.175.14
- 52.178.17.234
File paths
- X:\windows\system32\sysreset.exe
- X:\windows\system32\Dism\SiloedPackageProvider.dll.
- X:\windows\system32\Dism\MetaDeployProvider.dll.
- C:\Windows
- C:\$WINDOWS.~BT\NewOS\Windows
- C:\,
- C:\inetpub
- C:\Windows.old\inetpub,
- C:\SkyDriveTemp
- C:\Windows.old\SkyDriveTemp,
- C:\Recovery
- C:\Windows.old\Recovery,
- C:\Windows.old\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim]
- C:\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim]
- C:\Windows.old\Recovery]
- C:\Recovery\ReAgentOld.xml)
- C:\Windows.old]
- C:\Reset_SafeToDelete_OverwriteSpaceFile_0.tmp]
- C:\Windows\System32\ResetEngine.exe
More Sivis samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report