MALICIOUS — 6b57d68b6392cb44a62c5b7d68bf256621c2646934fd754f64dfbc70077640b6
MALICIOUS — 6b57d68b6392cb44a62c5b7d68bf256621c2646934fd754f64dfbc70077640b6 is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (76/100), attributed to the Maldoc family. 1 of 54 detection engines flagged it.
Identification
- SHA-256:
6b57d68b6392cb44a62c5b7d68bf256621c2646934fd754f64dfbc70077640b6 - SHA-1:
7b2464945bf5b13859face2af4bd8da3dfd73a5c - MD5:
c5627a527b61c9252d5cbbcf3b1c2ea9 - ssdeep:
768:lZ6uiTtiDMrAoSoTPpZDBdvFkFSI+8loTPpB:lZ6FmoxjDRL - TLSH:
T143310D04E70F947B874EBCA3B0D6E0285E4768DCA07E63CD57DE710948EAC64D27894A - Submitted as: 6b57d68b6392cb44a62c5b7d68bf256621c2646934fd754f64dfbc70077640b6
- File type: script · Size: 42482 bytes
- Verdict: malicious (76/100) · Family: Maldoc
Detections (1 of 54 engines)
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
Why this verdict
The malicious score of 76/100 is the fusion of 3 weighted signals:
- YARA: delivr.to detections flagged DLV_Maldoc_VBA_AutoExec (rule
DLV_Maldoc_VBA_AutoExec) - engine signal, weight 0.70, confidence 0.70 - Obfuscated vbscript script: download, dynamic-exec, shellcode-injection, defense-evasion (layers: base64) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://www.motobit.com, https://codes-sources.commentcamarche.net/so, https://bit.ly/2Kz5Fyk - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1101 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- 23.40.52.85
- 40.126.14.162
Embedded URLs
- http://www.motobit.com
- https://codes-sources.commentcamarche.net/so
- https://docs.microsoft.com/en-us/windows/desktop/api/winbase/ns-winbase-
- https://bit.ly/2Kz5Fyk
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- www.motobit.com
- codes-sources.commentcamarche.net
- ctivevb.de
- docs.microsoft.com
- bit.ly
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 48.211.4.16
- 85.210.193.152
- 40.84.85.40
- 74.178.76.128
- 162.159.142.9
- 20.89.1.12
- 20.247.184.197
- 52.110.12.33
- 52.110.12.1
- 4.230.171.124
- 74.178.240.51
- 135.232.92.137
- 40.79.141.152
- 4.150.223.110
- 57.155.104.224
Registry keys
- HKEY_CURRENT_USER\Software\Microsoft\Office\\
More Maldoc samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report