MALICIOUS — 766be290e8d98ff9ce544ce6c4d898f721eb46a2ca69e738dfb191dae31ea7e5
MALICIOUS — 766be290e8d98ff9ce544ce6c4d898f721eb46a2ca69e738dfb191dae31ea7e5 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Maldoc family. 10 of 56 detection engines flagged it, exhibiting 8 ATT&CK techniques.
Identification
- SHA-256:
766be290e8d98ff9ce544ce6c4d898f721eb46a2ca69e738dfb191dae31ea7e5 - SHA-1:
c02a4c050da9f204e3786850248a8f0bfefe1a8f - MD5:
6fa9e70a7aa529c92b74d5f4fc6690c4 - imphash:
f5e2fae08fb1c8fba965c988eb10e880 - ssdeep:
393216:Sq9K51KDC7vq2RwuLOUYmWWXdMhiyYv4N16rrYfJ:Sq9KjwuLOUYmWm4N12sfJ - TLSH:
T16070AE9E51026207F1F2DBA886508E8E80D7E4E564FA18AD57C3E11E6FE4DFB71102E4 - Submitted as: 766be290e8d98ff9ce544ce6c4d898f721eb46a2ca69e738dfb191dae31ea7e5
- File type: pe · Size: 16608762 bytes
- Verdict: malicious (100/100) · Family: Maldoc
Detections (10 of 56 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Malware.Generickdz-9832066-0
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
- YARA: InQuest Labs: CVE_2018_4878_0day_ITW
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Stratosphere IPS: STRATO_Malicious_UserAgent
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Trojan:Win32/Vindor!pz
- Emsisoft (Emergency Kit): Gen:Variant.Ransom.Phobos.154
- Kaspersky (KVRT): HEUR:Trojan.Win32.Scar.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 23 weighted signals:
- ClamAV (daily) flagged Win.Malware.Generickdz-9832066-0 (rule
Win.Malware.Generickdz-9832066-0) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s) across 1 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - YARA: delivr.to detections flagged DLV_Maldoc_VBA_AutoExec (rule
DLV_Maldoc_VBA_AutoExec) - engine signal, weight 0.70, confidence 0.70 - YARA: InQuest Labs flagged CVE_2018_4878_0day_ITW (rule
CVE_2018_4878_0day_ITW) - engine signal, weight 0.70, confidence 0.70 - Microsoft Defender flagged Trojan:Win32/Vindor!pz (rule
Trojan:Win32/Vindor!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Ransom.Phobos.154 (rule
Gen:Variant.Ransom.Phobos.154) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win32.Scar.gen (rule
HEUR:Trojan.Win32.Scar.gen) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 2 external host(s) and 15 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- YARA: Stratosphere IPS flagged STRATO_Malicious_UserAgent (rule
STRATO_Malicious_UserAgent) - engine signal, weight 0.45, confidence 0.70 - Anti-analysis: T1497, T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:collection/keylog (rule
capability:collection/keylog) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://http.proxy.icq.com/hello, https://www.macromedia.com/support/flashplayer/sys/, https://ats.macromedia.com/Players/ATS/ATS10AS3/Shipping/html/Security/ProtectedMode/PenTestDriverDLL.sgn - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Dropped 9 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60 - Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
40102 behavior events · 3 ATT&CK techniques · 29 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- officeclient.microsoft.com
- www.msn.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
Dropped files
- C:\Users\analyst\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol -
90cb9360e98292b3670d4f43b6d95c3638c22639add54903c099c446781bc69f - C:\Users\analyst\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol -
c8746efeca1edd7e9d9a336e5685419ed5e90a6de16622715849a11ee024817c - C:\Users\analyst\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol -
75396ca8e99c43977b00969a0f5d39ba10101b7bc6d21f7ebff08f62344ea913 - C:\Users\analyst\AppData\Local\Temp\OCVZD -
951dee16f40fa1f1331f68aac78fbd861b90047a2b4f790852abec475b59218d - C:\Users\analyst\AppData\Local\Temp\tsk_241a8ee348c44cba.exe -
cc81b6555f5bd749d160b8f107d4d24378a9d5b195af47b8575ddc4592214f2e - C:\Users\Public\Microsoft Build\Isass.exe -
157f4ca3e478a59f1573c0bc59f79fd0c16c30adb7ba1a8000a4c8974b51cb88 - C:\Users\analyst\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol -
4b4f70069e2072c81219a465ffeaface0e912569c5efbdfd2e05155def3fe971 - C:\Users\analyst\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol -
1e6364e1a33cce9395071c75f7d8df3759dc475baa6f677422f29c9bcf3e6869 - C:\Users\analyst\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol -
5c1258ed8363e7d550d8213b5f428fc291cb72351db450cd63c9f718eac46df7 - C:\Python3\Lib\venv\scripts\nt\pythonw.exe -
271e26b43df604ddfac87660cb19deee82e4a7bfa7f966448b0f5d8c6a847f3f - C:\Users\analyst\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol -
8d35b1a74f506b7a0815d2d59609a8cd76e7437e657608bbc3a4ca4b26d4c247 - C:\Python3\Lib\venv\scripts\nt\python.exe -
db05a78e8633ab5bcee20e2c0d8344e5ac5c074cd542b14a9b806df55f88052f - C:\Users\analyst\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol -
8601aa9c2c3b0fd12d413eeab8539c6875e2ca5fd9a82c33458f182057e32738 - C:\Python3\Lib\site-packages\pip\_vendor\distlib\t32.exe -
2e88a256563015ee927bdb424b3920f69642d3d1e4db6880749937755f553cb1 - C:\Users\analyst\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol -
699e2e44e7bc2fe35910f867e1d3c5019ece8301b7a18bcbd7dc8f0177ecfc45
Embedded URLs
- http://http.proxy.icq.com/hello
- http://www.adobe.com/go/about_flash_player
- https://www.macromedia.com/support/flashplayer/sys/
- https://ats.macromedia.com/Players/ATS/ATS10AS3/Shipping/html/Security/ProtectedMode/PenTestDriverDLL.sgn
- http://www.adobe.com/go/learn_fp_safari_safe_mode
- http://adobe.com/go/addlocalstorage_rs
- http://adobe.com/go/addlocalstorage_ee
- http://adobe.com/go/addlocalstorage
- http://adobe.com/go/addlocalstorage_lt
- http://adobe.com/go/addlocalstorage_lv
- http://adobe.com/go/addlocalstorage_ua
- http://adobe.com/go/addlocalstorage_hr
- http://adobe.com/go/addlocalstorage_ro
- http://adobe.com/go/addlocalstorage_si
- http://adobe.com/go/addlocalstorage_bg
- http://adobe.com/go/addlocalstorage_sk
- http://www.adobe.com/go/learn_fp_safari_safe_mode_ae
- http://www.adobe.com/go/learn_fp_safari_safe_mode_fi
- http://adobe.com/go/addlocalstorage_fi
- http://www.adobe.com/go/learn_fp_safari_safe_mode_hu
- http://adobe.com/go/addlocalstorage_hu
- http://www.adobe.com/go/learn_fp_safari_safe_mode_no
- http://adobe.com/go/addlocalstorage_no
- http://www.adobe.com/go/learn_fp_safari_safe_mode_pt
- http://adobe.com/go/addlocalstorage_pt
Embedded domains
- http.proxy.icq.com
- login.icq.com
- www.adobe.com
- adobe.com
- swf.name
- www.macromedia.com
- macromedia.com
- ats.macromedia.com
- mem.network
- flash.net
- fpdownload2.macromedia.com
- fpdownload.macromedia.com
- auth.adobefpl.com
- primetimeengineering.sc.omtrdc.net
- s3.amazonaws.com
- dashif.org
- youtube.com
- cdn.auditude.com
- theplatform.com
- cdn2.auditude.com
- ad.auditude.com
- www.w3.org
- www.openssl.org
- o.za
- s.symcb.com
Embedded IP addresses
- 0.0.0.1
- 25.0.0.127
- 10.3.183.10
- 10.3.183.8
- 10.3.183.7
- 10.3.183.5
- 10.3.181.34
- 10.3.181.26
- 10.3.181.23
- 10.3.181.22
- 10.3.181.16
- 10.3.181.14
- 10.3.181.12
- 10.3.181.10
- 10.3.181.5
- 10.3.181.0
- 10.3.180.65
- 20.184.175.19
- 52.230.59.222
- 52.123.252.227
- 4.230.171.124
- 52.110.12.18
- 52.110.12.40
- 104.18.33.89
- 162.159.142.9
File paths
- e:\r\ws\st_make\code\modules\media\source\parsers\FragmentedHTTPStreamer.h
- e:\r\ws\st_make\code\modules\media\source\parsers\CEA_608_708.h
- e:\r\ws\st_make\code\modules\media\source\parsers\HlsParser.h
- e:\r\ws\st_make\code\modules\media\source\MediaUtils.h
- e:\r\ws\st_make\code\modules\media\source\parsers\F4FParser.h
- e:\r\ws\st_make\code\modules\media\source\adapters\sndcodec.h
- X:\:
- X:\:`:d:h:
- I:\:
- V:\:f:l:r:
- K:\:o:
- S:\:
- V:\=f=
- X:\:`:d:h:l:p:t:x:
- P:\;
- H:\:p:
- W:\:`:d:
- O:\;`;d;h;l;p;t;x;
- X:\:d:h:p:t:x:
- X:\:d:h:p:t:
- T:\:`:h:l:t:x:
- X:\:`:h:l:p:t:x:
- X:\:`:
- X:\:`:d:h:l:
- T:\:d:l:t:
More Maldoc samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report