MALICIOUS — 785cbaa2f4d202a79d15fe7c717796f81693191570e9d7e7415936b2d8488d10
MALICIOUS — 785cbaa2f4d202a79d15fe7c717796f81693191570e9d7e7415936b2d8488d10 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Maldoc family. 10 of 55 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
785cbaa2f4d202a79d15fe7c717796f81693191570e9d7e7415936b2d8488d10 - SHA-1:
0b746848c40830df4ba8917067ffa7899ddd2566 - MD5:
9d6aa0a4eab5e28d96445282ff5b8039 - imphash:
f5e2fae08fb1c8fba965c988eb10e880 - ssdeep:
393216:Sq9K51KDC7vq2RwuLOUYmWWXdMhiyYv4N16rrY:Sq9KjwuLOUYmWm4N12c - TLSH:
T1EA709E9E51026207F1F2DBA88A508E8E84D7E4E564FA18AD57C3D01E6BE4DFB71103E4 - Submitted as: 785cbaa2f4d202a79d15fe7c717796f81693191570e9d7e7415936b2d8488d10
- File type: pe · Size: 16611689 bytes
- Verdict: malicious (98/100) · Family: Maldoc
Detections (10 of 55 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Malware.Generickdz-9832066-0
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
- YARA: InQuest Labs: CVE_2018_4878_0day_ITW
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Stratosphere IPS: STRATO_Malicious_UserAgent
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Trojan:Win32/Vindor!pz
- Emsisoft (Emergency Kit): Gen:Variant.Ransom.Phobos.154
- Kaspersky (KVRT): HEUR:Trojan.Win32.Scar.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Win.Malware.Generickdz-9832066-0 (rule
Win.Malware.Generickdz-9832066-0) - engine signal, weight 0.90, confidence 0.95 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: delivr.to detections flagged DLV_Maldoc_VBA_AutoExec (rule
DLV_Maldoc_VBA_AutoExec) - engine signal, weight 0.35, confidence 0.70 - YARA: InQuest Labs flagged CVE_2018_4878_0day_ITW (rule
CVE_2018_4878_0day_ITW) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Malicious_UserAgent (rule
STRATO_Malicious_UserAgent) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://http.proxy.icq.com/hello, https://www.macromedia.com/support/flashplayer/sys/, https://ats.macromedia.com/Players/ATS/ATS10AS3/Shipping/html/Security/ProtectedMode/PenTestDriverDLL.sgn - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://http.proxy.icq.com/hello
- http://www.adobe.com/go/about_flash_player
- https://www.macromedia.com/support/flashplayer/sys/
- https://ats.macromedia.com/Players/ATS/ATS10AS3/Shipping/html/Security/ProtectedMode/PenTestDriverDLL.sgn
- http://www.adobe.com/go/learn_fp_safari_safe_mode
- http://adobe.com/go/addlocalstorage_rs
- http://adobe.com/go/addlocalstorage_ee
- http://adobe.com/go/addlocalstorage
- http://adobe.com/go/addlocalstorage_lt
- http://adobe.com/go/addlocalstorage_lv
- http://adobe.com/go/addlocalstorage_ua
- http://adobe.com/go/addlocalstorage_hr
- http://adobe.com/go/addlocalstorage_ro
- http://adobe.com/go/addlocalstorage_si
- http://adobe.com/go/addlocalstorage_bg
- http://adobe.com/go/addlocalstorage_sk
- http://www.adobe.com/go/learn_fp_safari_safe_mode_ae
- http://www.adobe.com/go/learn_fp_safari_safe_mode_fi
- http://adobe.com/go/addlocalstorage_fi
- http://www.adobe.com/go/learn_fp_safari_safe_mode_hu
- http://adobe.com/go/addlocalstorage_hu
- http://www.adobe.com/go/learn_fp_safari_safe_mode_no
- http://adobe.com/go/addlocalstorage_no
- http://www.adobe.com/go/learn_fp_safari_safe_mode_pt
- http://adobe.com/go/addlocalstorage_pt
Embedded domains
- http.proxy.icq.com
- login.icq.com
- www.adobe.com
- adobe.com
- swf.name
- www.macromedia.com
- macromedia.com
- ats.macromedia.com
- mem.network
- flash.net
- fpdownload2.macromedia.com
- fpdownload.macromedia.com
- auth.adobefpl.com
- primetimeengineering.sc.omtrdc.net
- s3.amazonaws.com
- dashif.org
- youtube.com
- cdn.auditude.com
- theplatform.com
- cdn2.auditude.com
- ad.auditude.com
- www.w3.org
- www.openssl.org
- o.za
- s.symcb.com
Embedded IP addresses
- 0.0.0.1
- 25.0.0.127
- 10.3.183.10
- 10.3.183.8
- 10.3.183.7
- 10.3.183.5
- 10.3.181.34
- 10.3.181.26
- 10.3.181.23
- 10.3.181.22
- 10.3.181.16
- 10.3.181.14
- 10.3.181.12
- 10.3.181.10
- 10.3.181.5
- 10.3.181.0
- 10.3.180.65
File paths
- e:\r\ws\st_make\code\modules\media\source\parsers\FragmentedHTTPStreamer.h
- e:\r\ws\st_make\code\modules\media\source\parsers\CEA_608_708.h
- e:\r\ws\st_make\code\modules\media\source\parsers\HlsParser.h
- e:\r\ws\st_make\code\modules\media\source\MediaUtils.h
- e:\r\ws\st_make\code\modules\media\source\parsers\F4FParser.h
- e:\r\ws\st_make\code\modules\media\source\adapters\sndcodec.h
- X:\:
- X:\:`:d:h:
- I:\:
- V:\:f:l:r:
- K:\:o:
- S:\:
- V:\=f=
- X:\:`:d:h:l:p:t:x:
- P:\;
- H:\:p:
- W:\:`:d:
- O:\;`;d;h;l;p;t;x;
- X:\:d:h:p:t:x:
- X:\:d:h:p:t:
- T:\:`:h:l:t:x:
- X:\:`:h:l:p:t:x:
- X:\:`:
- X:\:`:d:h:l:
- T:\:d:l:t:
More Maldoc samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report