MALICIOUS — 7ecf817020c0aba03d78f6ee1243a657d80741c91ee706161e24dae784d71333
MALICIOUS — 7ecf817020c0aba03d78f6ee1243a657d80741c91ee706161e24dae784d71333 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Sivis family. 8 of 56 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7ecf817020c0aba03d78f6ee1243a657d80741c91ee706161e24dae784d71333 - SHA-1:
9b597a659d485141b0eabc07e4f6963e8d86598a - MD5:
4b1a7f048075d3f9a08b289c8bee5f21 - imphash:
38aa7c2ff6ef0e48a9520d6702d08df4 - ssdeep:
6144:TeE0EFMFnUNixTmAcThAkZThMTMkS9vF3AK8:ibEFMFnUNix1c60yjS9vRAK - TLSH:
T137438D5710A0E86AE390119B3928F67E05CBDC254776584D62D8E7A0813843FB2FFB67 - Submitted as: 7ecf817020c0aba03d78f6ee1243a657d80741c91ee706161e24dae784d71333
- File type: pe · Size: 229379 bytes
- Verdict: malicious (100/100) · Family: Sivis
Detections (8 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Agent-6943819-1
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:UPX
- Microsoft Defender: Virus:Win32/Sivis.A
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Trellix Stinger (McAfee): PolyPatch-UPX
- Kaspersky (KVRT): Virus.Win32.Agent.es
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 15 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Agent-6943819-1 (rule
Win.Trojan.Agent-6943819-1) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Virus:Win32/Sivis.A (rule
Virus:Win32/Sivis.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Sivis.A (rule
Win32.Sivis.A) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PolyPatch-UPX (rule
PolyPatch-UPX) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.Agent.es (rule
Virus.Win32.Agent.es) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Contacted 2 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:UPX (rule
DIE:UPX) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.gnu.org/licenses/, http://creativecommons.org/publicdomain/zero/1.0/, https://www.gnu.org/software/automake/manual/automake.html - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: UPX - static signal, weight 0.25, confidence 0.55
- Dropped 10 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Extracted generic config (4 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 4 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
14996 behavior events · 0 ATT&CK techniques · 97 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- desktop-hsgcbep
- login.live.com
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- www.bing.com
- assets.msn.com
- watson.events.data.microsoft.com
- edge.microsoft.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Dropped files
- C:\Program Files\7-Zip\Lang\bn.txt -
03c971d927fe5b3c7e8b0be1dd693cd427d57779de23093f28d58bd5ce92fe3d - C:\Config.Msi\PTA956.tmp -
7d948e84f4f481d396fa1b2bc5c50b971838f866538dcac47396cfe19895ce0c - C:\Program Files\7-Zip\Lang\fi.txt -
15d2c7931e202451749cca398d9a9dbf2d5cfd2cd70d31da29ebb7fe8c2a07a5 - C:\Program Files\7-Zip\7z.dll -
4d0f21b3ad96e323ae2da0c34f6e634ad35a8bb6bed2d3862048ffc42eb8912c - C:\Program Files\7-Zip\Lang\kab.txt -
15574404908c3977b4d9a877ff68586104d98664f8b96b3c08aa074344551f3a - C:\Program Files\7-Zip\Lang\fur.txt -
1a3e0df954d9020379e2ec5617dd49e5c7b2ec5fb756ac628fbb14e5593d6b77 - C:\Program Files\7-Zip\Lang\ne.txt -
16971209276dcb8ca3857f0a96e2804cfe1c996a7306c6ce4cd9aed3f591348a - C:\Program Files\7-Zip\Lang\ps.txt -
6d2f46c8ae4f85ef561d7dca0e17f6072cbe3bd85f602886f901155bce4bdc24 - C:\Program Files\7-Zip\Lang\ast.txt -
807cc18a8ad0ff939eb4fef01da81538d3196adaa3c14bedb62bb5b39d6fe477 - C:\Program Files\7-Zip\Lang\ar.txt -
c3583209ffa40df68544994452f933487e8b060f258f7e406fa293ce736629e9 - C:\Program Files\7-Zip\Lang\ja.txt -
443dc99abd6ebff598a8feaa75bf8b8154c40438fc5a6525123ff47c03bcba91 - C:\Program Files\7-Zip\Lang\lij.txt -
8c17c6f7a7498962dfb6db5df243a63da9979c6f0964558d2deeb302deb647ec - C:\Program Files\7-Zip\Lang\mng2.txt -
52f74597bc5edba22cd6bb379855414187ba9726ed54d16a6a26d4d34207eba9 - C:\792.ini -
2ed9b09edd11e98547c1ab4136b32838ec09e1d418881a7f36694f607727c3bc - C:\Program Files\7-Zip\Lang\cs.txt -
ff5189a79762c553a8b76c4db11c4c967386f2379931c34990730c574d46c86d
Embedded URLs
- http://www.gnu.org/licenses/
- http://creativecommons.org/publicdomain/zero/1.0/
- https://www.gnu.org/software/automake/manual/automake.html
- http://fsmsh.com/2753
- https://autotools.io/index.html
- http://miller.emu.id.au/pmiller/books/rmch/
- https://www.digicert.com/CPS0
- http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
- http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
- http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
- http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
- http://www.digicert.com/ssl-cps-repository.htm0
- https://d.symcb.com/rpa0
- http://s.symcb.com/universal-root.crl0
- https://d.symcb.com/rpa0@
- http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
- http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- cwru.edu
- gnu.org
- www.gnu.org
- creativecommons.org
- fsmsh.com
- autotools.io
- miller.emu.id.au
- www.adobe.com
- helpx.adobe.com
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- cacerts.digicert.com
- d.symcb.com
- s.symcb.com
- ts-crl.ws.symantec.com
- ts-aia.ws.symantec.com
Embedded IP addresses
- 52.168.117.168
- 4.144.132.223
- 4.230.171.124
- 172.66.2.5
- 135.233.45.221
- 52.110.12.14
- 52.110.12.40
- 52.110.12.10
- 52.110.12.21
File paths
- X:\windows\system32\sysreset.exe
- X:\windows\system32\Dism\SiloedPackageProvider.dll.
- X:\windows\system32\Dism\MetaDeployProvider.dll.
- C:\Windows
- C:\$WINDOWS.~BT\NewOS\Windows
- C:\,
- C:\inetpub
- C:\Windows.old\inetpub,
- C:\SkyDriveTemp
- C:\Windows.old\SkyDriveTemp,
- C:\Recovery
- C:\Windows.old\Recovery,
- C:\Windows.old\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim]
- C:\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim]
- C:\Windows.old\Recovery]
- C:\Recovery\ReAgentOld.xml)
- C:\Windows.old]
- C:\Reset_SafeToDelete_OverwriteSpaceFile_0.tmp]
- C:\Windows\System32\ResetEngine.exe
More Sivis samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report