MALICIOUS — silverfox_hta.hta
MALICIOUS — silverfox_hta.hta is a hta sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 2 of 23 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
87f2552baff86893a70431dbb9c88f28c6b9abe5fb4a9408518f3bac58e76a41 - SHA-1:
6e7b4605a89d5c7cfa7288df0181d327e513f3f4 - MD5:
7b9fdc93f7f64c2b1359d56e0c100f01 - ssdeep:
384:AN1EoCRc+hmy8sRhOSFWVnI6oYFae7Xyd+45Dpclsqnv:QVPagO+45Dalsiv - TLSH:
T10C250608D54F73869CC641C2FC0660B50F6C7DE79925A8C98FB36E46E639DCA287460E - Submitted as: silverfox_hta.hta
- File type: hta · Size: 12846 bytes
- Verdict: malicious (99/100)
Detections (2 of 23 engines)
- Emsisoft (Emergency Kit): Trojan.GenericKD.80988258
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- 2 behavioral detection(s): LOLBin: mshta executing remote/scripted payload [high] (rule
tl-lolbin-mshta) - dynamic signal, weight 0.60, confidence 0.90 - Memory forensics: 3 finding(s), e.g. RWX/private injected region in svchost.exe (pid 928) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.GenericKD.80988258 (rule
Trojan.GenericKD.80988258) - engine signal, weight 0.55, confidence 0.85 - Dropped a suspicious payload: 13d22b1d1ed2476e851ffa19d998f3a43e657212b30fa061168d7c9240823eb1 - dynamic signal, weight 0.50, confidence 0.90
- Obfuscated powershell script: dynamic-exec, hidden-window, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 35 external host(s) at runtime (21 HTTP) - network signal, weight 0.40, confidence 0.80
- Document contains macros/active content: hta-application, create-object, wscript-shell, powershell - static signal, weight 0.35, confidence 0.75
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
39667 behavior events · 2 ATT&CK techniques · 30 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- hqrflcvifczglqtbukdu.supabase.co
- 85-9-207-79.de-fra1.upcloud.host
- x2.c.lencr.org
- ye.c.lencr.org
- ye1.c.lencr.org
- ctldl.windowsupdate.com
- login.live.com
- v20.events.data.microsoft.com
- desktop-hsgcbep
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- msedge.api.cdp.microsoft.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- assets.msn.com
Dropped files
- /opt/CAPEv2/storage/analyses/8785/files/74f50d5973029d806e519fc5ef33d1827b55eeca528a5099d3c5928d6be0c6bd -
74f50d5973029d806e519fc5ef33d1827b55eeca528a5099d3c5928d6be0c6bd - /opt/CAPEv2/storage/analyses/8785/files/12fd0590708bb38d8039bc994178acee8a3d220f0cd194b0f1c2fc9ba622f927 -
12fd0590708bb38d8039bc994178acee8a3d220f0cd194b0f1c2fc9ba622f927 - /opt/CAPEv2/storage/analyses/8785/files/294f073319c20c75327d0cfd607647cf848ac05d96bc8eb99f2f523d7690ee52 -
294f073319c20c75327d0cfd607647cf848ac05d96bc8eb99f2f523d7690ee52 - /opt/CAPEv2/storage/analyses/8785/files/249393f531757788c270db020ba068f6f2ad78cb546a53fbd70fbce58278689f -
249393f531757788c270db020ba068f6f2ad78cb546a53fbd70fbce58278689f - /opt/CAPEv2/storage/analyses/8785/files/4b182f9ba81e172881f1cbbfc771dfa3ef40366a1dcf505ccff0787bcf3554cc -
4b182f9ba81e172881f1cbbfc771dfa3ef40366a1dcf505ccff0787bcf3554cc - /opt/CAPEv2/storage/analyses/8785/files/3dd5ea8a14eb665ba6057d424f94e5e83757ffaab456578dbf038af04053b19e -
3dd5ea8a14eb665ba6057d424f94e5e83757ffaab456578dbf038af04053b19e - /opt/CAPEv2/storage/analyses/8785/files/c9b2f3a89dc364622c41d95c89660e195266df6a2831c986d1b4554f5f8bf58f -
c9b2f3a89dc364622c41d95c89660e195266df6a2831c986d1b4554f5f8bf58f - /opt/CAPEv2/storage/analyses/8785/files/49b0cf4517864406b79f56c42d984d25aa67694a678e2fac27c8ca3a3e3d3e37 -
49b0cf4517864406b79f56c42d984d25aa67694a678e2fac27c8ca3a3e3d3e37 - /opt/CAPEv2/storage/analyses/8785/files/13d22b1d1ed2476e851ffa19d998f3a43e657212b30fa061168d7c9240823eb1 -
13d22b1d1ed2476e851ffa19d998f3a43e657212b30fa061168d7c9240823eb1 - /opt/CAPEv2/storage/analyses/8785/files/1393e9a43414b0eead408bb6d9547a2239ce8858c589000018f7c9a9e9aa3488 -
1393e9a43414b0eead408bb6d9547a2239ce8858c589000018f7c9a9e9aa3488 - /opt/CAPEv2/storage/analyses/8785/files/251ed08cc8f5873098ea5ee083034e7cd99ece955920e12a42e50306a94cb6eb -
251ed08cc8f5873098ea5ee083034e7cd99ece955920e12a42e50306a94cb6eb - /opt/CAPEv2/storage/analyses/8785/files/96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7 -
96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7 - /opt/CAPEv2/storage/analyses/8785/files/94c3c30f1011e857636d3d980deb02675db92971849d8ab6b79e81a52c6f9c1b -
94c3c30f1011e857636d3d980deb02675db92971849d8ab6b79e81a52c6f9c1b - /opt/CAPEv2/storage/analyses/8785/files/16267f0db4d806d4e04324c72e21df9a2c526575370426aeba9c76f1b36f6136 -
16267f0db4d806d4e04324c72e21df9a2c526575370426aeba9c76f1b36f6136 - /opt/CAPEv2/storage/analyses/8785/files/1b156fcdc1aa7cbf15ca77971c12917fced2857e35a15709b20f02ea14908214 -
1b156fcdc1aa7cbf15ca77971c12917fced2857e35a15709b20f02ea14908214
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786360729&P2=404&P3=2&P4=SZW5CjVuWU7gLB7vhwN3NzHLaImp0ke0Flm5nBOImilO8%2fWOltiyccvn1uxkWCysXhZx5a4ngaMYB1Y7nwBgAQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786360752&P2=404&P3=2&P4=SuPcx7uUn3DuFAE9cpk5M07uNlVi0DReXWtzC1mwTFRqrIBbAOfk2KzqCLAGcfGtnHYIiNHAF9v%2fFyyGz%2b1Sqg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://ye1.c.lencr.org/107.crl
Embedded domains
- hqrflcvifczglqtbukdu.supabase.co
- 85-9-207-79.de-fra1.upcloud.host
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- ye1.c.lencr.org
Embedded IP addresses
- 13.69.116.104
- 4.230.171.124
- 52.230.60.54
- 85.210.196.11
- 4.247.188.233
- 74.178.232.29
- 74.179.77.204
- 135.233.95.135
- 203.26.79.13
- 52.168.117.169
- 135.233.45.222
- 85.9.207.79
- 72.154.7.109
- 172.64.149.246
- 52.148.114.188
- 104.18.21.213
- 52.110.12.50
- 52.110.12.14
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report