MALICIOUS — 8ca2533fcd9f0fff46a600ea117cf0b8bf20075f4cbd33c47abf463deae82ba2
MALICIOUS — 8ca2533fcd9f0fff46a600ea117cf0b8bf20075f4cbd33c47abf463deae82ba2 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Delf family. 6 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
8ca2533fcd9f0fff46a600ea117cf0b8bf20075f4cbd33c47abf463deae82ba2 - SHA-1:
3daaeec71a5ef43776121162e70470f7d077a3df - MD5:
844acc42824d55ba506dcfcc43ceead3 - imphash:
9973fdd4b86d866b3faa39fa66cf7e0a - ssdeep:
6144:8jMKITkBXkHhIiz1N3pFTXHxwsbcyT55K9Pt:/IK3ppHlDVMPt - TLSH:
T19346AE990246326BC2BBED512C0E9D9E90A3F0E571B40BAD4017C12F27F1533B9F569A - Submitted as: 8ca2533fcd9f0fff46a600ea117cf0b8bf20075f4cbd33c47abf463deae82ba2
- File type: pe · Size: 316783 bytes
- Verdict: malicious (100/100) · Family: Delf
Detections (6 of 56 engines)
- ClamAV (daily): Win.Worm.Delf-6980489-0
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Worm:Win32/Xolxo.A
- Emsisoft (Emergency Kit): Dropped:Generic.Malware.SNm.77E31C26
- Kaspersky (KVRT): P2P-Worm.Win32.Delf.aj
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Worm.Delf-6980489-0 (rule
Win.Worm.Delf-6980489-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Worm:Win32/Xolxo.A (rule
Worm:Win32/Xolxo.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Dropped:Generic.Malware.SNm.77E31C26 (rule
Dropped:Generic.Malware.SNm.77E31C26) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged P2P-Worm.Win32.Delf.aj (rule
P2P-Worm.Win32.Delf.aj) - engine signal, weight 0.55, confidence 0.85 - YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.55, confidence 0.70 - Contacted 16 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.gnu.org/software/coreutils/, http://translationproject.org/team/, http://gnu.org/licenses/gpl.html - static signal, weight 0.35, confidence 0.60
- 1 behavioral detection(s) across 1 rule(s): Discovery: enumerates installed security software [low] (rule
tl-security-software-discovery) - dynamic signal, weight 0.20, confidence 0.90 - Dropped 48 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
37354 behavior events · 0 ATT&CK techniques · 50 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- desktop-hsgcbep
- login.live.com
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
Dropped files
- C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe -
a9a7131f0b6c67b3781c2495c086909d92a48e3ebbc953f4429b00d913920dea - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe -
530e120d31aa6fdc2f88b5a940ca220c1f1530023b51e00f3f766e65d165002f - C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe -
153b8dd213d019210d80d6978a157acc46fe437203fe725e33ccfaaefc293888 - C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe -
b8a9d5807917687ab25ef2c5759f7f1520fda63f734924b93c86e5524d0e7f68 - C:\Program Files\7-Zip\Uninstall.exe -
9c61dfa0f7df4f35fcad0f44f3270073e647af8e972e1aabba5c72f5dc86a60f - C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe -
73b4434a412eafabeb06b9c49b5eea36855c019dc0d79a4cd7e9677fbdea2dd6 - C:\Program Files\7-Zip\7zG.exe -
8056c9dbf012a00656df42cf470020afec396fe520140ab300509cffba6aa771 - C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe -
377693e2ca6eefba36f61373194f572541a409cb10808b8c71d52897a6df3e8f - C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe -
98f2f4fa5b18931f9ee370a8c559128c6e79b574bf2845c1c807397b190ef35a - bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 -
bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 - C:\Program Files\7-Zip\7z.exe -
f09666400f2eb1b96d7657efde2eada0d13541c7c9374961b1b67aeba4b44777 - C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe -
ab2767b15fc8fa614051f478b29a287bd2b21821869c60dfb534657e1abef9e8 - C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe -
06757f956a081b9f3a177acdbac7ba98103ff5811a51b909b2d0bb0a0f047b49 - C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe -
745038a91db193c8efcf4d9f78d7ba3a1646df235a0c68b6370a89b881610dba - C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe -
0675487810ba4b855d049eb59efd9b4f44a89b8b15e7303b91abd47b09247484
Embedded URLs
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-cs-g1.crl05
- http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
- http://www.gnu.org/software/coreutils/
- http://translationproject.org/team/
- http://gnu.org/licenses/gpl.html
- http://www.gnu.org/gethelp/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- cacerts.digicert.com
- crl4.digicert.com
- crl3.digicert.com
- www.digicert.com
- www.gnu.org
- translationproject.org
- gnu.org
- cygwin.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 52.168.112.67
- 4.230.171.124
- 4.247.188.233
- 57.154.63.210
- 135.232.92.97
- 20.247.185.124
- 135.232.92.137
- 74.178.76.128
- 20.184.175.16
- 13.69.116.107
- 52.148.114.188
- 72.145.35.111
- 92.223.78.30
- 52.110.12.22
- 52.110.12.10
Registry keys
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\MIME\audio/x-aiff]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\MIME\audio/aiff]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.aiff]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.aifc]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.aif]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\MIME\video/quicktime]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.qt]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.mov]
File paths
- C:\My
- C:\WINNT\system32\actmovie.exe
- C:\WINDOWS\system32\dllhost.exe
- C:\WINDOWS\pchealth\helpctr\binaries\notiflag.exe
- C:\Program
- c:\jenkins\workspace\8-2-build-windows-amd64-cygwin\jdk8u281\880\build\windows-amd64\jdk\objs\keytool_objs\keytool.pdb
- C:\Windows\SysWOW64\wuapp.exe
- c:\jenkins\workspace\8-2-build-windows-amd64-cygwin\jdk8u281\880\build\windows-amd64\jdk\objs\rmiregistry_objs\rmiregistry.pdb
- C:\cygwin64\bin\cp.exe
More Delf samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report