MALICIOUS — 8da6602d7fe2fd6157836134c813e3bed8e2c332cdeaa34a65bd44999112c6b9
MALICIOUS — 8da6602d7fe2fd6157836134c813e3bed8e2c332cdeaa34a65bd44999112c6b9 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Delf family. 6 of 55 detection engines flagged it.
Identification
- SHA-256:
8da6602d7fe2fd6157836134c813e3bed8e2c332cdeaa34a65bd44999112c6b9 - SHA-1:
589f2cf463713bed9a09043a55a342bbe5c081f4 - MD5:
80be26dac6c5a2fba4ec0a96efc96725 - imphash:
9973fdd4b86d866b3faa39fa66cf7e0a - ssdeep:
3072:8jWZnKITkBXkHBDHsl3piopbuV0wipN2HGoKUUyj7:8jMKITkBXkHhIizipwHUtyj7 - TLSH:
T1313C9E4C1714B702E6B9D6A01C91DD6C40B3BC72397908DC22B3C96FA77197329692BE - Submitted as: 8da6602d7fe2fd6157836134c813e3bed8e2c332cdeaa34a65bd44999112c6b9
- File type: pe · Size: 114688 bytes
- Verdict: malicious (92/100) · Family: Delf
Detections (6 of 55 engines)
- ClamAV (daily): Win.Worm.Delf-6980489-0
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Worm:Win32/Xolxo.A
- Emsisoft (Emergency Kit): Gen:Trojan.Malware.hGZ@aGYDvaf
- Kaspersky (KVRT): P2P-Worm.Win32.Delf.aj
Why this verdict
The malicious score of 92/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Worm.Delf-6980489-0 (rule
Win.Worm.Delf-6980489-0) - engine signal, weight 0.90, confidence 0.95 - YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://www.digicert.com/CPS0
- http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
- http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
- http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
- http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
- http://www.digicert.com/ssl-cps-repository.htm0
- http://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
Embedded domains
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- cacerts.digicert.com
Registry keys
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\MIME\audio/x-aiff]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\MIME\audio/aiff]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.aiff]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.aifc]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.aif]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\MIME\video/quicktime]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.qt]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.mov]
File paths
- C:\My
- C:\WINNT\system32\actmovie.exe
- C:\WINDOWS\system32\dllhost.exe
- C:\WINDOWS\pchealth\helpctr\binaries\notiflag.exe
- C:\Program
- D:\B\T\BuildResults\bin\Release\AcroRd32Info.pdb
More Delf samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report