MALICIOUS — 938c821e27c81e2ab1325a6d2661527ba5ed606d790a2f623cdb49d213991b35
MALICIOUS — 938c821e27c81e2ab1325a6d2661527ba5ed606d790a2f623cdb49d213991b35 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Sivis family. 8 of 56 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
938c821e27c81e2ab1325a6d2661527ba5ed606d790a2f623cdb49d213991b35 - SHA-1:
2dc525384f3e2d1e549a98d8218ba2e21a568575 - MD5:
42bfd815f0f1cddf6d1548f97edfa7a3 - imphash:
38aa7c2ff6ef0e48a9520d6702d08df4 - ssdeep:
768:41uAkERoZtpcVK2Eq3GcOnTziEiVlpuCUtblllLJ:40nERoZtEEq3GcOviEiVlwlN - TLSH:
T122363DB93320A53FD5D148AB086CED7D84C316E95961808263C4F7B048B8C7BA62F796 - Submitted as: 938c821e27c81e2ab1325a6d2661527ba5ed606d790a2f623cdb49d213991b35
- File type: pe · Size: 65284 bytes
- Verdict: malicious (100/100) · Family: Sivis
Detections (8 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Agent-6943819-1
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:UPX
- Microsoft Defender: Virus:Win32/Sivis.A
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Trellix Stinger (McAfee): PolyPatch-UPX
- Kaspersky (KVRT): Virus.Win32.Agent.es
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 15 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Agent-6943819-1 (rule
Win.Trojan.Agent-6943819-1) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Virus:Win32/Sivis.A (rule
Virus:Win32/Sivis.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Sivis.A (rule
Win32.Sivis.A) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged PolyPatch-UPX (rule
PolyPatch-UPX) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.Agent.es (rule
Virus.Win32.Agent.es) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Contacted 16 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:UPX (rule
DIE:UPX) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://creativecommons.org/publicdomain/zero/1.0/ - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: UPX - static signal, weight 0.25, confidence 0.55
- Dropped 10 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
20577 behavior events · 0 ATT&CK techniques · 97 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- login.live.com
- update.googleapis.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- settings-win.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
Dropped files
- C:\Program Files\7-Zip\Lang\fa.txt -
4fffa8a0382e709ce84e7b972a9f0f4f991fd4bb21b8a9137553968e1bce15ea - C:\Program Files\7-Zip\7zG.exe -
5e0f3ab6666039cca36d444267d0e47bf498e3726e8e1270cb17ddc2e9c9aa26 - C:\Program Files\7-Zip\Lang\de.txt -
0bd7de38ff3e2991f2cebeb6fed466fa53cd6b8de78751a2af5386be4a83fdc9 - C:\Program Files\7-Zip\Lang\gu.txt -
74562b6c376d2400ce0d4236b1008771d4b1b706d7b176b8df37e860655a7dc4 - C:\Program Files\7-Zip\Lang\an.txt -
16288bd505292f9a82a1288aafda0762a5342f6dd6178c79a03d9a65f8e9b4e0 - C:\Program Files\7-Zip\7-zip32.dll -
dc21211aa94ff434f9cb465ebc65bdb08c93e20fab5f321cd0567892e810bca1 - C:\Program Files\7-Zip\Lang\pl.txt -
df7b721560acc81b3a3ae302c9c77613625f0f829fbc53c7eba4bf8879bb4480 - C:\Program Files\7-Zip\Lang\mng2.txt -
d1e90d86ac8e49c60de1ec594cfce8e825a4660d132dbfe79e5399a36b8f3108 - C:\Program Files\7-Zip\Lang\fr.txt -
a4bd2c3bdd32fbe96a53e32128db0216f3ea94cf650dcbd11ae2840b8e3d79e4 - C:\Program Files\7-Zip\Lang\nn.txt -
fa66cecda567590575054d20a96f5029d3af8232a36b35989f7a3c12fb4f0484 - C:\Program Files\7-Zip\7z.sfx -
625b156fbc54db03ffbb9abffe375d43e911ce23d3da622a8a106aed40806237 - C:\Program Files\7-Zip\Lang\lv.txt -
04e50f18af216894ae5fc1f8adf182839c0533a9575b8cef3dbce88622c55a55 - C:\Program Files\7-Zip\Lang\ga.txt -
20b9ed5e55de8ccb2067825eda52c08fc33d83e00245652146b6efb7a3356092 - C:\Program Files\7-Zip\Lang\ja.txt -
f7056b5f3b7d2821a9dfe4524dfa40d4683059dce3575be515cf2fc4496bf760 - C:\Program Files\7-Zip\Lang\ba.txt -
c5481fafdf990bf8ae6ef62ed45b95b2475868e5cd68424f5a7ebf0186efa475
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- http://ardownload.adobe.com/pub/adobe/reader/win/8.x/8.0/misc/WindowsInstaller-KB893803-v2-x86.exe
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- creativecommons.org
- geocities.com
- ardownload.adobe.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 52.168.117.175
- 172.215.188.225
- 4.144.132.114
- 4.230.171.124
- 172.215.188.232
- 74.179.77.204
- 74.179.77.164
- 74.178.76.128
- 51.116.253.168
- 162.159.142.9
- 135.234.160.244
- 57.155.104.224
- 52.110.12.49
- 52.110.12.47
File paths
- X:\windows\system32\sysreset.exe
- C:\Windows.old\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim]
- C:\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim]
- C:\Windows.old\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.1120_none_c3e
- C:\Windows.old\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.1_none_eedfed
- X:\SysResetTrace-Tel-Merge.etl,
- C:\$WINDOWS.~BT\Sources\Panther\SysResetTrace-Tel-Merge.etl)
More Sivis samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report