MALICIOUS — a3ba90a583b8a9485dc7761be8959443052d865153de9fd73bafd3c66db505d9
MALICIOUS — a3ba90a583b8a9485dc7761be8959443052d865153de9fd73bafd3c66db505d9 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Delf family. 9 of 56 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
a3ba90a583b8a9485dc7761be8959443052d865153de9fd73bafd3c66db505d9 - SHA-1:
a9d2a3e9ea78eb7c27760c9335ab18349d4010a2 - MD5:
b46fadad9b3a38ff28aaa3ecc46bff12 - imphash:
9973fdd4b86d866b3faa39fa66cf7e0a - ssdeep:
98304:i2gO9brx/NTwqXd2VuitTfN93iXKFAGBrNhS9Yw8y4:iObrx/NsqXd2VBlfDDAGvwf4 - TLSH:
T17F6A4C9A422F3222E2B7DC146C34A9DCC437B59C9175DA8D4703CD6E80D7A37A9F10A9 - Submitted as: a3ba90a583b8a9485dc7761be8959443052d865153de9fd73bafd3c66db505d9
- File type: pe · Size: 9572831 bytes
- Verdict: malicious (100/100) · Family: Delf
Detections (9 of 56 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Worm.Delf-6980489-0
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Worm:Win32/Xolxo.A
- Emsisoft (Emergency Kit): Gen:Variant.Ransom.Amnesia.1
- Kaspersky (KVRT): P2P-Worm.Win32.Delf.aj
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 100/100 is the fusion of 14 weighted signals:
- ClamAV (daily) flagged Win.Worm.Delf-6980489-0 (rule
Win.Worm.Delf-6980489-0) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - Microsoft Defender flagged Worm:Win32/Xolxo.A (rule
Worm:Win32/Xolxo.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Ransom.Amnesia.1 (rule
Gen:Variant.Ransom.Amnesia.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged P2P-Worm.Win32.Delf.aj (rule
P2P-Worm.Win32.Delf.aj) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.55, confidence 0.70 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser built-in flagged Windows_Injection_Api_Combo (rule
Windows_Injection_Api_Combo) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:collection/keylog (rule
capability:collection/keylog) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.gnu.org/software/coreutils/, http://translationproject.org/team/, http://gnu.org/licenses/gpl.html - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://www.gnu.org/software/coreutils/
- http://translationproject.org/team/
- http://gnu.org/licenses/gpl.html
- http://www.gnu.org/gethelp/
- http://schemas.microsoft.com/sharepoint/soap/
- http://schemas.microsoft.com/sharepoint/soap/GetVersions
- http://schemas.microsoft.com/sharepoint/soap/RestoreVersion
- http://schemas.microsoft.com/sharepoint/soap/DeleteVersion
- http://schemas.microsoft.com/sharepoint/soap/DeleteAllVersions
- http://schemas.microsoft.com/server/powerpoint/2009/main
- http://schemas.microsoft.com/server/powerpoint/2009/main/BroadcastGetHostInfo
- http://schemas.microsoft.com/server/powerpoint/2009/main/BroadcastGetNewUploadFile
- http://schemas.microsoft.com/server/powerpoint/2009/main/BroadcastGetHostToken
- http://schemas.microsoft.com/server/powerpoint/2009/main/BroadcastGetAttendeeUrl
- http://schemas.microsoft.com/server/powerpoint/2009/main/BroadcastDeleteUploadFile
- http://schemas.microsoft.com/server/powerpoint/2009/main/BroadcastGetServerInfo
- http://schemas.microsoft.com/server/powerpoint/2009/main/BroadcastStartSession
- http://schemas.microsoft.com/server/powerpoint/2009/main/BroadcastEndSession
- http://schemas.microsoft.com/server/powerpoint/2009/main/BroadcastPutData
- http://schemas.microsoft.com/server/broadcast/2010/main
- http://schemas.microsoft.com/server/broadcast/2010/main/BroadcastGetNewUploadFile
- http://schemas.microsoft.com/server/broadcast/2010/main/BroadcastCopyFile
- http://schemas.microsoft.com/server/broadcast/2010/main/BroadcastGetHostToken
- http://schemas.microsoft.com/server/broadcast/2010/main/BroadcastGetAttendeeUrl
Embedded domains
- schemas.microsoft.com
- www.gnu.org
- translationproject.org
- gnu.org
- cygwin.com
- www.w3.org
- openssl.org
- uninstall.cc
- field.cc
- streams.cc
- clients2.google.com
- crashpad.chromium.org
- install.cc
- settings.cc
- wmi.cc
- shortcut.cc
- blink.net
- pb.cc
- crash.pb.cc
- thread.cc
- common.cc
- arena.cc
- support.google.com
- cacerts.digicert.com
- crl3.digicert.com
Registry keys
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\MIME\audio/x-aiff]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\MIME\audio/aiff]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.aiff]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.aifc]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.aif]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\MIME\video/quicktime]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.qt]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.mov]
File paths
- C:\My
- C:\WINNT\system32\actmovie.exe
- C:\WINDOWS\system32\dllhost.exe
- C:\WINDOWS\pchealth\helpctr\binaries\notiflag.exe
- C:\Windows\Microsoft.NET\Framework64\v3.5\DataSvcUtil.exe
- C:\Windows\SysWOW64\iscsicli.exe
- C:\cygwin64\bin\tee.exe
- C:\Program
- P:\Target\x64\ship\csi\x-none\cmigrate.pdb
- C:\cygwin64\bin\grops.exe
More Delf samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report