MALICIOUS — ab1d6a6435ae611635bbd980effc359e6edc12b1119ff13420610b8655528b7f
MALICIOUS — ab1d6a6435ae611635bbd980effc359e6edc12b1119ff13420610b8655528b7f is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (84/100), attributed to the Maldoc family. 2 of 54 detection engines flagged it.
Identification
- SHA-256:
ab1d6a6435ae611635bbd980effc359e6edc12b1119ff13420610b8655528b7f - SHA-1:
ccf5a39e982eb6f62dfda2f40c8fafb4a9011e11 - MD5:
5d208cc93c38ab92036fbc291ad276f1 - ssdeep:
192:lTsvYxpHcVqCqrwFqrdnd067dUPFHDDb//+upFRFRK15T58FW:l5pHcVgfdnd0zDvX+upFFK15T58FW - TLSH:
T118211A4750FE083E0648EDC25665EF478F5611727AD7974822E6C331628ED62EC722E3 - Submitted as: ab1d6a6435ae611635bbd980effc359e6edc12b1119ff13420610b8655528b7f
- File type: script · Size: 9135 bytes
- Verdict: malicious (84/100) · Family: Maldoc
Detections (2 of 54 engines)
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
- Kaspersky (KVRT): HEUR:Trojan-Downloader.Script.Generic
Why this verdict
The malicious score of 84/100 is the fusion of 3 weighted signals:
- YARA: delivr.to detections flagged DLV_Maldoc_VBA_AutoExec (rule
DLV_Maldoc_VBA_AutoExec) - engine signal, weight 0.70, confidence 0.70 - Kaspersky (KVRT) flagged HEUR:Trojan-Downloader.Script.Generic (rule
HEUR:Trojan-Downloader.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated vbscript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75
Dynamic analysis (windows)
1151 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- _dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.85
- 23.11.37.157
- 20.190.167.66
- 20.247.185.124 SG · Singapore · AS8075 Microsoft Corporation
- 52.123.252.236 AU · Sydney · AS8075 Microsoft Corporation
- 52.110.12.31 AU · Sydney · AS8075 Microsoft Corporation
- 52.110.12.33 US · AS8075 Microsoft Corporation
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 34.104.35.123
- 20.247.185.124
- 52.123.252.236
- 52.110.12.31
- 52.110.12.33
- 4.230.171.124
- 20.42.179.204
- 40.84.85.40
More Maldoc samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report