MALICIOUS — bb381861dd153222014a0393d86a1752a319853a495d2fb59a3900f2782a73f2
MALICIOUS — bb381861dd153222014a0393d86a1752a319853a495d2fb59a3900f2782a73f2 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Gavir family. 9 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
bb381861dd153222014a0393d86a1752a319853a495d2fb59a3900f2782a73f2 - SHA-1:
02c72e4e487ccf6741043fc8ea7d9b223cf5d056 - MD5:
05d12997246f5b5a2635a946a300f7a1 - imphash:
4847bea2fab2ae7b3c2596a2782272f9 - ssdeep:
1536:AjMqxL2Q3qOLj5MtVlyEeROpqYYQe4XQxy//fgLdQAQfcfymN/FXyladCD:mAyL9W0ExYKXeM/ftffjmNpywU - TLSH:
T1CD439D3D6F2A6B4FED25C36618807A5C4862F4FA30764489536384AD77FEC239A5032D - Submitted as: bb381861dd153222014a0393d86a1752a319853a495d2fb59a3900f2782a73f2
- File type: pe · Size: 231816 bytes
- Verdict: malicious (98/100) · Family: Gavir
Detections (9 of 52 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- MalwareAnalyser heuristics (entropy/packer): Borland Delphi
- ClamAV (daily): Win.Worm.Gavir-1
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- Detect It Easy (packer/type): DIE:Borland Delphi
- Microsoft Defender: Virus:Win32/Viking.H
- Emsisoft (Emergency Kit): Win32.Worm.Viking.NDL
- Kaspersky (KVRT): Worm.Win32.Viking.j
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Worm.Gavir-1 (rule
Win.Worm.Gavir-1) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Borland Delphi (rule
DIE:Borland Delphi) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Borland Delphi - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://crl.verisign.com/tss-ca.crl0
- https://www.verisign.com/rpa
- https://www.verisign.com/cps0*
- https://www.verisign.com/rpa0
- http://logo.verisign.com/vslogo.gif0
- http://crl.verisign.com/pca3.crl0
Embedded domains
- schemas.microsoft.com
- crl.verisign.com
- www.verisign.com
- logo.verisign.com
- csc3-2009-2-crl.verisign.com
- csc3-2009-2-aia.verisign.com
File paths
- C:\jdk7_32P\jdk7\build\windows-i586\tmp\sun\launcher\javadoc\obj\javadoc.pdb
More Gavir samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report