MALICIOUS — bfa3dcfc4ec50deea1e1ac3d03a0c30300e08e858936f5a9ddb409c436099243
MALICIOUS — bfa3dcfc4ec50deea1e1ac3d03a0c30300e08e858936f5a9ddb409c436099243 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Delf family. 6 of 55 detection engines flagged it, exhibiting 6 ATT&CK techniques.
Identification
- SHA-256:
bfa3dcfc4ec50deea1e1ac3d03a0c30300e08e858936f5a9ddb409c436099243 - SHA-1:
327fac812fb4775f9e4935f301d57f03114bb436 - MD5:
9a959f356aa01ec62d98b7bbee98d356 - imphash:
31d1c48ee7d8e07a5706e963146db875 - ssdeep:
1536:p4q8Q1xZtffrb8sjPFNhTYsFFrzckH2fmitmm1hGQadCL:qKtfDwsjPThTYszDH2fJGhA - TLSH:
T15F378D25576B2F87EF76D7220440B70D4462F979207A64882363D16F77FAC23AA7424C - Submitted as: bfa3dcfc4ec50deea1e1ac3d03a0c30300e08e858936f5a9ddb409c436099243
- File type: pe · Size: 74640 bytes
- Verdict: malicious (100/100) · Family: Delf
Detections (6 of 55 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- ClamAV (daily): Win.Trojan.Delf-1564
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Virus:Win32/Viking.MS
- Emsisoft (Emergency Kit): Trojan.Agent.FPMF
- Kaspersky (KVRT): Virus.Win32.Lamer.xe
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Delf-1564 (rule
Win.Trojan.Delf-1564) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - Dropped a malicious payload: MicrosoftEdge_X64_150.0.4078.105_150.0.4078.65.exe - dynamic signal, weight 0.62, confidence 0.90
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 26 external host(s) and 19 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- 1 behavioral detection(s) across 1 rule(s): Discovery: enumerates installed security software [low] (rule
tl-security-software-discovery) - dynamic signal, weight 0.20, confidence 0.90 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
55471 behavior events · 2 ATT&CK techniques · 82 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Dropped files
- C:\Program Files\LibreOffice\program\senddoc.exe -
281e6cd46fa70cd8bf9acfc779579974a190196f929a1c9e2110227d1d6acf6f - C:\Program Files\LibreOffice\program\python-core-3.12.13\bin\python.exe -
b2f2e1f7fed63f13783c48bd02e7a8b7305ba5ab074c4e26392dfd36bde15080 - C:\Program Files (x86)\Microsoft\EdgeUpdate\Download\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\150.0.4078.105\MicrosoftEdge_X64_150.0.4078.105_150.0.4078.65.exe -
0e30c51ac086b6b5dae2ae7039af88c090316805aa0927ab4e2f007895f3841f - bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 -
bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 - C:\Program Files\LibreOffice\program\gpgme-w32spawn.exe -
c2069e43bede5d6112cc29e32e414f7a527a4b5821e553ae194d0a6f46e6e6d6 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\kinit.exe -
02ffcacd19364de794367690c981f10e448c18d02adbd6cc4261462430a4f8a0 - C:\Windows\virDll.dll -
c2af39cd735fff0c32600813866ae952325cd64757a8855552c7fa4583da80bc - C:\Program Files\LibreOffice\program\update_service.exe -
e820e192b12d0bfffaf27b354b86c201fdba92519d1edff028409c6734f2ad56 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\java.exe -
539a944c2afc381a9e6b819e93757acd7f58b0603f8f178ad08dd9c531386da8 - C:\Program Files\LibreOffice\program\python-core-3.12.13\lib\setuptools\gui-64.exe -
6ae5139680aa5df36d1fd69cc3641a17eb2dd4f85e15eb49d695ef18a35bd82f - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\keytool.exe -
580abe19eebc6c19c7772107c22fc6c80dfc59056eff99d7f2e9c1d3d37aedd6 - C:\Program Files\LibreOffice\program\sbase.exe -
ad20459e6a4a647dc66b58cc575388009e6c66ca0e7ae9b1dcce4ec3a9671969 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jfr.exe -
411d9233af891aff0bcadf5d4b8ce0a12114dc72ffcab46b2b93d425968aaacd - C:\Program Files\LibreOffice\program\python-core-3.12.13\lib\setuptools\cli.exe -
9ddee23b15f758c17c6b8f4d8ef451b5fa5a724aa8a44ee105ff8ac786f4e1fe - C:\Program Files (x86)\Microsoft\Edge\Application\150.0.4078.105\msedge_proxy.exe -
9b5169f421547b5162e5dab1f84c0d4419ec5335bb09ac00d79fad6fb34bd887
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://crl.verisign.com/tss-ca.crl0
- https://www.verisign.com/rpa
- https://www.verisign.com/cps0*
- https://www.verisign.com/rpa0
- http://logo.verisign.com/vslogo.gif0
- http://crl.verisign.com/pca3.crl0
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9?P1=1787950267&P2=404&P3=2&P4=bmtzjnsA6WxHqWX0zruc3DW7rVFEGPqDi9Jy0qKmFnyj4CIHJaGsPQ8beU5K0F%2bULYS0BE1keiB9MVWWyHT5AQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Embedded domains
- schemas.microsoft.com
- crl.verisign.com
- www.verisign.com
- logo.verisign.com
- csc3-2009-2-crl.verisign.com
- csc3-2009-2-aia.verisign.com
Embedded IP addresses
- 192.168.0.30
- 192.168.8.1
- 20.89.1.12
- 52.123.252.230
- 4.230.171.124
- 20.42.179.204
- 4.144.132.114
- 74.178.240.61
- 20.184.175.6
- 74.178.240.51
- 20.112.250.133
- 52.123.128.14
- 40.99.133.242
- 52.123.129.14
- 20.165.94.63
- 135.234.160.246
- 203.26.79.13
- 172.66.2.5
- 20.184.175.13
- 20.184.175.2
- 52.148.114.188
- 74.178.232.29
- 184.84.165.136
- 72.153.5.96
- 135.232.92.34
File paths
- C:\jdk7_32P\jdk7\build\windows-i586\tmp\sun\launcher\servertool\obj\servertool.pdb
More Delf samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report