MALICIOUS — c8c756563dc905e00b0b7714459cb05d3ed8233bab1c31a308e656290ac705fd
MALICIOUS — c8c756563dc905e00b0b7714459cb05d3ed8233bab1c31a308e656290ac705fd is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Sivis family. 4 of 56 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c8c756563dc905e00b0b7714459cb05d3ed8233bab1c31a308e656290ac705fd - SHA-1:
863898daa7eba499cbea8f506616a1581778e882 - MD5:
8854915cb4801bfdec06f5c451ee51fb - imphash:
38aa7c2ff6ef0e48a9520d6702d08df4 - ssdeep:
3072:3nEOvifikieiKXd2HUinFhNGpW/YcQnm6oh+4b:5vifikieiisUinFhNGpWQcQnZ0b - TLSH:
T1043B1BDC539D171FC5ABC87B186CCAAD8072B1D12072A6A90FC2DB360465933FD7216A - Submitted as: c8c756563dc905e00b0b7714459cb05d3ed8233bab1c31a308e656290ac705fd
- File type: pe · Size: 105554 bytes
- Verdict: malicious (99/100) · Family: Sivis
Detections (4 of 56 engines)
- ClamAV (daily): Win.Trojan.Agent-6943819-1
- Microsoft Defender: Virus:Win32/Sivis.A
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Kaspersky (KVRT): Virus.Win32.Agent.es
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Agent-6943819-1 (rule
Win.Trojan.Agent-6943819-1) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Virus:Win32/Sivis.A (rule
Virus:Win32/Sivis.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Sivis.A (rule
Win32.Sivis.A) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.Agent.es (rule
Virus.Win32.Agent.es) - engine signal, weight 0.55, confidence 0.85 - Contacted 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- Embedded network infrastructure: http://creativecommons.org/publicdomain/zero/1.0/ - static signal, weight 0.35, confidence 0.60
- Dropped 10 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
17136 behavior events · 0 ATT&CK techniques · 97 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- desktop-hsgcbep
- login.live.com
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- odc.officeapps.live.com
- www.msn.com
- settings-win.data.microsoft.com
- assets.msn.com
- licensing.mp.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- v10.events.data.microsoft.com
- slscr.update.microsoft.com
Dropped files
- C:\Program Files\7-Zip\Lang\mng2.txt -
1d5b883ac8ba90aae021bddff9a596554d1983c205a4743b0b91f7ef97cc1985 - C:\Program Files\7-Zip\7z.dll -
f9322e47bea85ff177bf859fa17789851655889071aa4cc0d41861aef662da44 - C:\$WinREAgent\RollbackInfo.ini -
e2b2e6c88102015edb38dc9b331c00194ab1ed442e6341622edf6a5cab81c28e - C:\Program Files\7-Zip\Lang\br.txt -
49b8bf03a0795fe1cb32d6046484016d8584da4f2f853c9626d53ad5b1b73b42 - C:\Program Files\7-Zip\Lang\mk.txt -
95af6fd4d88ad8c549d94be7c1ebbabdb154fe9a0894a8fae4f8242d803af899 - C:\Program Files\7-Zip\Lang\cy.txt -
b909878c40b2647c6a7011e316ee488235ae07b6875400c21bb3368d55a1573f - C:\Program Files\7-Zip\Lang\fy.txt -
ac6a0d4a135de437e920a23c97971170d97517878d1cd1d692e12661b8922aa8 - C:\796.ini -
87d61d6e47784aa972ed6804f73cb3d90a85f45b7722dffb9f1271bc60d22bc0 - C:\$WinREAgent\Backup\SrSettings.ini -
62532f6cf154182978e3a79bc9fdaa9fa98a509ea87a3f919c008120f9fdb435 - C:\Program Files\7-Zip\History.txt -
eecf5ac8e7daf655d13685f6e011572714b4b3f563c953fc9f22cddba135ea50 - C:\Program Files\7-Zip\Lang\an.txt -
a9f7be40824a0ea81338955816419e6cf85d1968015c0e7920ec34a63f6b5023 - C:\office-config.ps1 -
92d907bcccc7cacfab73c73043f51907588af8108a8613156fd1149378243e16 - C:\$WinREAgent\Backup\ReAgent.xml -
a998dcbfa3ba489fa9f674766b7d6bce3fe1e1deac6d7c3e5c93423d028b33df - C:\Program Files\7-Zip\7z.exe -
6dcf0cdb465f54e555d3979586d5c6851ff584c8326014b129f74d287950ba39 - C:\Program Files\7-Zip\Lang\mn.txt -
037969a22e64babdace3250896e7f8a3175dddaa47febec49bd3790bd7c5d129
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- creativecommons.org
- geocities.com
- www.microsoft.com
Embedded IP addresses
- 52.182.143.212
- 52.123.252.192
- 4.230.171.124
- 52.230.60.54
- 85.210.196.11
- 74.178.240.51
- 74.179.77.204
- 20.42.65.89
- 20.184.175.20
- 104.18.33.89
- 135.233.45.221
- 52.110.12.40
- 52.110.12.28
More Sivis samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report