MALICIOUS — Confirmacion_de_Pago_Pendiente.pdf.hta
MALICIOUS — Confirmacion_de_Pago_Pendiente.pdf.hta is a hta sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Acsogenixx family. 4 of 51 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
ca3d18e1d65eb9b3eea2a1d56990f726a7cb12f2a8cd52e07d4d320b918a58bd - SHA-1:
307606ccf069808a5e2421abe7bb77779dad6713 - MD5:
1875270e480a3c98cae1f5dc4de57635 - ssdeep:
768:IOyq0Cdv/zZqoAxhBk1hGD5xTFXWLMThClFfhArInCeRPwzMQUB3/sXHDo6Wg835:NuCdIqw6mqOzOcOCobyQxY3r6yW - TLSH:
T119341E25A35D3CBF8518938A988425AF96FED3C46051FDD50AD97BD20023C8AFE27634 - Submitted as: Confirmacion_de_Pago_Pendiente.pdf.hta
- File type: hta · Size: 54851 bytes
- Verdict: malicious (99/100) · Family: Acsogenixx
Detections (4 of 51 engines)
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
- Microsoft Defender: Trojan:Win32/Qwexlafiba!rfn
- Emsisoft (Emergency Kit): GT:JS.Acsogenixx.2736.392C77BE
- Kaspersky (KVRT): HEUR:Trojan-Downloader.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 11 weighted signals:
- 2 behavioral detection(s): LOLBin: mshta executing remote/scripted payload [high] (rule
tl-lolbin-mshta) - dynamic signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged Trojan:Win32/Qwexlafiba!rfn (rule
Trojan:Win32/Qwexlafiba!rfn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged GT:JS.Acsogenixx.2736.392C77BE (rule
GT:JS.Acsogenixx.2736.392C77BE) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan-Downloader.Script.Generic (rule
HEUR:Trojan-Downloader.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated powershell script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Document contains macros/active content: hta-application, wscript-shell, powershell, activex - static signal, weight 0.35, confidence 0.75
- YARA: delivr.to detections flagged DLV_Maldoc_VBA_AutoExec (rule
DLV_Maldoc_VBA_AutoExec) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://firebasestorage.googleapis.com/v0/b/newjuly-cf41e/o/22WEDNESDAYLincoln.ps1?alt=media&token=49713b83-90b2-4f7f-b8ed-b1c9c8506e4d - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (windows)
8320 behavior events · 2 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- searchapp.bundleassets.example
- inference.location.live.net
- desktop-hsgcbep
- ctldl.windowsupdate.com
- config.edge.skype.com
- login.live.com
- v20.events.data.microsoft.com
- www.bing.com
- windows.msn.com
- officeclient.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- msedge.api.cdp.microsoft.com
- dns.msftncsi.com
- firebasestorage.googleapis.com
- edge.microsoft.com
- aefd.nelreports.net
- assets.msn.com
- settings-win.data.microsoft.com
- www.msftncsi.com
Dropped files
- 7f191e589555827bea48a806a55cbb6b45887714993239fd915c56200790e6d4 -
7f191e589555827bea48a806a55cbb6b45887714993239fd915c56200790e6d4 - 4104da4cbf6a686c3f2ab6a5af879b8ea648d7b8a10f70049a319333daee89e8 -
4104da4cbf6a686c3f2ab6a5af879b8ea648d7b8a10f70049a319333daee89e8
Embedded URLs
- https://firebasestorage.googleapis.com/v0/b/newjuly-cf41e/o/22WEDNESDAYLincoln.ps1?alt=media&token=49713b83-90b2-4f7f-b8ed-b1c9c8506e4d
Embedded domains
- firebasestorage.googleapis.com
- aefd.nelreports.net
Embedded IP addresses
- 162.159.36.2
More Acsogenixx samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report