MALICIOUS — da193049cd2aa56bd238af23b6e33ba6dece3b643cdf4505a56a0532aaad6268
MALICIOUS — da193049cd2aa56bd238af23b6e33ba6dece3b643cdf4505a56a0532aaad6268 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Sivis family. 8 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
da193049cd2aa56bd238af23b6e33ba6dece3b643cdf4505a56a0532aaad6268 - SHA-1:
f7343598400d45c2596ec2b11a004c89fe1b7e5d - MD5:
ec02003d6184bb1357bdcfd922c73a6a - imphash:
b10d16eedb1085ef7262dfc4ab03be6f - ssdeep:
98304:xW1XrwVegTk5yhLMj/0BEZ1NFt2889bxoJW/K:xQrY1TK+Mb/2tbuWy - TLSH:
T13F68BF865927B16BE6F78CD0E82455EC9412B4ECA4741BCDB303CDAA408AE37F1E1176 - Submitted as: da193049cd2aa56bd238af23b6e33ba6dece3b643cdf4505a56a0532aaad6268
- File type: pe · Size: 7530056 bytes
- Verdict: malicious (100/100) · Family: Sivis
Detections (8 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Dropper.Ausiv-9875523-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Detect It Easy (packer/type): DIE:UPX
- Microsoft Defender: Virus:Win32/Sivis.A
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Kaspersky (KVRT): Virus.Win32.Agent.es
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 16 weighted signals:
- ClamAV (daily) flagged Win.Dropper.Ausiv-9875523-0 (rule
Win.Dropper.Ausiv-9875523-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Virus:Win32/Sivis.A (rule
Virus:Win32/Sivis.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Sivis.A (rule
Win32.Sivis.A) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.Agent.es (rule
Virus.Win32.Agent.es) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Contacted 2 external host(s) and 16 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:UPX (rule
DIE:UPX) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.gnu.org/licenses/, http://www.gnu.org/software/coreutils/, http://translationproject.org/team/ - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 - static signal, weight 0.25, confidence 0.55
- Dropped 10 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
12618 behavior events · 0 ATT&CK techniques · 98 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- officeclient.microsoft.com
- www.msn.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- www.bing.com
Dropped files
- C:\Program Files\7-Zip\Lang\bg.txt -
03dedcb7254f28008633031936f3eb6f0ad3e8c45acdd1c7e9b8d7041e5241ce - C:\Program Files\7-Zip\Lang\hi.txt -
3ed6c18a217787e944d393ee97ae18d1cb17619c4af9b34de0fe9d60d8e51ea9 - C:\Program Files\7-Zip\7-zip.chm -
6c758efeb78653167bfacb5883228eaa696c16fb5da171162751bf429787160e - C:\Program Files\7-Zip\Lang\ja.txt -
d4bfe321b7cad900a35f8bb2b2e0213350b3aa1865151b42e319e1f35bd1cf7e - C:\office-config.ps1 -
3736c7cf9fb115095c1bb6c5f0402ed89970b99304f9ba523fcc072b7c4f5612 - C:\Program Files\7-Zip\Lang\el.txt -
f7b58fa6f3e411246e8e3509f9cbccefc6dad1448f0bbb112d276cc8695ec6e5 - C:\Program Files\7-Zip\Lang\gl.txt -
adac6e7dea15364d089bc784c40745a688705d5c3176ba8f51858b62786a1379 - C:\Program Files\7-Zip\Lang\da.txt -
86c4f4355c93e1fb1458266c045c7d1c55390d1e78191e19b9b9e77cde323b73 - C:\Program Files\7-Zip\Lang\gu.txt -
91e8320cd302a85fa3c0efe658a72b38612ea3b6313eb514d41a41b15f45eb13 - C:\Program Files\7-Zip\Lang\et.txt -
1d0e2e2255f62ba1b0f76fdbe89ba24a8a391e717f54a5f19f6200f578720dec - C:\Program Files\7-Zip\Lang\cs.txt -
dfa28036fecf99308d607919c732718490158dd93f8d9ac71d75094a609e82b6 - C:\Program Files\7-Zip\Lang\ar.txt -
078fbeff941369ca8677b761be03e47b3011c798c2c7047fa8c6b6409ef86c37 - C:\Program Files\7-Zip\Lang\eo.txt -
d75661f9d750a6bf610af8df36c3d558afe0d0cad5a3031db978ed64e04f8a73 - C:\Program Files\7-Zip\Lang\pl.txt -
49ea0edcaccb74e9b6c24ff69e0968d97b20584780eeff342d690177c91634a6 - C:\Program Files\7-Zip\Lang\fa.txt -
cdb797c3c46e9da8486179161a8c9a95a2f4c134421d6e93df78cf9e0df321ac
Embedded URLs
- http://schemas.microsoft.com/appx/2010/manifest
- http://schemas.microsoft.com/appv/2010/manifest
- http://schemas.microsoft.com/appv/2013/manifest
- http://schemas.microsoft.com/appv/2014/manifest
- http://www.gnu.org/licenses/
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://www.microsoft.com/windows0
- http://www.microsoft.com/pki/certs/MicCodSigPCA_2010-07-06.crt0
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
- http://www.gnu.org/software/coreutils/
- http://translationproject.org/team/
- http://gnu.org/licenses/gpl.html
- http://www.gnu.org/gethelp/
- http://crl.verisign.com/tss-ca.crl0
- http://logo.verisign.com/vslogo.gif0
- https://www.verisign.com/rpa
- http://csc3-2010-crl.verisign.com/CSC3-2010.crl0D
- https://www.verisign.com/rpa0
- http://csc3-2010-aia.verisign.com/CSC3-2010.cer0
- https://www.verisign.com/cps0*
- http://logo.verisign.com/vslogo.gif04
- http://crl.verisign.com/pca3-g5.crl04
Embedded domains
- schemas.microsoft.com
- cwru.edu
- gnu.org
- www.gnu.org
- crl.microsoft.com
- www.microsoft.com
- translationproject.org
- cygwin.com
- www.adobe.com
- crl.verisign.com
- logo.verisign.com
- www.verisign.com
- csc3-2010-crl.verisign.com
- csc3-2010-aia.verisign.com
- helpx.adobe.com
- www.microsoft.nl
- installeren.de
- opstarten.de
- voltooid.de
- selecteren.de
- domein.de
- overeen.de
- al.de
- groep.de
- crl3.digicert.com
Embedded IP addresses
- 2.1.4.0
- 20.184.175.22
- 4.230.171.124
- 85.210.196.11
- 20.247.185.124
- 48.211.4.16
- 74.178.240.51
- 4.150.223.106
- 135.233.95.144
- 52.168.117.171
- 20.184.175.8
- 4.207.44.67
- 52.110.12.25
- 52.110.12.47
- 135.233.45.223
- 20.42.179.192
- 52.148.114.188
- 52.110.12.18
- 52.110.12.50
File paths
- X:\windows\system32\sysreset.exe
- C:\Windows.old\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim]
- C:\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim]
- C:\Windows.old\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.1120_none_c3e
- C:\Windows.old\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.1_none_eedfed
- X:\SysResetTrace-Tel-Merge.etl,
- C:\$WINDOWS.~BT\Sources\Panther\SysResetTrace-Tel-Merge.etl)
- C:\btvsts\3621\private\softgrid\shared\include\shared\file_utils.hpp
- C:\btvsts\3621\private\softgrid\subsystems\include\subsystem_virtualization_error_utils.h
- C:\btvsts\3621\private\softgrid\shared\procmon\loggerlib\devicedriver.hpp
- c:\btvsts\3621\private\softgrid\subsystems\vcom\process_runtime\ComExceptions.h
- A:\.
More Sivis samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report