CLEAN — e2364865eb53943382341b5a7328c7a84f6753e5b4ed43b9562b9ec59e64ef23.jar
CLEAN — e2364865eb53943382341b5a7328c7a84f6753e5b4ed43b9562b9ec59e64ef23.jar is a jar sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (14/100). 4 of 53 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
e2364865eb53943382341b5a7328c7a84f6753e5b4ed43b9562b9ec59e64ef23 - SHA-1:
11204ba69a9c96c0e27fa375c723225d51170a97 - MD5:
bc51cdbe6cb657a633696621b9a20053 - ssdeep:
98304:LTX66PQGWc8IQYrc16j5E0iG8oEiUygtka0iyLmH800Dx+KyksqYaQ:Lb6SQ/+QR16j5E0bhDKU680S8KMF - TLSH:
T1616533AF6713484FE3D41B94469A784C9146D8D7363409C76222AE24A3B43FF83BE674 - Submitted as: e2364865eb53943382341b5a7328c7a84f6753e5b4ed43b9562b9ec59e64ef23.jar
- File type: jar · Size: 5662557 bytes
- Verdict: clean (14/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:Win32/Ravartar!rfn
- Emsisoft (Emergency Kit): Trojan.GenericKD.81008405
- Kaspersky (KVRT): HEUR:Trojan.Java.Agent.gen
MITRE ATT&CK
Why this verdict
The clean score of 14/100 is the fusion of 1 weighted signal:
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Archive contents (1 executable)
This jar carries 1 extracted member, each analyzed as its own sample:
- sample -
c6ed5159a2977e28a201c906b475cedaff3532d2afe0dbee5d896733861f8508
Dynamic analysis (windows)
75954 behavior events · 2 ATT&CK techniques · 237 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- cloudflare-dns.com
- polygon-rpc.com
- rpc-mainnet.matic.quiknode.pro
- polygon-public.nodies.app
- 1rpc.io
- polygon-mainnet.rpcfast.com
- polygon-bor-rpc.publicnode.com
- go.getblock.io
- api.zan.top
- polygon.rpc.subquery.network
Dropped files
- C:\Users\analyst\AppData\Local\Microsoft\Windows\IManagementEngine\Lib\site-packages\pip\_internal\build_env\__init__.py -
008e71d8a7efd5ec46d486ec347b885756a0a8d82cb538ff2d6a5bc162eaf289 - C:\Users\analyst\AppData\Local\Microsoft\Windows\IManagementEngine\Lib\site-packages\pip\_internal\cache.py -
7aa31055fa43f31ec67023b4574cfbde69e33c8b926a9305a10fd6444ee22d8f - c:\users\analyst\appdata\local\pip\cache\http-v2\a\1\9\5\3\a19537d3cf37c122db841d6fe4cd322bc10d1a558bb00d146b85cb9a -
31eefd8b61ad08dfb871fc5b6d223cc349126f2bf687c448503640839f0b0715 - C:\Users\analyst\AppData\Local\Microsoft\Windows\NtProfileIndex\Lib\site-packages\PIL\DcxImagePlugin.py -
2f6d5cde0557e883e6938cee7ff96db779807917dcb8209c5e1902569b9e7765 - c:\users\analyst\appdata\local\microsoft\windows\ntprofileindex\lib\site-packages\charset_normalizer\__pycache__\legacy.cpython-312.pyc -
431cfc7b1cdc761b2af392d45c725188c65fb10a79792e9a73cedd1e8d0faaa3 - C:\Users\analyst\AppData\Local\Microsoft\Windows\IManagementEngine\Lib\site-packages\pip\_internal\commands\freeze.py -
2e0f043a89319d166bc1d2d62602e9056c4d52defe1eb9169440b4e5efaf070c - C:\Users\analyst\AppData\Local\Microsoft\Windows\NtProfileIndex\Lib\site-packages\PIL\BlpImagePlugin.py -
1291e85528585f2a6ac671288924a19e00fb08f842798f1e7f0487d46e659d79 - C:\Users\analyst\AppData\Local\Microsoft\Windows\IManagementEngine\Lib\site-packages\pip\_internal\exceptions.py -
65dbb5ee955b0f5788ff28e0e7665dd32800583cbc2ed5d2d40b5fbe7d693edb - C:\Users\analyst\AppData\Local\Microsoft\Windows\NtProfileIndex\Lib\site-packages\PIL\CurImagePlugin.py -
3bf6c5b56f3662100cf3f17cb69af73b952bcca3cfca257d4b6ce357d430a9a2 - c:\users\analyst\appdata\local\microsoft\windows\ntprofileindex\lib\site-packages\requests\__pycache__\certs.cpython-312.pyc -
8acc60e828cfc02dfe97c7fd7d763011d75f99f2bcb5bdea0a0188004c6b53e6 - C:\Users\analyst\AppData\Local\Microsoft\Windows\NtProfileIndex\_asyncio.pyd -
184fc13677c7856e7a8b31dfe79ce68dcea10cdf83a205de2b0d5497fb0ffdf3 - C:\Users\analyst\AppData\Local\Microsoft\Windows\NtProfileIndex\python312.zip -
50923b458dad653990105637b17227af36cde152cfc1f88c16c99672a82d2e9c - c:\users\analyst\appdata\local\microsoft\windows\ntprofileindex\lib\site-packages\certifi\__pycache__\__init__.cpython-312.pyc -
6c3a49dbbbf05668bf41a5afcb3f5db59b2dcc3aa47052843ebc6002178135d8 - C:\Users\analyst\AppData\Local\Microsoft\Windows\NtProfileIndex\Lib\site-packages\idna\core.py -
b46525a332f4f83e1f2983de6437151ab8621f5aeff98a2a558295964fd5de19 - C:\Users\analyst\AppData\Local\Microsoft\Windows\NtProfileIndex\sqlite3.dll -
2f9c9940e87840ff1b5c4922d8b73c7302d1b12badc860990dfebdf77b4140ee
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787586914&P2=404&P3=2&P4=jgkD33NqS%2bsKBhWclTi3qhWlho0bDaQAyy4gAAKLbk9K9Hdm50b7a2ocQXT1ypkUUDkabgNAsaku5W35tSwvIQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/45cd9142-6feb-4946-89e7-63e58fada30a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/45cd9142-6feb-4946-89e7-63e58fada30a?P1=1787587051&P2=404&P3=2&P4=ORsEGAj7oAskbDxmKb9Idh9Yb2%2bTmFhKUTHoqO0tmHZ27wKEMCY4ChTkHS1VjOwU6fdT5ANI4aS0Kv2blTOozQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- 3j.ws
- polygon-rpc.com
- rpc-mainnet.matic.quiknode.pro
- polygon-public.nodies.app
- 1rpc.io
- polygon-mainnet.rpcfast.com
- polygon-bor-rpc.publicnode.com
- go.getblock.io
- api.zan.top
- polygon.rpc.subquery.network
- endpoints.omniatech.io
- bootstrap.pypa.io
- sltnnt.ru
- files.pythonhosted.org
Embedded IP addresses
- 74.179.71.159
- 104.46.162.230
- 52.230.60.54
- 172.215.188.232
- 4.230.171.124
- 74.179.77.204
- 74.179.77.164
- 52.168.117.168
- 135.233.95.144
- 52.123.129.14
- 20.76.201.171
- 172.178.240.161
- 203.26.79.13
- 206.223.224.224
- 132.145.155.63
- 185.178.208.191
- 52.148.114.188
- 104.16.248.249
- 104.26.4.88
- 104.21.77.34
- 104.21.80.104
- 172.66.150.162
- 185.44.207.189
- 8.219.97.231
- 104.26.13.231
File paths
- U:\F:
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report