MALICIOUS — e9b4d6a5caf4cbff318da751d338e29c95a187557221be23c53b0da6a506105d
MALICIOUS — e9b4d6a5caf4cbff318da751d338e29c95a187557221be23c53b0da6a506105d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Sivis family. 7 of 56 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e9b4d6a5caf4cbff318da751d338e29c95a187557221be23c53b0da6a506105d - SHA-1:
3a10f51951fa86015764a40326f0a567a5fb38df - MD5:
c8b30f9c83fe1e1eb4812c95fa8ed8f7 - imphash:
b10d16eedb1085ef7262dfc4ab03be6f - ssdeep:
1536:KEq3GcOK+LOBk8admpNNxEycf0sgTDFhNGpWMlwle3hhGrscg7Hq:KEqpa+NNxpsyFhNGpW0Grb - TLSH:
T1D23A03A4630CF439DDE9AFC70A75746CDE42256D2D9132CFACD096EA50A8C47B50BB80 - Submitted as: e9b4d6a5caf4cbff318da751d338e29c95a187557221be23c53b0da6a506105d
- File type: pe · Size: 97539 bytes
- Verdict: malicious (100/100) · Family: Sivis
Detections (7 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Ausiv-9881309-1
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:UPX
- Microsoft Defender: Virus:Win32/Sivis.A
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Kaspersky (KVRT): Virus.Win32.Agent.es
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 13 weighted signals:
- ClamAV (daily) flagged Win.Malware.Ausiv-9881309-1 (rule
Win.Malware.Ausiv-9881309-1) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Virus:Win32/Sivis.A (rule
Virus:Win32/Sivis.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Sivis.A (rule
Win32.Sivis.A) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.Agent.es (rule
Virus.Win32.Agent.es) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Contacted 1 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:UPX (rule
DIE:UPX) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://d.symcb.com/rpa0, http://s.symcb.com/universal-root.crl0, https://d.symcb.com/rpa0@ - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: UPX, high-entropy-sections:UPX1 - static signal, weight 0.25, confidence 0.55
- Dropped 10 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Memory forensics: 4 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
17852 behavior events · 0 ATT&CK techniques · 98 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- msedge.api.cdp.microsoft.com
- th.bing.com
- geo.prod.do.dsp.mp.microsoft.com
- kv801.prod.do.dsp.mp.microsoft.com
Dropped files
- C:\Program Files\7-Zip\Lang\ko.txt -
a6dac15ae35848c8f5f76aa01e0267b18b0dae200eb6b413f979f3fc27dcd463 - C:\Program Files\7-Zip\Lang\ms.txt -
33e87e089ce4b8adb4bccc9728e6abe79ab5e8989e232033d442cc751ad7c727 - C:\bake.ps1 -
ed15441cbaa128651187f687b5accc43ecea0c24674268457871cdee6031816b - C:\Program Files\7-Zip\Lang\hy.txt -
5b743fd6ee10b4e296f7b331b6743d970026e7db26b366b76c2330ec4f9da6f2 - C:\$Recycle.Bin\S-1-5-21-976637724-599762485-334819845-1001\desktop.ini -
22c62fcccb73a8dddb47540b50b3a988b5109832b7c6dac305182859340845bb - C:\Program Files\7-Zip\Lang\et.txt -
2309099152d9069917d12de9b35eec21e2333765ff220c734eeb6b67c76dbda5 - c64abc17045c2ec7d7745d4b9c1bb577f002afe2d94181aacc9c6ae68e3609ac -
c64abc17045c2ec7d7745d4b9c1bb577f002afe2d94181aacc9c6ae68e3609ac - C:\Program Files\7-Zip\Lang\ky.txt -
2bb44620f140dcd19c3e0de832d5460a271f061bb206219e49f4c11bbb314adf - C:\$WinREAgent\RollbackInfo.ini -
7acdc3d659999c15d216a9cbb8558a8dda4bc954223816caedaa7d787c9da5b8 - C:\Program Files\7-Zip\Lang\gl.txt -
6f3cea7c028e0e1df629dcd2619e3da62ced04ad4a55e14fba6c21150498060b - C:\Program Files\7-Zip\Lang\he.txt -
9195889ab935f8c84a01dcfddebfaeaa1bcce0f162258e2b1bf8e1a7770f5f53 - C:\Program Files\7-Zip\Lang\eu.txt -
968e03dde36e6f801e62ca62e8ee3b05896a4270f9176625dbb1caf4cf86d666 - C:\Program Files\7-Zip\Lang\eo.txt -
7fe5daf498b53db4975423ee9f5df0723e2ea74250a5c5e73ecffa0bfa8861ae - C:\Program Files\7-Zip\Lang\ro.txt -
949a7af4a41d56bf847f804b1a923679cb1cea3e1ea5e2fc3c6b15f320574fc5 - 9c27cb68e4ec789403add825c5be2950b2fb47d9d39b994295fe4959faaf3249 -
9c27cb68e4ec789403add825c5be2950b2fb47d9d39b994295fe4959faaf3249
Embedded URLs
- https://www.digicert.com/CPS0
- http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
- http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
- http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
- http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
- http://www.digicert.com/ssl-cps-repository.htm0
- https://d.symcb.com/rpa0
- http://s.symcb.com/universal-root.crl0
- https://d.symcb.com/rpa0@
- http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
- http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/89c77c08-6078-44b6-8f27-85720154df65/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/89c77c08-6078-44b6-8f27-85720154df65?P1=1788271557&P2=404&P3=2&P4=Gz52ro%2bDvaa5K%2ftIOYD9EpjtxOBtpNpExSOSTIHzfCP4W1iBID4DH3Gpm9QEahyVEVKPIApuKiTcEd97ywbedg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- cacerts.digicert.com
- d.symcb.com
- s.symcb.com
- ts-crl.ws.symantec.com
- ts-aia.ws.symantec.com
Embedded IP addresses
- 20.42.65.88
- 52.230.59.222
- 4.230.171.124
- 172.64.154.167
- 135.233.95.80
- 20.247.184.197
- 203.26.79.13
- 20.247.184.142
- 20.42.179.204
- 135.233.45.222
- 52.110.12.33
- 52.110.12.22
- 72.145.35.110
File paths
- C:\Windows.old\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim]
- C:\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim][gle=0x00000020]
- C:\Windows.old\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.1120_none_c3e
- C:\Windows.old\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.1_none_eedfed
- X:\SysResetTrace-Tel-Merge.etl,
- C:\$WINDOWS.~BT\Sources\Panther\SysResetTrace-Tel-Merge.etl)
- X:\windows\system32\sysreset.exe
- C:\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim]
More Sivis samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report