MALICIOUS — ed48e74129c7f946abf72f6a14d4683a69cad54787e91c8a0b84b41b5eedfbd5.hta
MALICIOUS — ed48e74129c7f946abf72f6a14d4683a69cad54787e91c8a0b84b41b5eedfbd5.hta is a hta sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the execute family. 4 of 51 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
ed48e74129c7f946abf72f6a14d4683a69cad54787e91c8a0b84b41b5eedfbd5 - SHA-1:
eb39e030b6c13c2c8a28e88b75f489b6dc624604 - MD5:
da8e26b87e7ab3bbc11d9871cc400627 - ssdeep:
24576:FqTdye/nXJYlqjDd+7A5zlQYRxHTkQ/QxrJk+jaDNlJBAR/cq65ZaL47HReAZxVc:k+D93X - TLSH:
T10F64A0CEA5CF7369D67B2967A6644E21321583CCB52316187092D803AD5FEBEE3CC484 - Submitted as: ed48e74129c7f946abf72f6a14d4683a69cad54787e91c8a0b84b41b5eedfbd5.hta
- File type: hta · Size: 5507119 bytes
- Verdict: malicious (99/100) · Family: execute
Detections (4 of 51 engines)
- capa (capabilities): execute via PowerShell
- YARA: Trellix/McAfee ATR: ATR_BlackCat_ALPHV
- Emsisoft (Emergency Kit): Trojan.GenericFCA.9379
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 11 weighted signals:
- 2 behavioral detection(s): LOLBin: mshta executing remote/scripted payload [high] (rule
tl-lolbin-mshta) - dynamic signal, weight 0.60, confidence 0.90 - 2 behavioral detection(s): LOLBin: mshta executing remote/scripted payload [high] (rule
tl-lolbin-mshta) - dynamic signal, weight 0.60, confidence 0.90 - Memory forensics: 5 finding(s), e.g. RWX/private injected region in explorer.exe (pid 4944) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Obfuscated powershell script: dynamic-exec, encoded-command, defense-evasion (layers: base64) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Document contains macros/active content: hta-application, create-object, wscript-shell, powershell - static signal, weight 0.35, confidence 0.75
- YARA: Trellix/McAfee ATR flagged ATR_BlackCat_ALPHV (rule
ATR_BlackCat_ALPHV) - engine signal, weight 0.35, confidence 0.70 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
39882 behavior events · 2 ATT&CK techniques · 31 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- secure.globalsign.com
- outlook.cloud.microsoft
- checkip.dyndns.org
- www.bing.com
- desktop-hsgcbep
- dns.msftncsi.com
- config.edge.skype.com
- to-do.microsoft.com
- settings-win.data.microsoft.com
- ctldl.windowsupdate.com
- staging.to-do.microsoft.com
- edge.microsoft.com
- aps.prod.windows.com
- teams.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/3583/files/a9e770072d5e0200825142011e6880bf85f4b79e99cfdc7921870e9d3aa9e5ca -
a9e770072d5e0200825142011e6880bf85f4b79e99cfdc7921870e9d3aa9e5ca - /opt/CAPEv2/storage/analyses/3583/files/c579ca9e7b7eaf822f977942e8c33f86e4b69496bb4cb686afe3a702f1f64505 -
c579ca9e7b7eaf822f977942e8c33f86e4b69496bb4cb686afe3a702f1f64505 - /opt/CAPEv2/storage/analyses/3583/files/6c13fa3aa94a81793150902b5f77eda1b5678b85ce82d3324719bc8ce99725ae -
6c13fa3aa94a81793150902b5f77eda1b5678b85ce82d3324719bc8ce99725ae - /opt/CAPEv2/storage/analyses/3583/files/853a813183f0a1869905c5879dda2e85726658cd18149fc4a61bb9a861f6c9cf -
853a813183f0a1869905c5879dda2e85726658cd18149fc4a61bb9a861f6c9cf - /opt/CAPEv2/storage/analyses/3583/files/96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7 -
96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7 - /opt/CAPEv2/storage/analyses/3583/files/d46960a1392e06c11d21301afa0fb4e66fa44319fb038269c91312ca1a992db8 -
d46960a1392e06c11d21301afa0fb4e66fa44319fb038269c91312ca1a992db8 - /opt/CAPEv2/storage/analyses/3583/files/8aa7134c4b5c25087b5a44d641d82c95ea20e9c54574928439e99adc9f97bdab -
8aa7134c4b5c25087b5a44d641d82c95ea20e9c54574928439e99adc9f97bdab - /opt/CAPEv2/storage/analyses/3583/files/a78494c5c9dc5eaaa7f84ec6e2d4b542cfa770d28e64450168b2f07a626471e2 -
a78494c5c9dc5eaaa7f84ec6e2d4b542cfa770d28e64450168b2f07a626471e2 - /opt/CAPEv2/storage/analyses/3583/files/bdd2b7236a110b04c288380ad56e8d7909411da93eed2921301206de0cb0dda1 -
bdd2b7236a110b04c288380ad56e8d7909411da93eed2921301206de0cb0dda1 - c27905f18b0302310fa19644c3275b131820e86b362ff87fbaf008865de82732 -
c27905f18b0302310fa19644c3275b131820e86b362ff87fbaf008865de82732 - 15fb8f62f583bf0ce7726dac66ad377a009aee4c428e8e0c8d0d8f1d64bdd035 -
15fb8f62f583bf0ce7726dac66ad377a009aee4c428e8e0c8d0d8f1d64bdd035 - 5f4e7d0d195260df218fb3e0ad472c1500eb328fb836d4fee5b47268f89d2681 -
5f4e7d0d195260df218fb3e0ad472c1500eb328fb836d4fee5b47268f89d2681 - 1b708f0a3674ac801657e25ea045e7eef1164e3a4880bb9b93f7af1d2d6f923b -
1b708f0a3674ac801657e25ea045e7eef1164e3a4880bb9b93f7af1d2d6f923b - c451638cdce45da5545fb404b39827b228153d7a0e3ac59fde1eec27b0d97fc8 -
c451638cdce45da5545fb404b39827b228153d7a0e3ac59fde1eec27b0d97fc8 - 5ea3b561cb4c263139e96e07aad3cb3e6d05960ea9153713d1b1ef29228b2739 -
5ea3b561cb4c263139e96e07aad3cb3e6d05960ea9153713d1b1ef29228b2739
Embedded domains
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.cloud.microsoft
- checkip.dyndns.org
- searchapp.bundleassets.example
- www.msftconnecttest.com
- outlook.office.com
- outlook.office365.com
- secure.globalsign.com
- www.bing.com
- dns.msftncsi.com
- config.edge.skype.com
- to-do.microsoft.com
- settings-win.data.microsoft.com
- ctldl.windowsupdate.com
- staging.to-do.microsoft.com
- edge.microsoft.com
- aps.prod.windows.com
- teams.microsoft.com
- ecs.office.com
- watson.events.data.microsoft.com
- www.msftncsi.com
- g.live.com
- self.events.data.microsoft.com
- fs.microsoft.com
More execute samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report