MALICIOUS — f86f96e91d462857fab9ee4f1d47ee8973cc1175a84eccdb28104c403f4a1ebc
MALICIOUS — f86f96e91d462857fab9ee4f1d47ee8973cc1175a84eccdb28104c403f4a1ebc is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the Delf family. 7 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
f86f96e91d462857fab9ee4f1d47ee8973cc1175a84eccdb28104c403f4a1ebc - SHA-1:
676f6a7107e6b1c791d54517a2bb8b63e5f228e3 - MD5:
2a9d17c0b69ec3397471b2762f3306f1 - imphash:
500ff1538958cc73738bf0c262a1773f - ssdeep:
196608:FAsn9TJn9Tin9TIn9T+n9TCn9T0fUefUQU4UUU3UUUJCfU1n9Tin9TNfUg:1Dcm4MCFymc73 - TLSH:
T14C69C0D5516211F2DE82CEB80DC03E1E1851E31659FC3CCC8591592A37EA2F7A48F7AA - Submitted as: f86f96e91d462857fab9ee4f1d47ee8973cc1175a84eccdb28104c403f4a1ebc
- File type: pe · Size: 8867548 bytes
- Verdict: malicious (96/100) · Family: Delf
Detections (7 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.dafixer,.dafixer,.dafixer,.dafixer,.dafixer
- ClamAV (daily): Win.Virus.Delf-9955432-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Detect It Easy (packer/type): DIE:Turbo Linker
- Microsoft Defender: Trojan:Win32/Vindor!pz
- Emsisoft (Emergency Kit): Trojan.Generic.34054357
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Virus.Delf-9955432-0 (rule
Win.Virus.Delf-9955432-0) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: high-entropy-sections:.dafixer,.dafixer,.dafixer,.dafixer,.dafixer, Turbo Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-cs-g1.crl05
- http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
- http://www.digicert.com/ssl-cps-repository.htm0
- http://crl.thawte.com/ThawteTimestampingCA.crl0
- http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
- http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
- http://appsyndication.org/2006/appsyn
Embedded domains
- mb.fi
- www.microsoft.com
- crl.microsoft.com
- schemas.microsoft.com
- cacerts.digicert.com
- crl4.digicert.com
- crl3.digicert.com
- www.digicert.com
- crl.thawte.com
- ts-aia.ws.symantec.com
- ts-crl.ws.symantec.com
- n5f5.se
- appsyndication.org
File paths
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System\37a1d51f35918dd36a0d4e34cc91732e\System.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Ga41585c2#\7145367d78cd9d75b5533cec821c7353\Microsoft.GroupPolicy.AdmTmplEditor.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\7e5e0d92b127a5150606d81839f29044\System.Drawing.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\028f9e8b0c8b1820df7bec952b01fe12\System.Windows.Forms.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\89bc329e8c65a9e13067c9776d925d78\System.Core.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\b5152c3c02957bbe4459505a39afde20\System.Configuration.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\1fb6db2ce6d2887fe6f8f620cb092343\System.Xml.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Accessibility\21911640a598b9b50a75e4b9b6330330\Accessibility.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\TaskScheduler\8f05bc8ead96f927b70dd88a9cb115ca\TaskScheduler.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\MIGUIControls\f3a17d2bfc42f22de1ee5f79808438e5\MIGUIControls.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\CustomMarshalers\38aff4f93ebb48cb7a316d01b4a806f7\CustomMarshalers.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\2bef38851483abae82f1172c1aaa604c\System.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\9d04ce1d8a3042f50b54c7f9ccdb4068\System.Core.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\fea996c385fbc624826f8e043f6d5329\System.Management.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wad78daf4#\8f73bd36654fa77803c3167f39ead17e\Microsoft.Windows.Diagnosis.SDHost.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wed3937f9#\3dae65a1b718d3a083094b67e1413e9a\Microsoft.Windows.Diagnosis.SDCommon.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\f02732d562721457afde5c189a906d17\System.Management.Automation.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.W0bb5dac4#\4c396dcf426dbba8eddd04adc0b562fe\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.W69ef49d2#\9dcd27fe1c298162f13c6bdb7c0cfe88\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wd518ee0d#\e9bd08c5c1a8c5fdef45c7025b262edc\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.W708fc392#\3c226a9afdce13116b1fdfa9e92b4152\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.W79a81d80#\2efe3e39ab8a210a684558961ff266d2\Microsoft.Windows.Diagnosis.Commands.WriteDiagTelemetry.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.P1706cafe#\16ab851088227b0798b233d026a1019e\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Confe64a9051#\29c26981c4b4347ca371002934f6f2ac\System.Configuration.Install.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Pb378ec07#\dac77e2bdc0040a1a2a446cbf77b6bae\Microsoft.PowerShell.ConsoleHost.ni.dll
More Delf samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report