MALICIOUS — 1109f814cc1af300e85891fe792789960e7b0d6b593fbc9c2f37e3e62593b224.img
MALICIOUS — 1109f814cc1af300e85891fe792789960e7b0d6b593fbc9c2f37e3e62593b224.img is a unknown sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (77/100), attributed to the Container family. 4 of 50 detection engines flagged it.
Identification
- SHA-256:
1109f814cc1af300e85891fe792789960e7b0d6b593fbc9c2f37e3e62593b224 - SHA-1:
ac8cc92babced4998f64ed9951dce6b01ff8b91e - MD5:
a27a6841affb6c8f0d016370a2262dcb - File type: unknown · Size: 6371328 bytes
- Verdict: malicious (77/100) · Family: Container
Source: MalwareBazaar · first seen 2026-08-01T00:00:00.000Z · SHA-256 verified
Detections (4 of 50 engines)
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: MalwareAnalyser community pack: TL_UPX_Packed
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Kaspersky (KVRT): HEUR:Trojan.VBS.SAgent.gen
Dynamic analysis (linux)
851 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep
- 4.247.188.224 IN · Pune · AS8075 Microsoft Corporation
- 10.240.0.1
- 224.0.0.251
- ff02::fb
- ff02::1:3
- 224.0.0.252
- 135.232.92.137 US · Boydton · AS8075 Microsoft Limited
- 10.240.0.255
- 169.254.255.255
- 185.125.190.58
- ff02::16
- 239.255.255.250
- 91.189.91.157
- ff02::2
- ff02::1
- 224.0.0.22
- ff02::1:ff12:3456
Dropped files
- tmp_tmp.fBtbFOFRFQ —
de1e87c35db3fe97190ea1b71e04a47f4dce991ccdb5184e70dd92b77f2f36c7
Embedded URLs
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.digicert.com/CPS0
- http://www.w3.org/1999/XSL/Format
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://ns.adobe.com/xap/1.0/
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/mm/
- http://mingw-w64.sourceforge.net/
Embedded domains
- www.microsoft.com
- crl.microsoft.com
- cacerts.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- www.w3.org
- lowagie.com
- ns.adobe.com
- purl.org
- mingw-w64.sourceforge.net
Embedded IP addresses
- 4.247.188.224
- 135.232.92.137
- 172.172.255.217
- 4.150.223.111
File paths
- Z:\Compilacao\4-Gerador-Loaders\TempZIP_W9
More Container samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report