MALICIOUS — 1418a13be8f07a11ae24c41e9d47054fd4edf86b5d55488ee817d93eecccca1d
MALICIOUS — 1418a13be8f07a11ae24c41e9d47054fd4edf86b5d55488ee817d93eecccca1d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Sivis family. 9 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1418a13be8f07a11ae24c41e9d47054fd4edf86b5d55488ee817d93eecccca1d - SHA-1:
8fadf497667d8bd80875f394c7a4ba5fa0c20d7a - MD5:
c7e2e0a4c6f569081462eec2d89dfc23 - imphash:
38aa7c2ff6ef0e48a9520d6702d08df4 - File type: pe · Size: 436510 bytes
- Verdict: malicious (100/100) · Family: Sivis
Detections (9 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Agent-6943819-1
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:UPX 3.91
- Microsoft Defender: Virus:Win32/Sivis.A
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Trellix Stinger (McAfee): PolyPatch-UPX
- Kaspersky (KVRT): Virus.Win32.Agent.es
MITRE ATT&CK
Dynamic analysis (windows)
25482 behavior events · 1 ATT&CK techniques · 97 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
- licensing.mp.microsoft.com
- www.bing.com
- tas02.sls.update.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- v10.events.data.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/12008/files/b825a01e35bd5d389168060718d054b4b2a3dbd8d92c3adc1f2e875dd0a00072 —
b825a01e35bd5d389168060718d054b4b2a3dbd8d92c3adc1f2e875dd0a00072 - /opt/CAPEv2/storage/analyses/12008/files/42749ee868b8d0b58b714557161a51c7b619ccaa63cb49b124e4c44df58909d3 —
42749ee868b8d0b58b714557161a51c7b619ccaa63cb49b124e4c44df58909d3 - /opt/CAPEv2/storage/analyses/12008/files/9ef27367ce49c59aeaa7bae7f6fab5c5253193f929bf79387d30f5012c78d192 —
9ef27367ce49c59aeaa7bae7f6fab5c5253193f929bf79387d30f5012c78d192 - /opt/CAPEv2/storage/analyses/12008/files/d3a087e497e17da1b5c941405bb4a8c0ae6f71cdc9960cc920fa8aa8eb8bfda6 —
d3a087e497e17da1b5c941405bb4a8c0ae6f71cdc9960cc920fa8aa8eb8bfda6 - /opt/CAPEv2/storage/analyses/12008/files/778c457616aac6a52967b456668a2dc86c400ecab6daef8a8dd06e139f5a4b74 —
778c457616aac6a52967b456668a2dc86c400ecab6daef8a8dd06e139f5a4b74 - /opt/CAPEv2/storage/analyses/12008/files/9e78d3d876181f75a392a97eec3b5866ec9007852622304d43289d3bd374e068 —
9e78d3d876181f75a392a97eec3b5866ec9007852622304d43289d3bd374e068 - /opt/CAPEv2/storage/analyses/12008/files/badac682e414f7294670217ef6d5085013bce4b986ee844645e966da4a260f21 —
badac682e414f7294670217ef6d5085013bce4b986ee844645e966da4a260f21 - /opt/CAPEv2/storage/analyses/12008/files/848e7e59b49af026fc40bd31d16e66d217e69d500a31a25708ffbd827d190db8 —
848e7e59b49af026fc40bd31d16e66d217e69d500a31a25708ffbd827d190db8 - /opt/CAPEv2/storage/analyses/12008/files/3a54b731114b7138a9582a0c853d3d413e073f59fb50f88f7a4dd8870de29e54 —
3a54b731114b7138a9582a0c853d3d413e073f59fb50f88f7a4dd8870de29e54 - /opt/CAPEv2/storage/analyses/12008/files/13105068c4b9f52bd18838115e64b5cfc107d00eb9590d762dd5fd7210cfc0e6 —
13105068c4b9f52bd18838115e64b5cfc107d00eb9590d762dd5fd7210cfc0e6 - /opt/CAPEv2/storage/analyses/12008/files/13ada199ee57c9dea2ce6c81bb58a610a8aa3028f2c6536e63de3e6972379843 —
13ada199ee57c9dea2ce6c81bb58a610a8aa3028f2c6536e63de3e6972379843 - /opt/CAPEv2/storage/analyses/12008/files/822d119f78305e9e02513001c1956f8cf0146243c762d838b1f7074e9b2afd6c —
822d119f78305e9e02513001c1956f8cf0146243c762d838b1f7074e9b2afd6c - /opt/CAPEv2/storage/analyses/12008/files/c4bb299f0d79a835f837c6a30b2363c7c0d97b27ca8c6480fa16c03dfb421395 —
c4bb299f0d79a835f837c6a30b2363c7c0d97b27ca8c6480fa16c03dfb421395 - /opt/CAPEv2/storage/analyses/12008/files/ef8dfabde9452422368770c29572fbbcbc8ec9115e8c028d9b863a22f892edfe —
ef8dfabde9452422368770c29572fbbcbc8ec9115e8c028d9b863a22f892edfe - /opt/CAPEv2/storage/analyses/12008/files/578990d1d24199864d537d2f69b2bebe95854df7916997b2f47e2cb7cdc16611 —
578990d1d24199864d537d2f69b2bebe95854df7916997b2f47e2cb7cdc16611
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- http://www.adobe.com/go/reader_system_reqs_it.UnmoveFilesRimozione
- http://www.adobe.com/go/reader_system_reqs_it
- https://www.digicert.com/CPS0
- http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
- http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
- http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
- http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
- http://www.digicert.com/ssl-cps-repository.htm0
- https://d.symcb.com/rpa0
- http://s.symcb.com/universal-root.crl0
- https://d.symcb.com/rpa0@
- http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
- http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786508199&P2=404&P3=2&P4=SGREIr%2bBLeImjKPa6Kd0dBBAx6%2b3OU4HQ%2fp1r7k93u%2bD3SkzT04vdAcO2fgLzrCfOa8xX7ERWZFtlKESkhjoww%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786508228&P2=404&P3=2&P4=PwyhFDN4mIG6mRM3Oi0zsQ3MeaItOpuu%2f%2fO7rDWJKI8%2fa95m1XgNyGGDHJsE0Nmoh9X5TRIOQ%2bbOGckUQ0JocA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- creativecommons.org
- geocities.com
- www.adobe.com
- helpx.adobe.com
- www.microsoft.com
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- cacerts.digicert.com
- d.symcb.com
- s.symcb.com
- ts-crl.ws.symantec.com
- ts-aia.ws.symantec.com
Embedded IP addresses
- 52.168.117.174
- 52.123.252.248
- 4.230.171.124
- 85.210.196.11
- 20.247.184.142
- 57.155.101.212
- 135.232.92.137
- 74.179.77.164
- 20.42.65.85
- 135.234.160.246
- 52.123.252.245
- 20.165.94.46
- 203.26.79.13
- 135.234.160.245
- 72.154.7.109
- 52.110.12.4
More Sivis samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report