SUSPICIOUS — 1ac9785462b0e86303d612861b4ed1bb06116d6e8b095a615e724a1427fba7f4
SUSPICIOUS — 1ac9785462b0e86303d612861b4ed1bb06116d6e8b095a615e724a1427fba7f4 is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100), attributed to the Container family. 2 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
1ac9785462b0e86303d612861b4ed1bb06116d6e8b095a615e724a1427fba7f4 - SHA-1:
20966ca6bffe4dd11ebe4fcdc2fa0a57cfd7c928 - MD5:
c81da76c7a74b82cc99e73f11645c928 - imphash:
8551886d6bc6bb9ee7fb70e8a2f2cd6d - File type: pe · Size: 962920 bytes
- Verdict: suspicious (58/100) · Family: Container
Detections (2 of 52 engines)
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: Yara-Rules community: YR_AntiDebug_Checks
MITRE ATT&CK
Embedded URLs
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/pkiops/certs/Microsoft%20Windows%20Code%20Signing%20PCA%202024.crt0
Embedded domains
- crl.microsoft.com
- www.microsoft.com
- my.microsoftpersonalcontent.com
File paths
- F:\dbs\sh\odct\0628_231015\cmd\11\client\onedrive\Product\Common\CommonUtil\CommonUtil.cpp
- F:\dbs\sh\odct\0628_231015\cmd\11\client\onedrive\Product\Common\CommonUtil\FavoritesAndNameSpaceUtilities.cpp
- F:\dbs\sh\odct\0628_231015\cmd\11\client\onedrive\Product\Common\CommonUtil\NamespaceRootUtil.cpp
- F:\dbs\sh\odct\0628_231015\client\onedrive\Product\Nucleus\win\exe\obj\amd64\OneDrive.Sync.Service.pdb
More Container samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report