MALICIOUS — 2acf302ba6b0ac8e508d2d69ae6d0fdb092fe14a333215a53e1dbdd754f6e31d
MALICIOUS — 2acf302ba6b0ac8e508d2d69ae6d0fdb092fe14a333215a53e1dbdd754f6e31d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Sivis family. 9 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2acf302ba6b0ac8e508d2d69ae6d0fdb092fe14a333215a53e1dbdd754f6e31d - SHA-1:
e6dc777a2da677a8dd1168ba5c63af23150c93e7 - MD5:
1c3b21e198234c3390c391a4e6f2ba9f - imphash:
38aa7c2ff6ef0e48a9520d6702d08df4 - File type: pe · Size: 446488 bytes
- Verdict: malicious (100/100) · Family: Sivis
Detections (9 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Agent-6943819-1
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:UPX 3.91
- Microsoft Defender: Virus:Win32/Sivis.A
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Trellix Stinger (McAfee): PolyPatch-UPX
- Kaspersky (KVRT): Virus.Win32.Agent.es
MITRE ATT&CK
Dynamic analysis (windows)
25480 behavior events · 1 ATT&CK techniques · 97 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- settings-win.data.microsoft.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- licensing.mp.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- tas02.sls.update.microsoft.com
- www.bing.com
- fe3cr.delivery.mp.microsoft.com
- v10.events.data.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/12037/files/83a1dffe5e62c1097937cf2b3a608abe445deec8180dd13a0c3b409ae468b08e —
83a1dffe5e62c1097937cf2b3a608abe445deec8180dd13a0c3b409ae468b08e - /opt/CAPEv2/storage/analyses/12037/files/bf642b9bd642b550651ef86dcad30ef829e08760cc6642ce8d0ce828d57dfd19 —
bf642b9bd642b550651ef86dcad30ef829e08760cc6642ce8d0ce828d57dfd19 - /opt/CAPEv2/storage/analyses/12037/files/aec000840da677c235d46faca0d08d37fcade06eecfa9059fb4f2179bcb9e705 —
aec000840da677c235d46faca0d08d37fcade06eecfa9059fb4f2179bcb9e705 - /opt/CAPEv2/storage/analyses/12037/files/d77e9b98b443a3c1375a1191aab4a4f6f3c4fff78911ba720d30c0169f0425ee —
d77e9b98b443a3c1375a1191aab4a4f6f3c4fff78911ba720d30c0169f0425ee - /opt/CAPEv2/storage/analyses/12037/files/d700632ba3f18d39a0e3b7d2175e21c5985938498e50d773ab2cf3d8d28ebe63 —
d700632ba3f18d39a0e3b7d2175e21c5985938498e50d773ab2cf3d8d28ebe63 - /opt/CAPEv2/storage/analyses/12037/files/dbd9c3cb9e7840ffbe3c8886c86a70e7f3093ff91743a095a975474501bd75b5 —
dbd9c3cb9e7840ffbe3c8886c86a70e7f3093ff91743a095a975474501bd75b5 - /opt/CAPEv2/storage/analyses/12037/files/8e423a5cf82538761c91a18a207f71ec7f396e070d5a20e3b26d45a00a539fcd —
8e423a5cf82538761c91a18a207f71ec7f396e070d5a20e3b26d45a00a539fcd - /opt/CAPEv2/storage/analyses/12037/files/a93d2989df961028a571c48769c1c03486826d90396533edcb00177e25fa6036 —
a93d2989df961028a571c48769c1c03486826d90396533edcb00177e25fa6036 - /opt/CAPEv2/storage/analyses/12037/files/88827398b0515d58b73e57b0a3bc6a3b062c42a24656137e476a6974ac93ff1f —
88827398b0515d58b73e57b0a3bc6a3b062c42a24656137e476a6974ac93ff1f - /opt/CAPEv2/storage/analyses/12037/files/dd6823c68da19ad9738860a52af3a44fa6554d693c7b594b7d204c52bf9dae88 —
dd6823c68da19ad9738860a52af3a44fa6554d693c7b594b7d204c52bf9dae88 - /opt/CAPEv2/storage/analyses/12037/files/74f47aecba1dd140bb2c133b47e60a63810cf6d6498fb2d839190da8db629244 —
74f47aecba1dd140bb2c133b47e60a63810cf6d6498fb2d839190da8db629244 - /opt/CAPEv2/storage/analyses/12037/files/99e0e62af16aa6c9fc833a289e6be007ac254db8c4690f458468c6951ab595a7 —
99e0e62af16aa6c9fc833a289e6be007ac254db8c4690f458468c6951ab595a7 - /opt/CAPEv2/storage/analyses/12037/files/ad526a3c5df09fd53931fd87ea6ab4b64a0deb294266fec1c08261e034387424 —
ad526a3c5df09fd53931fd87ea6ab4b64a0deb294266fec1c08261e034387424 - /opt/CAPEv2/storage/analyses/12037/files/f3d88d1f65ad1c3a09c76a0f1b0128e06952143233ab7cefc44bb48696b67f21 —
f3d88d1f65ad1c3a09c76a0f1b0128e06952143233ab7cefc44bb48696b67f21 - /opt/CAPEv2/storage/analyses/12037/files/cc00f6087df441b57e1b96c42756b26450f468e4e57217f26aabd9fbc890659f —
cc00f6087df441b57e1b96c42756b26450f468e4e57217f26aabd9fbc890659f
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- http://www.adobe.com/go/reader_system_reqs_it.UnmoveFilesRimozione
- http://www.adobe.com/go/reader_system_reqs_it
- https://www.digicert.com/CPS0
- http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
- http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
- http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
- http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
- http://www.digicert.com/ssl-cps-repository.htm0
- https://d.symcb.com/rpa0
- http://s.symcb.com/universal-root.crl0
- https://d.symcb.com/rpa0@
- http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
- http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0
- http://mozilla.org/MPL/2.0/
- http://www.apache.org/licenses/LICENSE-2.0
- http://www.w3.org/1999/XSL/Transform
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786509319&P2=404&P3=2&P4=GOjF9sUEIsCzhkDFrDyoUlHOZtbH1jzVF4G4FKxICBvIttN6f2%2fl%2bdPYitIkw%2bwpVVU7uOTjWhSSKm%2bq1wi1MA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786509336&P2=404&P3=2&P4=hwA9Gyw%2fATlxi%2f%2fuZApsdDVlllQVn7JV7h2wpa%2fpzeivjYSIKfPJ%2b7CIoXjVUvxH5p6ZeMcQ2bOaVG%2f8giUKJA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- creativecommons.org
- geocities.com
- www.adobe.com
- helpx.adobe.com
- www.microsoft.com
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- cacerts.digicert.com
- d.symcb.com
- s.symcb.com
- ts-crl.ws.symantec.com
- ts-aia.ws.symantec.com
- mozilla.org
- www.apache.org
- www.w3.org
Embedded IP addresses
- 51.105.71.137
- 57.154.63.210
- 52.123.252.213
- 20.247.184.142
- 4.230.171.124
- 57.155.101.212
- 20.165.94.63
- 135.233.95.135
- 20.184.175.10
- 20.89.1.12
- 135.234.160.245
- 135.233.95.80
- 203.26.79.13
- 135.233.45.221
- 52.148.114.188
- 72.153.5.96
- 52.110.12.19
- 52.110.12.31
More Sivis samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report