CLEAN — 39e58d3da19de4d491a4fe3f49d8226403c11e9949f83e3d9893ee78beff2f72
CLEAN — 39e58d3da19de4d491a4fe3f49d8226403c11e9949f83e3d9893ee78beff2f72 is a script sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (29/100). 1 of 50 detection engines flagged it.
Identification
- SHA-256:
39e58d3da19de4d491a4fe3f49d8226403c11e9949f83e3d9893ee78beff2f72 - SHA-1:
07bce2cabb889c5963f08838a7b12403ab8dcfcf - MD5:
134f137cb04de16821a16da88401183d - File type: script · Size: 4158 bytes
- Verdict: clean (29/100)
Detections (1 of 50 engines)
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
Dynamic analysis (linux)
867 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- _dosvc._tcp.local
- ntp.ubuntu.com
- 4.247.188.233 IN · Pune · AS8075 Microsoft Corporation
- 72.154.7.97 US · Moses Lake · AS8075 Microsoft Corporation
- 203.26.79.13 NZ · Auckland · AS24305 EdgeIX Pty Ltd
- 224.0.0.251
- ff02::fb
- 10.240.0.1
- 57.155.101.212 SG · Singapore · AS8075 Microsoft Limited UK
- 91.189.91.157
- 135.232.92.137 US · Boydton · AS8075 Microsoft Limited
- ff02::2
- ff02::1:ff12:3456
- ff02::16
- 40.84.85.40 US · Boydton · AS8075 Microsoft Corporation
- 172.172.255.218 US · Ashburn · AS8075 Microsoft Limited
- 20.190.167.18
- 255.255.255.255
Dropped files
- tmp_tmp.UMESr1TXaG —
9ef3428f8a0393d4467d95af42d41fa487cf2dc4eab99a54e7c9b12578250050
Embedded IP addresses
- 4.247.188.233
- 72.154.7.97
- 203.26.79.13
- 57.155.101.212
- 135.232.92.137
- 40.84.85.40
- 172.172.255.218
File paths
- C:\UTAS-SA
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report