MALICIOUS — 48ec62401a40a9e9b4917149f364e689ee11623972fd015bcdbaadbdae32b635
MALICIOUS — 48ec62401a40a9e9b4917149f364e689ee11623972fd015bcdbaadbdae32b635 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Container family. 9 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
48ec62401a40a9e9b4917149f364e689ee11623972fd015bcdbaadbdae32b635 - SHA-1:
8e342d0117de6cb9a184cd700fb0fa2a510b5628 - MD5:
8f5cf6f6f9fe42c4a3c912bd7b2cb14c - imphash:
38aa7c2ff6ef0e48a9520d6702d08df4 - File type: pe · Size: 431857 bytes
- Verdict: malicious (98/100) · Family: Container
Detections (9 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Agent-6943819-1
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:UPX 3.91
- Kaspersky (KVRT): Virus.Win32.Agent.es
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Trellix Stinger (McAfee): PolyPatch-UPX
MITRE ATT&CK
Dynamic analysis (windows)
25478 behavior events · 1 ATT&CK techniques · 97 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- v20.events.data.microsoft.com
- desktop-hsgcbep
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
- www.bing.com
- licensing.mp.microsoft.com
- tas02.sls.update.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- v10.events.data.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/11991/files/ca9f4dbf8d92d16bb12ddeca7975508e6d007aba6591e5a2bc0e6040701f466d —
ca9f4dbf8d92d16bb12ddeca7975508e6d007aba6591e5a2bc0e6040701f466d - /opt/CAPEv2/storage/analyses/11991/files/9b84544b334eb5f199bb738e56354b3290c2413e79261980ff9f5540ea58bfcb —
9b84544b334eb5f199bb738e56354b3290c2413e79261980ff9f5540ea58bfcb - /opt/CAPEv2/storage/analyses/11991/files/e25dc21d67faa61bb10fc486ad54913cf0f27b86cd55996cfcf8ee3dac00099e —
e25dc21d67faa61bb10fc486ad54913cf0f27b86cd55996cfcf8ee3dac00099e - /opt/CAPEv2/storage/analyses/11991/files/6a90ab25eda91d9e0fe0d47b23f4ea8efbba15c584821e54c72c71cfd3d38e02 —
6a90ab25eda91d9e0fe0d47b23f4ea8efbba15c584821e54c72c71cfd3d38e02 - /opt/CAPEv2/storage/analyses/11991/files/b103d7ed47b40b8d80f55c97c4aa87e4dca3a5a81deaa988b7b0eaf07c9c9008 —
b103d7ed47b40b8d80f55c97c4aa87e4dca3a5a81deaa988b7b0eaf07c9c9008 - /opt/CAPEv2/storage/analyses/11991/files/ab159fe1b30c58cff472086c93d6fc0fe999f698df11ccd184796356b3349689 —
ab159fe1b30c58cff472086c93d6fc0fe999f698df11ccd184796356b3349689 - /opt/CAPEv2/storage/analyses/11991/files/a9d87db256b6e66f3e606012bfc2f6fa032e3775d8452fc7c2d7bfc9107a2170 —
a9d87db256b6e66f3e606012bfc2f6fa032e3775d8452fc7c2d7bfc9107a2170 - /opt/CAPEv2/storage/analyses/11991/files/f02a6a4d67fa1dab196a9eca7c5e9e52e7b0f5e666e5375644d225a84b9e646a —
f02a6a4d67fa1dab196a9eca7c5e9e52e7b0f5e666e5375644d225a84b9e646a - /opt/CAPEv2/storage/analyses/11991/files/e9f8a5a26a0374260f7ff0de8f3386fc3e42adafbafd1251a464e43c56214746 —
e9f8a5a26a0374260f7ff0de8f3386fc3e42adafbafd1251a464e43c56214746 - /opt/CAPEv2/storage/analyses/11991/files/b25d69021e10c477b2224980cbd642e9734b653017dd4233f5fd17cf9ceb19a8 —
b25d69021e10c477b2224980cbd642e9734b653017dd4233f5fd17cf9ceb19a8 - /opt/CAPEv2/storage/analyses/11991/files/88937cc4f2e3ac8d3b89a48d6401c91c4935c4ee7b46a09c81cc3b61b49838dc —
88937cc4f2e3ac8d3b89a48d6401c91c4935c4ee7b46a09c81cc3b61b49838dc - /opt/CAPEv2/storage/analyses/11991/files/5acf446efea6d71426064b643d584cdac6c1697e67ebfbad4c0c77a03fa275df —
5acf446efea6d71426064b643d584cdac6c1697e67ebfbad4c0c77a03fa275df - /opt/CAPEv2/storage/analyses/11991/files/0678041f8b9fc866e9faf8d0c5d5b611acaeaedba19880440d3a168edfeceef2 —
0678041f8b9fc866e9faf8d0c5d5b611acaeaedba19880440d3a168edfeceef2 - /opt/CAPEv2/storage/analyses/11991/files/b529aa86fad54ea939901fed26ece91f75600bb199fb507b4eed2c617775d5ac —
b529aa86fad54ea939901fed26ece91f75600bb199fb507b4eed2c617775d5ac - /opt/CAPEv2/storage/analyses/11991/files/43fccef0ae7d00ddbc2e42cfdccf702bf2533fe5cb98da507ffe912259d34157 —
43fccef0ae7d00ddbc2e42cfdccf702bf2533fe5cb98da507ffe912259d34157
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- http://www.adobe.com/go/reader_system_reqs_it.UnmoveFilesRimozione
- http://www.adobe.com/go/reader_system_reqs_it
- https://www.digicert.com/CPS0
- http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
- http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
- http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
- http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
- http://www.digicert.com/ssl-cps-repository.htm0
- https://d.symcb.com/rpa0
- http://s.symcb.com/universal-root.crl0
- https://d.symcb.com/rpa0@
- http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
- http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786507232&P2=404&P3=2&P4=XPgfUPyNX%2bbtClak0IOOBHfcjvq5BN07kRYdp8tzVM1sNVfJmh6QwPAqKkbFq15fOO4eRRMzSCAqwIbuDGKXQg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786507262&P2=404&P3=2&P4=BBckCZPMiko5Je3sEjqbPlb2ukofcnGgHdXw%2b6%2bgfcnumduF2pge2PH2Rsf3Y4cHcc9rhdXr4yn4DiW8dcsBPg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- creativecommons.org
- geocities.com
- www.adobe.com
- helpx.adobe.com
- www.microsoft.com
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- cacerts.digicert.com
- d.symcb.com
- s.symcb.com
- ts-crl.ws.symantec.com
- ts-aia.ws.symantec.com
Embedded IP addresses
- 13.69.116.107
- 4.230.171.124
- 40.84.97.4
- 52.230.60.54
- 135.232.92.137
- 135.232.92.97
- 13.89.179.15
- 172.178.240.163
- 135.232.92.34
- 203.26.79.13
- 135.233.45.221
- 72.154.7.104
- 52.110.12.38
- 172.66.2.5
More Container samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report