MALICIOUS — 5377831079742fc65104a663b34fa7a0a7ab19e2cf016baf2599ed586d4ad94f
MALICIOUS — 5377831079742fc65104a663b34fa7a0a7ab19e2cf016baf2599ed586d4ad94f is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Container family. 9 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5377831079742fc65104a663b34fa7a0a7ab19e2cf016baf2599ed586d4ad94f - SHA-1:
d6396b462547cdaab0da241ca7f65dfebf1fa1ae - MD5:
18b52d9fb4c18f898f86a15665c5cde9 - imphash:
38aa7c2ff6ef0e48a9520d6702d08df4 - File type: pe · Size: 412018 bytes
- Verdict: malicious (98/100) · Family: Container
Detections (9 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Agent-6943819-1
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:UPX 3.91
- Kaspersky (KVRT): Virus.Win32.Agent.es
- Microsoft Defender: Virus:Win32/Sivis.A
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Trellix Stinger (McAfee): PolyPatch-UPX
MITRE ATT&CK
Dynamic analysis (windows)
25478 behavior events · 1 ATT&CK techniques · 97 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- settings-win.data.microsoft.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- licensing.mp.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- tas02.sls.update.microsoft.com
- v10.events.data.microsoft.com
- fe3cr.delivery.mp.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/12329/files/f56b7cf0c4121a9a4373670281c1665b348d809956d9de329c1779d5ac2a2ab3 —
f56b7cf0c4121a9a4373670281c1665b348d809956d9de329c1779d5ac2a2ab3 - /opt/CAPEv2/storage/analyses/12329/files/c6e8355b5b7b20479cd8995d0c19bcc66ee4331d3c3e0650e9f60322824d1c07 —
c6e8355b5b7b20479cd8995d0c19bcc66ee4331d3c3e0650e9f60322824d1c07 - /opt/CAPEv2/storage/analyses/12329/files/27dc11c2951d616c22fa4ec3cd466a042087fc33f8f5d213fb07c2e5d3308c5a —
27dc11c2951d616c22fa4ec3cd466a042087fc33f8f5d213fb07c2e5d3308c5a - /opt/CAPEv2/storage/analyses/12329/files/40f3673cc25696870f5b913107b75495d912b411051a2710cbfd60955672a0f0 —
40f3673cc25696870f5b913107b75495d912b411051a2710cbfd60955672a0f0 - /opt/CAPEv2/storage/analyses/12329/files/9ea0c1862abd2e6e31d0704eb17a6b446706bac627403ce5300d485aac95df1d —
9ea0c1862abd2e6e31d0704eb17a6b446706bac627403ce5300d485aac95df1d - /opt/CAPEv2/storage/analyses/12329/files/c26da7edb752b3a81c306692f51d7c6439698043f878015c9047f579264e38af —
c26da7edb752b3a81c306692f51d7c6439698043f878015c9047f579264e38af - /opt/CAPEv2/storage/analyses/12329/files/5eb8d6ce8a0e994fb6b51b7962747bffe826f1894678b52d475912cb07f9866d —
5eb8d6ce8a0e994fb6b51b7962747bffe826f1894678b52d475912cb07f9866d - /opt/CAPEv2/storage/analyses/12329/files/c4f520dbb098afaa7a71ad0c5b03537203e13d3f04b46f14d71feaf9bdc7b5af —
c4f520dbb098afaa7a71ad0c5b03537203e13d3f04b46f14d71feaf9bdc7b5af - /opt/CAPEv2/storage/analyses/12329/files/7e58130a79e039e22d55b7dd3205b1497e32e08685d501b5fcb426961d456a1f —
7e58130a79e039e22d55b7dd3205b1497e32e08685d501b5fcb426961d456a1f - /opt/CAPEv2/storage/analyses/12329/files/84a9526eaeff6a64b41fae6e3e1564eb52da0c3c1699c69134e34ae14b395bb9 —
84a9526eaeff6a64b41fae6e3e1564eb52da0c3c1699c69134e34ae14b395bb9 - /opt/CAPEv2/storage/analyses/12329/files/859f7ed6eecf24aab4c60c2b5cee85810e696da1797e0d856450b5149e4e409a —
859f7ed6eecf24aab4c60c2b5cee85810e696da1797e0d856450b5149e4e409a - /opt/CAPEv2/storage/analyses/12329/files/82d18af62893226f9759d77cccb873b756084f8348681e88ca6540e58b82280b —
82d18af62893226f9759d77cccb873b756084f8348681e88ca6540e58b82280b - /opt/CAPEv2/storage/analyses/12329/files/49ee510a8bf59756890d3548baf7952a49e7e8866c03aaf7542c154e48e39ff5 —
49ee510a8bf59756890d3548baf7952a49e7e8866c03aaf7542c154e48e39ff5 - /opt/CAPEv2/storage/analyses/12329/files/4742e27edbb5012478606fe7ccc2f0f217243a535a8595663ee149be18249ac2 —
4742e27edbb5012478606fe7ccc2f0f217243a535a8595663ee149be18249ac2 - /opt/CAPEv2/storage/analyses/12329/files/56cd02f1eec7b6a342bdbc0bd2a1fcd7f25f4dfeb9b350edcb224521a87bf7a6 —
56cd02f1eec7b6a342bdbc0bd2a1fcd7f25f4dfeb9b350edcb224521a87bf7a6
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- http://www.adobe.com/go/reader_system_reqs_it.UnmoveFilesRimozione
- http://www.adobe.com/go/reader_system_reqs_it
- https://www.digicert.com/CPS0
- http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
- http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
- http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
- http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
- http://www.digicert.com/ssl-cps-repository.htm0
- https://d.symcb.com/rpa0
- http://s.symcb.com/universal-root.crl0
- https://d.symcb.com/rpa0@
- http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
- http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0
- http://mozilla.org/MPL/2.0/
- http://www.apache.org/licenses/LICENSE-2.0
- http://www.w3.org/1999/XSL/Transform
- http://openoffice.org/2000/office
- http://openoffice.org/2000/style
- http://openoffice.org/2000/table
- http://openoffice.org/2000/drawing
- http://www.w3.org/1999/XSL/Format
- http://www.w3.org/1999/xlink
- http://purl.org/dc/elements/1.1/
- http://openoffice.org/2000/meta
Embedded domains
- creativecommons.org
- geocities.com
- www.adobe.com
- helpx.adobe.com
- www.microsoft.com
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- cacerts.digicert.com
- d.symcb.com
- s.symcb.com
- ts-crl.ws.symantec.com
- ts-aia.ws.symantec.com
- mozilla.org
- www.apache.org
- www.w3.org
- openoffice.org
- purl.org
- sun.com
Embedded IP addresses
- 20.42.179.204
- 20.42.65.88
- 20.247.184.197
- 4.230.171.124
- 172.215.188.225
- 74.178.240.61
- 135.233.95.135
- 51.132.193.104
- 85.210.196.11
- 48.211.4.16
- 135.233.45.223
- 203.26.79.13
- 74.178.76.44
- 20.184.175.12
- 104.208.16.94
- 72.154.7.105
- 74.178.76.128
- 172.178.240.163
- 4.209.250.170
- 20.42.65.91
- 52.148.114.188
- 52.168.117.170
- 92.223.78.30
- 52.110.12.44
- 52.110.12.4
More Container samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report