MALICIOUS — 658b879af35c40c006fa8b6f09d8f5a66d7a8740b2aafd0cba618a79a5c02295
MALICIOUS — 658b879af35c40c006fa8b6f09d8f5a66d7a8740b2aafd0cba618a79a5c02295 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Container family. 9 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
658b879af35c40c006fa8b6f09d8f5a66d7a8740b2aafd0cba618a79a5c02295 - SHA-1:
ebb41035cb7a5854fd0b8be721d725b1de12020f - MD5:
fe1fd33e72defba990f71418ec86308e - imphash:
38aa7c2ff6ef0e48a9520d6702d08df4 - File type: pe · Size: 410293 bytes
- Verdict: malicious (98/100) · Family: Container
Detections (9 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Agent-6943819-1
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:UPX 3.91
- Kaspersky (KVRT): Virus.Win32.Agent.es
- Microsoft Defender: Virus:Win32/Sivis.A
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Trellix Stinger (McAfee): PolyPatch-UPX
MITRE ATT&CK
Dynamic analysis (windows)
25476 behavior events · 1 ATT&CK techniques · 97 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- msedge.api.cdp.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- tas02.sls.update.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- v10.events.data.microsoft.com
- settings-win.data.microsoft.com
- kv801.prod.do.dsp.mp.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/12254/files/31d5541cd6a4dd253b7049f491cd28c66ce99947dc85d99cefe2e8dfd0c0ed55 —
31d5541cd6a4dd253b7049f491cd28c66ce99947dc85d99cefe2e8dfd0c0ed55 - /opt/CAPEv2/storage/analyses/12254/files/1d3b4f353b92fe6e32c995e1a23f1b6e3b871c3c08b4b9b243fc55553e5c3de8 —
1d3b4f353b92fe6e32c995e1a23f1b6e3b871c3c08b4b9b243fc55553e5c3de8 - /opt/CAPEv2/storage/analyses/12254/files/b0f43556daead19815e4376aeeca2153c668484b3531f518f2231b03ef3764cc —
b0f43556daead19815e4376aeeca2153c668484b3531f518f2231b03ef3764cc - /opt/CAPEv2/storage/analyses/12254/files/0377dce47eaea114a496139dc6de673bce1bcd10ba70dbd49f92d084f5b47959 —
0377dce47eaea114a496139dc6de673bce1bcd10ba70dbd49f92d084f5b47959 - /opt/CAPEv2/storage/analyses/12254/files/38b5e4e478e306e8d2e9b24eb83704c1bd07db36fb0aa564ae96e5e16f8c5fb0 —
38b5e4e478e306e8d2e9b24eb83704c1bd07db36fb0aa564ae96e5e16f8c5fb0 - /opt/CAPEv2/storage/analyses/12254/files/1a3fc94eb621c7813e96b0600aa879bbb7f1dcd3a7ec4ac1c59e74c62fbd8b6c —
1a3fc94eb621c7813e96b0600aa879bbb7f1dcd3a7ec4ac1c59e74c62fbd8b6c - /opt/CAPEv2/storage/analyses/12254/files/48e776001c930e410f96aee61ba4dcf845c2c4b53e03e690c64ff81274147fa5 —
48e776001c930e410f96aee61ba4dcf845c2c4b53e03e690c64ff81274147fa5 - /opt/CAPEv2/storage/analyses/12254/files/de2afe1f9062ade5ae8d408616987e82a49d9e398fc07cc1eb672fba3bdfe131 —
de2afe1f9062ade5ae8d408616987e82a49d9e398fc07cc1eb672fba3bdfe131 - /opt/CAPEv2/storage/analyses/12254/files/c8b06ddf83d602c4363ecd19d8c788635882f0b9d1bfef5eeb2f740f6137ecdb —
c8b06ddf83d602c4363ecd19d8c788635882f0b9d1bfef5eeb2f740f6137ecdb - /opt/CAPEv2/storage/analyses/12254/files/3689993cd0bb7dda507b3df8051019425dca9ed04a0ee5ee19d929730b2193de —
3689993cd0bb7dda507b3df8051019425dca9ed04a0ee5ee19d929730b2193de - /opt/CAPEv2/storage/analyses/12254/files/43bfd38ddd4b17a28d93a753417d7693bab9ff34b386e13eed7552bb490fbdb4 —
43bfd38ddd4b17a28d93a753417d7693bab9ff34b386e13eed7552bb490fbdb4 - /opt/CAPEv2/storage/analyses/12254/files/6ff1011a3a022ba026fc59f24b9d6d705b152240ef55ad05e002c7ced23092b2 —
6ff1011a3a022ba026fc59f24b9d6d705b152240ef55ad05e002c7ced23092b2 - /opt/CAPEv2/storage/analyses/12254/files/30810ba385baf8702bd89d6daf9391ac7313bab2c39d69795c0b29a2dd49b302 —
30810ba385baf8702bd89d6daf9391ac7313bab2c39d69795c0b29a2dd49b302 - /opt/CAPEv2/storage/analyses/12254/files/cea042310d9941394fb5a9d52e384866629d0c56b98b635680bba833025c0433 —
cea042310d9941394fb5a9d52e384866629d0c56b98b635680bba833025c0433 - /opt/CAPEv2/storage/analyses/12254/files/7bb0a85dbf48b6a66e415e9020501f21cf123aab858582a42483bc6833ff03f0 —
7bb0a85dbf48b6a66e415e9020501f21cf123aab858582a42483bc6833ff03f0
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- http://www.adobe.com/go/reader_system_reqs_it.UnmoveFilesRimozione
- http://www.adobe.com/go/reader_system_reqs_it
- https://www.digicert.com/CPS0
- http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
- http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
- http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
- http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
- http://www.digicert.com/ssl-cps-repository.htm0
- https://d.symcb.com/rpa0
- http://s.symcb.com/universal-root.crl0
- https://d.symcb.com/rpa0@
- http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
- http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786516192&P2=404&P3=2&P4=ihTmv1rRo6Rr7AuQj0uDNDFfW1w4riztskt65y9rZwjkQyH9tCW9rIzkVTlkBWPHVNssGU9Ep%2bGV3QUgc8jl6g%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786516277&P2=404&P3=2&P4=j38yOmcl17sMbylfQMz3m4rPQV6H%2bhDvxEpHpabLpCAPvSGJDCs11CLIjeQqp4Sus3jV9Lvk7YL2yQ7P49Ctxg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- creativecommons.org
- geocities.com
- www.adobe.com
- helpx.adobe.com
- www.microsoft.com
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- cacerts.digicert.com
- d.symcb.com
- s.symcb.com
- ts-crl.ws.symantec.com
- ts-aia.ws.symantec.com
Embedded IP addresses
- 4.150.223.99
- 52.123.252.230
- 135.233.95.144
- 4.230.171.124
- 135.232.92.97
- 20.42.73.30
- 40.84.85.40
- 52.253.84.76
- 20.42.65.90
- 203.26.79.13
- 135.233.95.80
- 135.233.45.221
- 135.234.160.246
- 72.154.7.109
- 92.223.78.30
- 52.148.114.188
- 52.110.12.44
- 52.110.12.16
More Container samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report