MALICIOUS — 6f6fbe1903b9e22ecc9209c2c074a6391e4b44dde8af209809de756124dafc35
MALICIOUS — 6f6fbe1903b9e22ecc9209c2c074a6391e4b44dde8af209809de756124dafc35 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Container family. 9 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6f6fbe1903b9e22ecc9209c2c074a6391e4b44dde8af209809de756124dafc35 - SHA-1:
a03a14fda94fa9554a42e7c8759c4566bda86c93 - MD5:
8c92a034b890059321b52160beb0ad41 - imphash:
38aa7c2ff6ef0e48a9520d6702d08df4 - File type: pe · Size: 440039 bytes
- Verdict: malicious (98/100) · Family: Container
Detections (9 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Agent-6943819-1
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:UPX 3.91
- Kaspersky (KVRT): Virus.Win32.Agent.es
- Microsoft Defender: Virus:Win32/Sivis.A
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Trellix Stinger (McAfee): PolyPatch-UPX
MITRE ATT&CK
Dynamic analysis (windows)
25476 behavior events · 1 ATT&CK techniques · 97 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- assets.msn.com
- www.bing.com
- tas02.sls.update.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- v10.events.data.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/11851/files/0b4e380bdc5e7251466045464a6bb62ce278ba50666fdb76d01509a1ad9c8774 —
0b4e380bdc5e7251466045464a6bb62ce278ba50666fdb76d01509a1ad9c8774 - /opt/CAPEv2/storage/analyses/11851/files/fbc56d825343d4514a0638dbe2aa7dbdee562ae480981c4eb251cf5eb28a0c14 —
fbc56d825343d4514a0638dbe2aa7dbdee562ae480981c4eb251cf5eb28a0c14 - /opt/CAPEv2/storage/analyses/11851/files/5e35ca6b1ed722f596a04913c4a6c28fd70c9755d2538396d8637517d32ffd8b —
5e35ca6b1ed722f596a04913c4a6c28fd70c9755d2538396d8637517d32ffd8b - /opt/CAPEv2/storage/analyses/11851/files/84b7d6a1b003e1eb67c24c585f7abb4790888ebf6f42e4cc1019219e65410564 —
84b7d6a1b003e1eb67c24c585f7abb4790888ebf6f42e4cc1019219e65410564 - /opt/CAPEv2/storage/analyses/11851/files/7db0b03c6760fbf9bfaa9319012532bf2656a58fb48ff063b88c7159e288f9b8 —
7db0b03c6760fbf9bfaa9319012532bf2656a58fb48ff063b88c7159e288f9b8 - /opt/CAPEv2/storage/analyses/11851/files/ec1e209ad5d63e50a9801a01cd747131e9f5b24cbdeec3e9cafc8111170f9290 —
ec1e209ad5d63e50a9801a01cd747131e9f5b24cbdeec3e9cafc8111170f9290 - /opt/CAPEv2/storage/analyses/11851/files/6396b0cc8e00755f631df49908fee4bc93973c677bea977b58ae4ede12a3cf44 —
6396b0cc8e00755f631df49908fee4bc93973c677bea977b58ae4ede12a3cf44 - /opt/CAPEv2/storage/analyses/11851/files/b803e716e2cbf91660c62d5fd7e681c9de450b5be37a186824027ac040762f53 —
b803e716e2cbf91660c62d5fd7e681c9de450b5be37a186824027ac040762f53 - /opt/CAPEv2/storage/analyses/11851/files/7d224cc8d3ea9d9e3244412900b04e5c0c850767701401d5f246d604be8616d4 —
7d224cc8d3ea9d9e3244412900b04e5c0c850767701401d5f246d604be8616d4 - /opt/CAPEv2/storage/analyses/11851/files/f456c78236cdc2f59b2f4a7e2806ef1d1e43793dde02c029016aa8b166463d1b —
f456c78236cdc2f59b2f4a7e2806ef1d1e43793dde02c029016aa8b166463d1b - /opt/CAPEv2/storage/analyses/11851/files/e27464b583e6f590b55f5cbcd14299078e24c75719315839a12128568104f74d —
e27464b583e6f590b55f5cbcd14299078e24c75719315839a12128568104f74d - /opt/CAPEv2/storage/analyses/11851/files/06ebebb15c8236ad26072d2cf81c09bfde101f5b0df11a74f051f531a18eeb22 —
06ebebb15c8236ad26072d2cf81c09bfde101f5b0df11a74f051f531a18eeb22 - /opt/CAPEv2/storage/analyses/11851/files/807386b06702d75523df7c6a7e137ca9ed525aa41965ec203c782c26dc2ce927 —
807386b06702d75523df7c6a7e137ca9ed525aa41965ec203c782c26dc2ce927 - /opt/CAPEv2/storage/analyses/11851/files/11533dfc36b454c992f703b0de31711cb006b05d76d672da3084d1098a44485f —
11533dfc36b454c992f703b0de31711cb006b05d76d672da3084d1098a44485f - /opt/CAPEv2/storage/analyses/11851/files/c0a66b5ad47218e806a0203f444743902c51f7d773005743fb79591aa9c87138 —
c0a66b5ad47218e806a0203f444743902c51f7d773005743fb79591aa9c87138
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- http://www.adobe.com/go/reader_system_reqs_it.UnmoveFilesRimozione
- http://www.adobe.com/go/reader_system_reqs_it
- https://www.digicert.com/CPS0
- http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
- http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
- http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
- http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
- http://www.digicert.com/ssl-cps-repository.htm0
- https://d.symcb.com/rpa0
- http://s.symcb.com/universal-root.crl0
- https://d.symcb.com/rpa0@
- http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
- http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786503247&P2=404&P3=2&P4=WopQthugMHoChwbRcxtfv6F8X%2fI5dirSl4qIIk6jjdyZrBMgX93nDH2WQ0GN3MvUCUAkapcnFWbjUb76Wz%2fmTA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- creativecommons.org
- geocities.com
- www.adobe.com
- helpx.adobe.com
- www.microsoft.com
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- cacerts.digicert.com
- d.symcb.com
- s.symcb.com
- ts-crl.ws.symantec.com
- ts-aia.ws.symantec.com
Embedded IP addresses
- 4.150.223.97
- 52.123.252.192
- 4.230.171.124
- 20.247.185.124
- 40.84.97.4
- 20.165.94.63
- 4.150.223.98
- 74.178.240.51
- 4.207.44.75
- 135.233.45.221
- 4.150.223.109
- 20.50.201.203
- 203.26.79.13
- 52.123.252.212
- 135.233.95.80
- 135.234.160.245
- 52.148.114.188
- 72.154.7.110
- 52.110.12.30
- 52.110.12.1
More Container samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report