MALICIOUS — 8114019d38380730b852d3b9ef2270cc449d37490184e2c7a674333e7ca5c039
MALICIOUS — 8114019d38380730b852d3b9ef2270cc449d37490184e2c7a674333e7ca5c039 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Sivis family. 9 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8114019d38380730b852d3b9ef2270cc449d37490184e2c7a674333e7ca5c039 - SHA-1:
bda5520e1dd814b43f87a8474c8ca0ac1bec50c2 - MD5:
66f217646bf2da1a4e68831ba3969f41 - imphash:
38aa7c2ff6ef0e48a9520d6702d08df4 - File type: pe · Size: 440764 bytes
- Verdict: malicious (100/100) · Family: Sivis
Detections (9 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Agent-6943819-1
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:UPX 3.91
- Microsoft Defender: Virus:Win32/Sivis.A
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Trellix Stinger (McAfee): PolyPatch-UPX
- Kaspersky (KVRT): Virus.Win32.Agent.es
MITRE ATT&CK
Dynamic analysis (windows)
25478 behavior events · 1 ATT&CK techniques · 97 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- settings-win.data.microsoft.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- licensing.mp.microsoft.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- tas02.sls.update.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- v10.events.data.microsoft.com
- slscr.update.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/12044/files/decaf71882dd739715108ef2f4fff279cb7269668a47a587714a0adc76f30286 —
decaf71882dd739715108ef2f4fff279cb7269668a47a587714a0adc76f30286 - /opt/CAPEv2/storage/analyses/12044/files/5befb1d18aee8ca2e130aa38b881661076c5fa8fdf4605c76d379638258a3b5b —
5befb1d18aee8ca2e130aa38b881661076c5fa8fdf4605c76d379638258a3b5b - /opt/CAPEv2/storage/analyses/12044/files/1a41816595982946810c78d864699cbc29abfee9e82af1dc10130f972fe3c71b —
1a41816595982946810c78d864699cbc29abfee9e82af1dc10130f972fe3c71b - /opt/CAPEv2/storage/analyses/12044/files/2c7ed5183a0a63d4fce71b6c5af1b44589b64bde5ad16bc431db873044574de5 —
2c7ed5183a0a63d4fce71b6c5af1b44589b64bde5ad16bc431db873044574de5 - /opt/CAPEv2/storage/analyses/12044/files/c7eca8b35d4e83762d7933b6fd9dde5a1b917715f4a80cd6753fe11b7986c4ec —
c7eca8b35d4e83762d7933b6fd9dde5a1b917715f4a80cd6753fe11b7986c4ec - /opt/CAPEv2/storage/analyses/12044/files/05011631f7288492c936151d70ab3a0631bf6fadb2534ad862742634fb698dfa —
05011631f7288492c936151d70ab3a0631bf6fadb2534ad862742634fb698dfa - /opt/CAPEv2/storage/analyses/12044/files/08ba1923d06e55def19b60a193a1f3da3a429a69daa48e568d09926b0b0023c8 —
08ba1923d06e55def19b60a193a1f3da3a429a69daa48e568d09926b0b0023c8 - /opt/CAPEv2/storage/analyses/12044/files/3d07b2d47020ccf5f3f27666971d373851974cee21d50c328cbe3371b41dfc51 —
3d07b2d47020ccf5f3f27666971d373851974cee21d50c328cbe3371b41dfc51 - /opt/CAPEv2/storage/analyses/12044/files/7cb658366f4c51fc8ba5db6dbe51aeac4026e7d8839578f4f313ef9eb1a2dc00 —
7cb658366f4c51fc8ba5db6dbe51aeac4026e7d8839578f4f313ef9eb1a2dc00 - /opt/CAPEv2/storage/analyses/12044/files/58efa1c2b6893ccb468e7c7caa117cdd0579d38759f47f164c8fb959b85eaf5c —
58efa1c2b6893ccb468e7c7caa117cdd0579d38759f47f164c8fb959b85eaf5c - /opt/CAPEv2/storage/analyses/12044/files/3270f26c57ca06ff57a47cc371028747ded1c7875ad00146d5f5f2b967a33431 —
3270f26c57ca06ff57a47cc371028747ded1c7875ad00146d5f5f2b967a33431 - /opt/CAPEv2/storage/analyses/12044/files/74d9a0bd118c140578bc6087a9220c07f68382c7e15349e49226eb9e0ee43311 —
74d9a0bd118c140578bc6087a9220c07f68382c7e15349e49226eb9e0ee43311 - /opt/CAPEv2/storage/analyses/12044/files/955e1e45abbc362193f8b046d9b4ca6e932c56970dded1728421f4099e966ad9 —
955e1e45abbc362193f8b046d9b4ca6e932c56970dded1728421f4099e966ad9 - /opt/CAPEv2/storage/analyses/12044/files/453be96ce5d51167c97f52f083abe38473fae950be96b8c6c0c1d2575b3fae88 —
453be96ce5d51167c97f52f083abe38473fae950be96b8c6c0c1d2575b3fae88 - /opt/CAPEv2/storage/analyses/12044/files/fc35d197bac7ec752d80478362d18d92e84452ac4eb6fda35c055c38f775a4e9 —
fc35d197bac7ec752d80478362d18d92e84452ac4eb6fda35c055c38f775a4e9
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- http://www.adobe.com/go/reader_system_reqs_it.UnmoveFilesRimozione
- http://www.adobe.com/go/reader_system_reqs_it
- https://www.digicert.com/CPS0
- http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
- http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
- http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
- http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
- http://www.digicert.com/ssl-cps-repository.htm0
- https://d.symcb.com/rpa0
- http://s.symcb.com/universal-root.crl0
- https://d.symcb.com/rpa0@
- http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
- http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786509459&P2=404&P3=2&P4=Mj3cty23%2bfXHqG4nOaofxvV7N9z%2bzm%2bYSC0kGgKGnPfHCUu2NSoCX3G%2b33KEc6ucDeqBMDkepxlNnLQVU8Fakw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786509520&P2=404&P3=2&P4=aRnUVfFCZ%2b%2f49PfuX6G7cwUGyV%2fMlhMchN0EcevKAJIlG9q58cpqn6%2fF0eNsgoLCQlkNo6mf2bTbMfp%2f0mHEMQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- creativecommons.org
- geocities.com
- www.adobe.com
- helpx.adobe.com
- www.microsoft.com
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- cacerts.digicert.com
- d.symcb.com
- s.symcb.com
- ts-crl.ws.symantec.com
- ts-aia.ws.symantec.com
- if.name
Embedded IP addresses
- 135.233.95.80
- 4.247.188.224
- 20.184.175.8
- 52.123.252.226
- 52.253.84.76
- 4.230.171.124
- 48.211.4.16
- 20.165.94.63
- 74.179.77.164
- 20.184.175.22
- 4.150.223.105
- 52.123.252.231
- 4.150.223.102
- 172.178.240.161
- 203.26.79.13
- 92.223.78.30
- 52.123.252.225
- 74.178.76.44
- 52.123.252.232
- 135.233.45.223
- 40.84.85.40
- 52.148.114.188
- 72.153.5.96
- 52.110.12.11
- 52.110.12.15
File paths
- C:\CAPE
- C:\CAPE\bootstrap.log
- C:\Python310-32\pythonw.exe
- C:\CAPE\agent.py
More Sivis samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report