MALICIOUS — 1136882a413e41a6ac5d565bd9c61e403f020b005a7a80114392588b7fcb61e9
MALICIOUS — 1136882a413e41a6ac5d565bd9c61e403f020b005a7a80114392588b7fcb61e9 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Ulise family. 8 of 52 detection engines flagged it.
Identification
- SHA-256:
1136882a413e41a6ac5d565bd9c61e403f020b005a7a80114392588b7fcb61e9 - SHA-1:
d1034a19c7fa2693378cb65668d45d6539f97cd0 - MD5:
7f2147f12ce138d5e5055d79ea2ee01b - imphash:
68864e2c52b98624974843d1b22a695b - ssdeep:
12288:CzCr6D+2OkeG9F1xk1kwZRo5FbDFBQX6f6AkdIAELARixZFDuW:Cza2OkeG9jxyTo5Fbz/zkOLLARixXDuW - TLSH:
T1724A23D806A6B310E1FA3777DB48D98D10D165F3686D203512CB531FA2F609BAE5A323 - Submitted as: 1136882a413e41a6ac5d565bd9c61e403f020b005a7a80114392588b7fcb61e9
- File type: pe · Size: 441284 bytes
- Verdict: malicious (97/100) · Family: Ulise
Detections (8 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): ASPack
- ClamAV (daily): Win.Malware.Ulise-9806872-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:Microsoft Linker
- LIEF (executable format parser): lief:invalid-authenticode
- Microsoft Defender: Trojan:Win32/Tonmye!pz
- Kaspersky (KVRT): HEUR:Trojan.Win32.AddUser.gen
Why this verdict
The malicious score of 97/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Malware.Ulise-9806872-0 (rule
Win.Malware.Ulise-9806872-0) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.360.cn, http://www.eyuyan.com, http://www.360.cn/ - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: ASPack, high-entropy-sections:.text, Microsoft Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://crl.verisign.com/tss-ca.crl0
- https://www.verisign.com/rpa
- https://www.verisign.com/rpa0
- https://www.verisign.com/cps0*
- http://logo.verisign.com/vslogo.gif0
- http://crl.verisign.com/pca3.crl0
- http://www.360.cn
- http://www.eyuyan.com
- http://www.360.cn/
Embedded domains
- crl.verisign.com
- www.verisign.com
- csc3-2009-2-crl.verisign.com
- csc3-2009-2-aia.verisign.com
- logo.verisign.com
- www.360.cn
- www.eyuyan.com
More Ulise samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report