MALICIOUS — 1f18c536c4cea112a0b2c1491474481d5e77a43c9467509c3807cad7a95f3236
MALICIOUS — 1f18c536c4cea112a0b2c1491474481d5e77a43c9467509c3807cad7a95f3236 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the Zusy family. 8 of 55 detection engines flagged it.
Identification
- SHA-256:
1f18c536c4cea112a0b2c1491474481d5e77a43c9467509c3807cad7a95f3236 - SHA-1:
3700ecb87cae670d8d62b70e58c96115a43016ce - MD5:
243abb610d5a4460692e1f587371b2ea - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
3072:q7CaoAs10ubol0xPTM7mRCAdJSSxPUkl3VEMQTCk/dN92sd0:EqD/Ml0xPTMiR9JSSxPUKAdy - TLSH:
T1A749FB3B30485E9FF299D6D978190D2DD1B24EC639E105C4DDD3983E7188867B8288E7 - Submitted as: 1f18c536c4cea112a0b2c1491474481d5e77a43c9467509c3807cad7a95f3236
- File type: pe · Size: 409600 bytes
- Verdict: malicious (96/100) · Family: Zusy
Detections (8 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): MPRESS
- ClamAV (daily): Win.Malware.Zusy-6804618-0
- YARA: Stratosphere IPS: STRATO_Malicious_UserAgent
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:MPRESS
- Microsoft Defender: Trojan:Win32/QQPass
- Emsisoft (Emergency Kit): Gen:Variant.Stealer.239
- Kaspersky (KVRT): Trojan.Win32.Scar.oetk
Why this verdict
The malicious score of 96/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Malware.Zusy-6804618-0 (rule
Win.Malware.Zusy-6804618-0) - engine signal, weight 0.90, confidence 0.95 - YARA: Stratosphere IPS flagged STRATO_Malicious_UserAgent (rule
STRATO_Malicious_UserAgent) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:MPRESS (rule
DIE:MPRESS) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://i2.tietuku.com/8975c2a506763d03.jpg, http://purl.org/dc/elements/1.1/, http://www.iec.ch - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: MPRESS - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://i2.tietuku.com/8975c2a506763d03.jpg
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://ns.adobe.com/xap/1.0/
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/photoshop/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/tiff/1.0/
- http://ns.adobe.com/exif/1.0/
- http://www.iec.ch
- http://zc.qq.com/chs/index.html
- https://aq.qq.com/cn2/findpsw/pc/pc_find_pwd_input_account?pw_type=0&aquin=
Embedded domains
- i2.tietuku.com
- ns.adobe.com
- www.w3.org
- purl.org
- www.iec.ch
- zc.qq.com
- aq.qq.com
More Zusy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report