MALICIOUS — 50f9c33587c6ecc731fb4a88cb002c8bb32e362d83bf1a18050f1e98b968c216
MALICIOUS — 50f9c33587c6ecc731fb4a88cb002c8bb32e362d83bf1a18050f1e98b968c216 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the Zusy family. 8 of 55 detection engines flagged it.
Identification
- SHA-256:
50f9c33587c6ecc731fb4a88cb002c8bb32e362d83bf1a18050f1e98b968c216 - SHA-1:
2eb18d5c62c14d09cf49752574df6169129afbe2 - MD5:
04919cb1f9c58668af2d33af57b29e6f - imphash:
3e4757b6c44f364955a909104e3b2b4d - ssdeep:
49152:afwWBmcCfwWBmc6fwWBmcX+Qn/Jf4MgVrVjnTKAdf:abBmcCbBmc6bBmcdyVPKAd - TLSH:
T17E5F8F86461BA106E1B7EC90B81495FC8421F4AD7AB4D28DA707C5AE4097D3BFEF1036 - Submitted as: 50f9c33587c6ecc731fb4a88cb002c8bb32e362d83bf1a18050f1e98b968c216
- File type: pe · Size: 3289710 bytes
- Verdict: malicious (96/100) · Family: Zusy
Detections (8 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Zusy-9875693-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Detect It Easy (packer/type): DIE:VMProtect
- Microsoft Defender: Trojan:Win32/Ausiv
- Emsisoft (Emergency Kit): GenPack:Trojan.Agent.EXMP
- Kaspersky (KVRT): UDS:Trojan.Win32.Generic
Why this verdict
The malicious score of 96/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Malware.Zusy-9875693-0 (rule
Win.Malware.Zusy-9875693-0) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:VMProtect (rule
DIE:VMProtect) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://creativecommons.org/publicdomain/zero/1.0/, http://purl.org/dc/elements/1.1/, http://xml.org/sax/features/namespaces - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-sections:.lol 1, VMProtect - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://office.microsoft.com/0
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://ns.adobe.com/iX/1.0/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://purl.org/dc/elements/1.1/
- http://schemas.microsoft.com/appv/2010/manifest
- http://xml.org/sax/features/namespaces
- http://xml.org/sax/features/namespace-prefixes
- http://xml.org/sax/properties/declaration-handler
- http://xml.org/sax/properties/lexical-handler
- http://schemas.microsoft.com/appx/2010/manifest
- http://schemas.microsoft.com/appv/2013/manifest
- http://schemas.microsoft.com/appv/2014/manifest
Embedded domains
- creativecommons.org
- geocities.com
- crl.microsoft.com
- www.microsoft.com
- office.microsoft.com
- www.w3.org
- ns.adobe.com
- purl.org
- schemas.microsoft.com
- xml.org
Embedded IP addresses
- 5.1.131.0
Registry keys
- HKEY_USERS\*_Classes
- HKEY_USERS\*\Software\Classes
- HKEY_CURRENT_USER\Software\Classes
- HKCU\Software\Classes
File paths
- f:\dd\tools\devdiv\FinalPublicKey.snk
- f:\dd\trinity\vsta\rt\VSTAAddInModel\AddInBase\objr\i386\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.pdb
- C:\ProgramData\Microsoft\Search\Data\Applications\Windows\
- C:\btvsts\3621\private\softgrid\shared\include\shared\file_utils.hpp
- C:\btvsts\3621\private\softgrid\shared\include\shared\env_utils.hpp
- C:\btvsts\3621\private\softgrid\shared\include\integration_subsystem_data.h
- c:\btvsts\3621\private\softgrid\client\integration\subsystem_tokenizer_collection_factory.h
- C:\btvsts\3621\private\softgrid\client\integration\PublishingCommands.h
- C:\btvsts\3621\private\softgrid\client\integration\isv_client_session.h
- C:\btvsts\3621\private\softgrid\client\integration\TransactionFactory.h
- C:\btvsts\3621\private\softgrid\client\integration\TransactionClasses.h
- C:\btvsts\3621\private\softgrid\client\integration\ActivityTransactionMap.h
- c:\btvsts\3621\private\softgrid\shared\include\SwRpcClient.h
- C:\btvsts\3621\private\softgrid\subsystems\include\integration_rpc_task.hpp
- c:\btvsts\3621\private\softgrid\subsystems\include\integration_rpc_client.hpp
- C:\btvsts\3621\private\softgrid\client\integration\notifier_process.hpp
- c:\btvsts\3621\private\softgrid\shared\clientconfiguration\ValueName.h
- c:\btvsts\3621\private\softgrid\shared\clientconfiguration\RegistryValue.h
- C:\btvsts\3621\private\softgrid\subsystems\shortcuts\unregister_command.hpp
- C:\btvsts\3621\private\softgrid\subsystems\shortcuts\register_command.hpp
- C:\btvsts\3621\private\softgrid\subsystems\include\exclusion_data.h
- C:\btvsts\3621\private\softgrid\shared\include\XMLUtils.h
- c:\btvsts\3621\private\softgrid\subsystems\fta\xml_interface.hpp
- D:\Program
- D:\OrcasSP.30620.00_25\ddsuites\src\vs\perf\Trinity\OptimizationTraining\opt_TarmacBase\ExcelVBSetup\perfprojects\published\blankxls.xlsx
More Zusy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report