MALICIOUS — 668eba558892d6d36406d2a9a7551d3a618edd941183e02f611ad3440f27f76b
MALICIOUS — 668eba558892d6d36406d2a9a7551d3a618edd941183e02f611ad3440f27f76b is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Shodi family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
668eba558892d6d36406d2a9a7551d3a618edd941183e02f611ad3440f27f76b - SHA-1:
e33fd5b1eed0096ee86b8d762979102f3af64469 - MD5:
0031f029a4fac02821a4db3168590705 - imphash:
77f13bc24efea5a05601b43cf44d1f1a - ssdeep:
49152:QX//w6X//wlX//wlX//wlX//wlX//wCX//wCX//wEr2:P - TLSH:
T179658C950226B784EEB59EB2B8414E3CA0A374FF75FA14CC6382D06F16F9E63A01514D - Submitted as: 668eba558892d6d36406d2a9a7551d3a618edd941183e02f611ad3440f27f76b
- File type: pe · Size: 6019929 bytes
- Verdict: malicious (97/100) · Family: Shodi
Detections (5 of 52 engines)
- ClamAV (daily): Win.Trojan.FuBu-1
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Virus:Win32/Shodi
- Emsisoft (Emergency Kit): Win32.HLLP.Shodi.A
- Kaspersky (KVRT): Virus.Win32.HLLP.Shodi.a
Why this verdict
The malicious score of 97/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Trojan.FuBu-1 (rule
Win.Trojan.FuBu-1) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Virus:Win32/Shodi (rule
Virus:Win32/Shodi) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.HLLP.Shodi.A (rule
Win32.HLLP.Shodi.A) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://crl.verisign.com/tss-ca.crl0
- https://www.verisign.com/rpa
- https://www.verisign.com/rpa01
- http://crl.verisign.com/pca3.crl0
- http://CSC3-2004-crl.verisign.com/CSC3-2004.crl0D
- https://www.verisign.com/rpa0
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
Embedded domains
- crl.verisign.com
- www.verisign.com
- www.microsoft.com
- crl.microsoft.com
- csc3-2004-crl.verisign.com
More Shodi samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report