MALICIOUS — 8d9586b7fdad7cc4fcf76837568636f05eec8c534a02a3c86add9037b1f7a537
MALICIOUS — 8d9586b7fdad7cc4fcf76837568636f05eec8c534a02a3c86add9037b1f7a537 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Zusy family. 9 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8d9586b7fdad7cc4fcf76837568636f05eec8c534a02a3c86add9037b1f7a537 - SHA-1:
24750614a7fcbbd9adde66006fec7a67ff24ccda - MD5:
0fa1620007845486f747275d9871119d - imphash:
b10d16eedb1085ef7262dfc4ab03be6f - ssdeep:
196608:np55xTMpEldhKM6cWbCLDYBBnvjeApaAvktc:npxTMpuCM6cWbCQBNvjtIAvkS - TLSH:
T1446BC08846176312E2F3CDA4F8345BAC9432F09C6179ABCE7703D5AE4492A37E9E5035 - Submitted as: 8d9586b7fdad7cc4fcf76837568636f05eec8c534a02a3c86add9037b1f7a537
- File type: pe · Size: 10594829 bytes
- Verdict: malicious (97/100) · Family: Zusy
Detections (9 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Zusy-9875693-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: ReversingLabs: RL_AsyncRAT
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Detect It Easy (packer/type): DIE:UPX
- Microsoft Defender: Virus:Win32/Sivis.A
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Kaspersky (KVRT): Virus.Win32.Agent.es
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Malware.Zusy-9875693-0 (rule
Win.Malware.Zusy-9875693-0) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: ReversingLabs flagged RL_AsyncRAT (rule
RL_AsyncRAT) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:UPX (rule
DIE:UPX) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.gnu.org/licenses/, http://creativecommons.org/publicdomain/zero/1.0/, https://contoso.azurehdinsight.net/ - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: UPX, high-entropy-sections:UPX1 - static signal, weight 0.25, confidence 0.55
- encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.gnu.org/licenses/
- http://creativecommons.org/publicdomain/zero/1.0/
- http://www.adobe.com/type/legal.html
- http://crl.verisign.com/tss-ca.crl0
- http://logo.verisign.com/vslogo.gif0
- https://www.verisign.com/rpa
- http://csc3-2010-crl.verisign.com/CSC3-2010.crl0D
- https://www.verisign.com/rpa0
- http://csc3-2010-aia.verisign.com/CSC3-2010.cer0
- https://www.verisign.com/cps0*
- http://logo.verisign.com/vslogo.gif04
- http://crl.verisign.com/pca3-g5.crl04
- https://contoso.azurehdinsight.net/
- https://cluster.osdinfra.net/cosmos/vc/
- https://contoso.documents.azure.com
- http://example.com:10000/cliservice
- https://go.microsoft.com/fwlink/?LinkId=394782
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://office.microsoft.com/0
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
- http://www.w3.org/TR/REC-html40/loose.dtd
- http://www.adobe.com/go/accessibility
Embedded domains
- cwru.edu
- gnu.org
- www.gnu.org
- creativecommons.org
- www.adobe.com
- crl.verisign.com
- logo.verisign.com
- www.verisign.com
- csc3-2010-crl.verisign.com
- csc3-2010-aia.verisign.com
- contoso.azuredatalakestore.net
- contoso.azurehdinsight.net
- cluster.osdinfra.net
- contoso.documents.azure.com
- example.com
- go.microsoft.com
- crl.microsoft.com
- www.microsoft.com
- office.microsoft.com
- www.w3.org
- report.to
Embedded IP addresses
- 2.1.4.0
- 11.0.07.79
File paths
- X:\windows\system32\sysreset.exe
- C:\Windows.old\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim]
- C:\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim]
- C:\Windows.old\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.1120_none_c3e
- C:\Windows.old\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.1_none_eedfed
- X:\SysResetTrace-Tel-Merge.etl,
- C:\$WINDOWS.~BT\Sources\Panther\SysResetTrace-Tel-Merge.etl)
- X:\:`:d:h:l:
- X:\:`:d:h:l:p:d
- X:\:`:d:h:l:p:t:x:
- d:\temp\fields.txt
- c:\difficulty.dat
- A:\:t:y:
- C:\:f:y:
- O:\:
- L:\:q:z:
- X:\:`:d:h:
- X:\:`:d:h:x:
- X:\:l:p:t:
- D:\:l:p:
- X:\:l:p:x:
- X:\:l:p:
- X:\:`:h:
- H:\:d:l:t:
- T:\:l:x:
More Zusy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report