MALICIOUS — 985e7e111045873869ec27c3cdf7db4c46eab4cb6b89e0888bf4d9f05b287aa7
MALICIOUS — 985e7e111045873869ec27c3cdf7db4c46eab4cb6b89e0888bf4d9f05b287aa7 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the FuBu family. 8 of 55 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
985e7e111045873869ec27c3cdf7db4c46eab4cb6b89e0888bf4d9f05b287aa7 - SHA-1:
630889a31eff23927e9d9e15960bee6a5540e294 - MD5:
1e9bcf6a8a4eee9c822c8f4cdef21ed1 - imphash:
77f13bc24efea5a05601b43cf44d1f1a - ssdeep:
12288:jZwrnIfqrQSaKKP85bM3npxYfj63hgD1Zin:FwMfqQXKS3npi63iw - TLSH:
T1914F39CD022E6301E2B6CE246C209EED48A5B4D961797A8C0F47CA7F01D3927FDB1569 - Submitted as: 985e7e111045873869ec27c3cdf7db4c46eab4cb6b89e0888bf4d9f05b287aa7
- File type: pe · Size: 727041 bytes
- Verdict: malicious (99/100) · Family: FuBu
Detections (8 of 55 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Trojan.FuBu-1
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Virus:Win32/Shodi
- Emsisoft (Emergency Kit): Win32.HLLP.Shodi.A
- Kaspersky (KVRT): Virus.Win32.HLLP.Shodi.a
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Win.Trojan.FuBu-1 (rule
Win.Trojan.FuBu-1) - engine signal, weight 0.90, confidence 0.95 - Dropped a suspicious payload: sdraw.usa - dynamic signal, weight 0.40, confidence 0.90
- capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 25 external host(s) at runtime (23 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: delivr.to detections flagged DLV_Maldoc_VBA_AutoExec (rule
DLV_Maldoc_VBA_AutoExec) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://d.symcb.com/rpa0, http://s.symcb.com/universal-root.crl0, https://d.symcb.com/rpa0@ - static signal, weight 0.35, confidence 0.60
- 1 behavioral detection(s): Discovery: enumerates installed security software [low] (rule
tl-security-software-discovery) - dynamic signal, weight 0.20, confidence 0.90 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60
Dynamic analysis (windows)
12733 behavior events · 0 ATT&CK techniques · 21 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- settings-win.data.microsoft.com
Dropped files
- C:\Program Files\LibreOffice\program\sbase.exe -
8f0137d59948d75cdc1b4400044ba11d9e3da6399e28da93fb3322383e93bb06 - C:\Program Files\LibreOffice\program\simpress.usa -
920fb0937f8a9d345830865059b6ae3f35ab6803ad4cffef4447473ec18e17a0 - C:\Program Files\LibreOffice\program\sdraw.usa -
f19afa9bbf2ef0308f37ce6cb87cb3c59eb2d1685e08d8b15fd197dda813f379 - C:\Windows\System32\UsaShohdi.asu -
eaaa0e9eedab09c0ba533120cee9be2721809a4ce3f675eb7717da41095c3bff - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jaccessinspector.usa -
a7487ee88d94f322148489c818cc861ee1e77ec31ce5b5e7b5e999c0d5acf6f6 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\javaw.usa -
00293b1fc4c093b570c7a9433fb5b16b188e938061cacf6f7a35721a6f346acb - C:\Program Files\LibreOffice\program\simpress.exe -
25b2faed7cda297e2005b44c417dc3c894f4c44ded84f50f39d877c27ab8c72a - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jaccesswalker.exe -
afee820d037fed9319a8659866d201de1d3029fb9e6f44f9477bd143c8a4ebd4 - C:\Program Files\LibreOffice\program\scalc.exe -
5b7f66954edf558bd7b0071f6de3669514551304a0da1f034cf705c5cf058ae1 - C:\Windows\System32\UsaShohdi.asu -
ed00904324dc0fe4d2a7bffd814cc10d346c18665e566896a4a750f5ad9fef6c - C:\Program Files\LibreOffice\program\scalc.usa -
130a4605825eea29caadb8594dd5a1762c18d778759eebcc648b4b96596ce20f - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\javaw.exe -
bcb6bf1e48e141f68ae63fa9eb0bb0706270d329670bf604ec981b663de075c3 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jaccessinspector.exe -
a46586972d5e6a83d0a471a2f0ce691c22f9c96085d5ca1e88acc09fdca12a91 - C:\Program Files\LibreOffice\program\quickstart.exe -
a3109a8096172f76c61aa61b6f6d3a8f8b22453a674942b18349033797fcca96 - C:\Program Files\LibreOffice\program\odbcconfig.usa -
70f519a82ef226da3791ff910a9204b130b3dacc0d2da4b60412f0dae113d7b7
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- https://www.digicert.com/CPS0
- http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
- http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
- http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
- http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
- http://www.digicert.com/ssl-cps-repository.htm0
- https://d.symcb.com/rpa0
- http://s.symcb.com/universal-root.crl0
- https://d.symcb.com/rpa0@
- http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
- http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0
- http://www.adobe.com/go/acrobat_system_reqs_ae
- http://www.adobe.com/go/acrobat_system_reqs
- http://www.adobe.com/go/acrobat_system_reqs_cn
- http://www.adobe.com/go/acrobat_system_reqs_tw
- http://www.adobe.com/go/acrobat_system_reqs_hr
- http://www.adobe.com/go/acrobat_system_reqs_cz
- http://www.adobe.com/go/acrobat_system_reqs_dk
- http://www.adobe.com/go/acrobat_system_reqs_nl
- http://www.adobe.com/go/acrobat_system_reqs_fi
- http://www.adobe.com/go/acrobat_system_reqs_fr
- http://www.adobe.com/go/acrobat_system_reqs_de
- http://www.adobe.com/go/acrobat_system_reqs_il
- http://www.adobe.com/go/acrobat_system_reqs_hu
Embedded domains
- schemas.microsoft.com
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- cacerts.digicert.com
- d.symcb.com
- s.symcb.com
- ts-crl.ws.symantec.com
- ts-aia.ws.symantec.com
- www.adobe.com
- afsluttes.se
- avsluttes.se
Embedded IP addresses
- 52.182.141.63
- 52.123.252.198
- 20.247.184.142
- 57.154.63.210
- 4.230.171.124
- 20.42.179.192
- 52.123.252.203
- 20.165.94.63
- 135.233.95.135
- 52.168.117.174
- 20.231.239.246
- 52.123.128.14
- 52.123.129.14
- 203.26.79.13
- 20.42.73.27
- 40.79.141.154
- 135.234.160.245
- 52.123.252.248
- 135.233.95.80
- 52.123.252.223
- 52.148.114.188
- 72.145.35.105
- 92.223.78.30
- 52.110.12.18
- 52.110.12.56
File paths
- D:\DCB\CBT_Main\Acrobat\Installers\BootStrapExe_Small\Release\Setup.pdb
- f:\dd\vctools\vc7libs\ship\atlmfc\include\afxwin2.inl
- f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\array_s.cpp
- f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp
- f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\appcore.cpp
More FuBu samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report