MALICIOUS — 9979db5caf2def9ae1f73d66579599d4a10a8b4246ad174c58f6a0e415a022cb
MALICIOUS — 9979db5caf2def9ae1f73d66579599d4a10a8b4246ad174c58f6a0e415a022cb is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Ulise family. 8 of 52 detection engines flagged it.
Identification
- SHA-256:
9979db5caf2def9ae1f73d66579599d4a10a8b4246ad174c58f6a0e415a022cb - SHA-1:
e8a794d587c982a24de438bbecb440b232d32cd6 - MD5:
73f1d46abda926bcc450f72bb7231a75 - imphash:
68864e2c52b98624974843d1b22a695b - ssdeep:
12288:CzCr6D+2OkeG9F1xk1kwZRo5FbDFBQX6f6AkdIAELARixZFDul:Cza2OkeG9jxyTo5Fbz/zkOLLARixXDul - TLSH:
T1434A23D806A6B310E1FA3777DB48D98D10D165F3686D203512C7532FA2E609BAE5A323 - Submitted as: 9979db5caf2def9ae1f73d66579599d4a10a8b4246ad174c58f6a0e415a022cb
- File type: pe · Size: 441280 bytes
- Verdict: malicious (97/100) · Family: Ulise
Detections (8 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): ASPack
- ClamAV (daily): Win.Malware.Ulise-9806872-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:ASProtect SKE 2.72+
- LIEF (executable format parser): lief:invalid-authenticode
- Microsoft Defender: Trojan:Win32/Tonmye!pz
- Kaspersky (KVRT): HEUR:Trojan.Win32.AddUser.gen
Why this verdict
The malicious score of 97/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Malware.Ulise-9806872-0 (rule
Win.Malware.Ulise-9806872-0) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:ASProtect SKE 2.72+ (rule
DIE:ASProtect SKE 2.72+) - engine signal, weight 0.35, confidence 0.70 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.360.cn, http://www.eyuyan.com, http://www.360.cn/ - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: ASPack, high-entropy-sections:.text, ASProtect SKE 2.72+, ASPack 2.12-2.42 - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://crl.verisign.com/tss-ca.crl0
- https://www.verisign.com/rpa
- https://www.verisign.com/rpa0
- https://www.verisign.com/cps0*
- http://logo.verisign.com/vslogo.gif0
- http://crl.verisign.com/pca3.crl0
- http://www.360.cn
- http://www.eyuyan.com
- http://www.360.cn/
Embedded domains
- crl.verisign.com
- www.verisign.com
- csc3-2009-2-crl.verisign.com
- csc3-2009-2-aia.verisign.com
- logo.verisign.com
- www.360.cn
- www.eyuyan.com
More Ulise samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report