MALICIOUS — a46fbd1a76e682c6147b988e4660eabab9e2af577dc7aabb5171c873ab64f866
MALICIOUS — a46fbd1a76e682c6147b988e4660eabab9e2af577dc7aabb5171c873ab64f866 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Ulise family. 10 of 51 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
a46fbd1a76e682c6147b988e4660eabab9e2af577dc7aabb5171c873ab64f866 - SHA-1:
a9dc94555cd96d5513a8b27a0284400a93f37716 - MD5:
6090c5174af28f39ac134b440fc2bb93 - imphash:
9973fdd4b86d866b3faa39fa66cf7e0a - ssdeep:
49152:YsZGsYAI2wQ+LnUZbodvCC5gtHUujpj7AewZqZhRdhJ99zqFExqSjHJ3uTFxhrF3:dGjnU9k6FhHZhZPHbsDV7 - TLSH:
T179675B6230277011E1F9EE60E865889C8063B578B0789DCE820BD48251EDBF7E5F6F56 - Submitted as: a46fbd1a76e682c6147b988e4660eabab9e2af577dc7aabb5171c873ab64f866
- File type: pe · Size: 6763889 bytes
- Verdict: malicious (99/100) · Family: Ulise
Detections (10 of 51 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Ransomware.Ulise-9978047-0
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: Trellix/McAfee ATR: ATR_REvil_Sodinokibi
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Worm:Win32/Xolxo.A
- Emsisoft (Emergency Kit): Gen:Variant.Virus.Delf.1
- Kaspersky (KVRT): P2P-Worm.Win32.Delf.aj
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 99/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Win.Ransomware.Ulise-9978047-0 (rule
Win.Ransomware.Ulise-9978047-0) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - YARA: Trellix/McAfee ATR flagged ATR_REvil_Sodinokibi (rule
ATR_REvil_Sodinokibi) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.gnu.org/software/coreutils/, http://translationproject.org/team/, http://gnu.org/licenses/gpl.html - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: UPX - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - inject code into another process (rule
inject code into another process) - capa signal, weight 0.12, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/windows0
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-cs-g1.crl05
- http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
- http://www.gnu.org/software/coreutils/
- http://translationproject.org/team/
- http://gnu.org/licenses/gpl.html
- http://www.gnu.org/gethelp/
- https://clients2.google.com/cr/report
- http://www.digicert.com/CPS0
- https://crashpad.chromium.org/
- https://crashpad.chromium.org/bug/new
- http://go.microsoft.com/fwlink/?LinkId=33171&PartnerId=258
Embedded domains
- schemas.microsoft.com
- www.microsoft.com
- crl.microsoft.com
- cacerts.digicert.com
- crl4.digicert.com
- crl3.digicert.com
- www.digicert.com
- www.gnu.org
- translationproject.org
- gnu.org
- cygwin.com
- field.cc
- enter.cc
- core.cc
- dispatcher.cc
- blink.net
- thunks.cc
- node.cc
- openssl.org
- clients2.google.com
- settings.cc
- thread.cc
- crashpad.chromium.org
- arena.cc
- common.cc
File paths
- C:\My
- C:\Windows\SoftwareDistribution\Download\467d4844b1a06f896633937df86f641f\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.18715_none_6e38b8da126
- C:\Program
- c:\jenkins\workspace\8-2-build-windows-amd64-cygwin\jdk8u281\880\build\windows-amd64\jdk\objs\rmiregistry_objs\rmiregistry.pdb
- C:\cygwin64\bin\pr.exe
- c:\jenkins\workspace\8-2-build-windows-amd64-cygwin\jdk8u281\880\build\windows-amd64\jdk\objs\keytool_objs\keytool.pdb
- c:\jenkins\workspace\8-2-build-windows-amd64-cygwin\jdk8u281\880\build\windows-amd64\jdk\objs\servertool_objs\servertool.pdb
- R:\Sg
- C:\cygwin64\bin\comm.exe
More Ulise samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report