MALICIOUS — b3706028f17600ac3803c69ba8bf92f182c0e365d2b2cf8ea3748b7d7bb60585
MALICIOUS — b3706028f17600ac3803c69ba8bf92f182c0e365d2b2cf8ea3748b7d7bb60585 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the FuBu family. 5 of 55 detection engines flagged it.
Identification
- SHA-256:
b3706028f17600ac3803c69ba8bf92f182c0e365d2b2cf8ea3748b7d7bb60585 - SHA-1:
193a1892f3ad74911a2bcfc0684b836a160bb49b - MD5:
eb10435f2573d6ad195198ae87d403ca - imphash:
77f13bc24efea5a05601b43cf44d1f1a - ssdeep:
98304:qEkvY/EkvYEEkvYEEkvYEEkvYEEkvYnEkvYnEkvYEEkvY:XGY8GYdGYdGYdGYdGYEGYEGYdGY - TLSH:
T1F7628DEA02075661F1F3AFDA4C618E4E1427B0FE50B405CC8383D86DB6E5CD7A8B2656 - Submitted as: b3706028f17600ac3803c69ba8bf92f182c0e365d2b2cf8ea3748b7d7bb60585
- File type: pe · Size: 4519161 bytes
- Verdict: malicious (91/100) · Family: FuBu
Detections (5 of 55 engines)
- ClamAV (daily): Win.Trojan.FuBu-1
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Virus:Win32/Shodi
- Emsisoft (Emergency Kit): Win32.HLLP.Shodi.A
- Kaspersky (KVRT): Virus.Win32.HLLP.Shodi.a
Why this verdict
The malicious score of 91/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Trojan.FuBu-1 (rule
Win.Trojan.FuBu-1) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 8.0.251.8 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-cs-g1.crl05
- http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
Embedded domains
- cacerts.digicert.com
- crl4.digicert.com
- crl3.digicert.com
- www.digicert.com
Embedded IP addresses
- 8.0.251.8
File paths
- c:\jenkins\workspace\8-2-build-windows-amd64-cygwin\jdk8u251\737\build\windows-amd64\jdk\objs\javaw_objs\javaw.pdb
More FuBu samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report