MALICIOUS — f09acd52c1e554fa254bb0a23fca262055a797382595c3a034fdfda039fc534f
MALICIOUS — f09acd52c1e554fa254bb0a23fca262055a797382595c3a034fdfda039fc534f is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Zusy family. 8 of 51 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
f09acd52c1e554fa254bb0a23fca262055a797382595c3a034fdfda039fc534f - SHA-1:
565f4ca590dd84049fe89b824fb9f9dead78a602 - MD5:
24bc7bce4750a1b77cab88431cd2632f - imphash:
98dfd9b9e184a03c6ea488ca38f4797e - ssdeep:
196608:PUKKAsn9T3n9TBfUefUzn9Tin9T/n9To:Mb1zFScJ+ - TLSH:
T13C6BD08204176062E5F3ECD468502D7C4821F56D6EF4A9CC9302C95E50DBEBBE9EA13B - Submitted as: f09acd52c1e554fa254bb0a23fca262055a797382595c3a034fdfda039fc534f
- File type: pe · Size: 10424144 bytes
- Verdict: malicious (98/100) · Family: Zusy
Detections (8 of 51 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- ClamAV (daily): Win.Malware.Zusy-9875693-0
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Virus:Win32/Antitcpa.A
- Emsisoft (Emergency Kit): Gen:Variant.Razy.666238
- Kaspersky (KVRT): Virus.Win32.HLLP.Atcpa
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 98/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Malware.Zusy-9875693-0 (rule
Win.Malware.Zusy-9875693-0) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://antitcpa.alsherok.net/, http://th.symcb.com/th.crl0, https://www.thawte.com/cps0/ - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - inject code into another process (rule
inject code into another process) - capa signal, weight 0.12, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://antitcpa.alsherok.net/
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-cs-g1.crl05
- http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
- http://www.digicert.com/ssl-cps-repository.htm0
- http://crl.thawte.com/ThawteTimestampingCA.crl0
- http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
- http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
- http://www.w3.org/2000/09/xmldsig#
- http://www.w3.org/2001/XMLSchema-instance
- http://www.w3.org/2000/09/xmldsig#sha1
- http://www.w3.org/2001/10/xml-exc-c14n#
- http://www.w3.org/2000/09/xmldsig#rsa-sha1
- http://www.w3.org/2000/09/xmldsig#enveloped-signature
- http://schemas.microsoft.com/windows/rel/2005/reldata
- http://schemas.microsoft.com/windows/pki/2005/Authenticode
- http://crl.thawte.com/ThawtePCA.crl0
- http://th.symcb.com/th.crl0
- https://www.thawte.com/cps0/
- https://www.thawte.com/repository0W
- http://th.symcb.com/th.crt0
- https://d.symcb.com/rpa0
Embedded domains
- www.debian.org
- antitcpa.alsherok.net
- mb.fi
- www.microsoft.com
- crl.microsoft.com
- schemas.microsoft.com
- cacerts.digicert.com
- crl4.digicert.com
- crl3.digicert.com
- www.digicert.com
- crl.thawte.com
- ts-aia.ws.symantec.com
- ts-crl.ws.symantec.com
- www.w3.org
- crl.usertrust.com
- th.symcb.com
- www.thawte.com
- d.symcb.com
- sv.symcb.com
- www.symauth.com
- s1.symcb.com
Embedded IP addresses
- 1.12.1.1
- 1.12.1.9
File paths
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System\37a1d51f35918dd36a0d4e34cc91732e\System.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Ga41585c2#\7145367d78cd9d75b5533cec821c7353\Microsoft.GroupPolicy.AdmTmplEditor.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\7e5e0d92b127a5150606d81839f29044\System.Drawing.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\028f9e8b0c8b1820df7bec952b01fe12\System.Windows.Forms.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\89bc329e8c65a9e13067c9776d925d78\System.Core.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\b5152c3c02957bbe4459505a39afde20\System.Configuration.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\1fb6db2ce6d2887fe6f8f620cb092343\System.Xml.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Accessibility\21911640a598b9b50a75e4b9b6330330\Accessibility.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\TaskScheduler\8f05bc8ead96f927b70dd88a9cb115ca\TaskScheduler.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\MIGUIControls\f3a17d2bfc42f22de1ee5f79808438e5\MIGUIControls.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\CustomMarshalers\38aff4f93ebb48cb7a316d01b4a806f7\CustomMarshalers.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\2bef38851483abae82f1172c1aaa604c\System.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\9d04ce1d8a3042f50b54c7f9ccdb4068\System.Core.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\fea996c385fbc624826f8e043f6d5329\System.Management.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wad78daf4#\8f73bd36654fa77803c3167f39ead17e\Microsoft.Windows.Diagnosis.SDHost.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wed3937f9#\3dae65a1b718d3a083094b67e1413e9a\Microsoft.Windows.Diagnosis.SDCommon.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\f02732d562721457afde5c189a906d17\System.Management.Automation.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.W0bb5dac4#\4c396dcf426dbba8eddd04adc0b562fe\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.W69ef49d2#\9dcd27fe1c298162f13c6bdb7c0cfe88\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wd518ee0d#\e9bd08c5c1a8c5fdef45c7025b262edc\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.W708fc392#\3c226a9afdce13116b1fdfa9e92b4152\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.W79a81d80#\2efe3e39ab8a210a684558961ff266d2\Microsoft.Windows.Diagnosis.Commands.WriteDiagTelemetry.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.P1706cafe#\16ab851088227b0798b233d026a1019e\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Confe64a9051#\29c26981c4b4347ca371002934f6f2ac\System.Configuration.Install.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Pb378ec07#\dac77e2bdc0040a1a2a446cbf77b6bae\Microsoft.PowerShell.ConsoleHost.ni.dll
More Zusy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report