saber.exe

Dening Hu

The application saber.exe by Dening Hu has been detected as a potentially unwanted program by 3 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Tsydm-winex-23121”. While running, it connects to the Internet address server-54-230-51-96.jfk5.r.cloudfront.net on port 80 using the HTTP protocol.
Publisher:
Dening Hu  (signed and verified)

MD5:
6d6398cd62a116ca67d4265588d2dee7

SHA-1:
d8ec9994a7860a0f785db75e8c54f09448c6cd90

SHA-256:
e59dc3230e17ce1c42faaf37bb0237b740cba7f14fdffe5a3eedac07f11f8ad2

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
12/24/2024 1:38:14 AM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
HEUR/QVM10.1.0000.Malware.Gen
1.0.0.1120

Reason Heuristics
PUP.Elex (M)
16.8.1.9

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

File size:
506.2 KB (518,360 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\reoicult\saber.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
6/8/2016 7:00:00 AM

Valid to:
6/9/2017 6:59:59 AM

Subject:
CN=Dening Hu, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
1526014E3F697DCED61C390661163B6C

File PE Metadata
Compilation timestamp:
6/27/2016 12:16:05 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:4bG3FN8LJxZEouF+TKUJKCR9NyFCKUztLSNU+Gcrf:4bG3FN8xuF/xCR9NyFCfNiGcrf

Entry address:
0x363CC

Entry point:
E8, 3D, AC, 00, 00, E9, 7F, FE, FF, FF, E8, 6C, 45, 00, 00, 85, C0, 75, 06, B8, A4, E4, 46, 00, C3, 83, C0, 0C, C3, 55, 8B, EC, 56, E8, E4, FF, FF, FF, 8B, 4D, 08, 51, 89, 08, E8, 20, 00, 00, 00, 59, 8B, F0, E8, 05, 00, 00, 00, 89, 30, 5E, 5D, C3, E8, 38, 45, 00, 00, 85, C0, 75, 06, B8, A0, E4, 46, 00, C3, 83, C0, 08, C3, 55, 8B, EC, 8B, 4D, 08, 33, C0, 3B, 0C, C5, 38, E3, 46, 00, 74, 27, 40, 83, F8, 2D, 72, F1, 8D, 41, ED, 83, F8, 11, 77, 05, 6A, 0D, 58, 5D, C3, 8D, 81, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8...
 
[+]

Entropy:
6.1725

Code size:
363.5 KB (372,224 bytes)

10 Services
Display name:
Tsydm-winex-23121

Service name:
winsaber

Type:
Win32OwnProcess

Display name:
Tsydm-winex-23177

Service name:
winsaber

Type:
Win32OwnProcess

Display name:
Tsydm-winex-23108

Service name:
winsaber

Type:
Win32OwnProcess

Display name:
Tsydm-winex-23131

Service name:
winsaber

Type:
Win32OwnProcess

Display name:
Tsydm-winex-22991

Service name:
winsaber

Type:
Win32OwnProcess

Display name:
Tsydm-winex-23167

Service name:
winsaber

Type:
Win32OwnProcess


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-54-230-51-138.jfk5.r.cloudfront.net  (54.230.51.138:80)

TCP (HTTP):
Connects to server-52-85-94-174.jfk5.r.cloudfront.net  (52.85.94.174:80)

TCP (HTTP):
Connects to server-54-230-51-165.jfk5.r.cloudfront.net  (54.230.51.165:80)

TCP (HTTP):
Connects to server-54-230-163-28.jax1.r.cloudfront.net  (54.230.163.28:80)

TCP (HTTP):
Connects to server-52-85-94-252.jfk5.r.cloudfront.net  (52.85.94.252:80)

TCP (HTTP):
Connects to server-52-84-87-219.yul62.r.cloudfront.net  (52.84.87.219:80)

TCP (HTTP):
Connects to server-52-84-87-175.yul62.r.cloudfront.net  (52.84.87.175:80)

TCP (HTTP):
Connects to server-54-230-51-193.jfk5.r.cloudfront.net  (54.230.51.193:80)

TCP (HTTP):
Connects to server-52-85-94-250.jfk5.r.cloudfront.net  (52.85.94.250:80)

TCP (HTTP):
Connects to server-52-85-94-156.jfk5.r.cloudfront.net  (52.85.94.156:80)

TCP (HTTP):
Connects to server-54-230-51-149.jfk5.r.cloudfront.net  (54.230.51.149:80)

TCP (HTTP):
Connects to server-52-85-94-119.jfk5.r.cloudfront.net  (52.85.94.119:80)

TCP (HTTP):
Connects to server-54-230-5-57.dfw3.r.cloudfront.net  (54.230.5.57:80)

TCP (HTTP):
Connects to server-54-192-51-190.jfk5.r.cloudfront.net  (54.192.51.190:80)

TCP (HTTP):
Connects to server-54-230-51-35.jfk5.r.cloudfront.net  (54.230.51.35:80)

TCP (HTTP):
Connects to server-54-230-51-231.jfk5.r.cloudfront.net  (54.230.51.231:80)

TCP (HTTP):
Connects to server-54-230-51-217.jfk5.r.cloudfront.net  (54.230.51.217:80)

TCP (HTTP):
Connects to server-52-85-94-218.jfk5.r.cloudfront.net  (52.85.94.218:80)

TCP (HTTP):
Connects to server-54-230-51-86.jfk5.r.cloudfront.net  (54.230.51.86:80)

TCP (HTTP):
Connects to server-54-192-36-253.jfk1.r.cloudfront.net  (54.192.36.253:80)

Remove saber.exe - Powered by Reason Core Security