winsaber.exe

Dening Hu

The application winsaber.exe by Dening Hu has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “winsaber”. While running, it connects to the Internet address server-52-84-25-115.sea32.r.cloudfront.net on port 80 using the HTTP protocol.
Publisher:
Dening Hu  (signed and verified)

MD5:
c37f2920c0b99df758573ec90d888013

SHA-1:
745d6228f26b6c7972deaec733d1416c10f0f4a9

SHA-256:
1fcfc50713aa8ede55d64d3c9d8daba4d4fc61fb4dce94e1d2f308497498feec

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/5/2024 2:25:20 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex (M)
16.10.10.3

File size:
856.7 KB (877,272 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\winsaber\winsaber.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
10/10/2016 7:00:00 AM

Valid to:
6/9/2017 6:59:59 AM

Subject:
CN=Dening Hu, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
7A2DF2BB7E9010EDF9FC306983C02B4D

File PE Metadata
Compilation timestamp:
10/10/2016 9:20:24 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:ILB32yNcV4K1ufyFQ2eEeImhCzMpPleI4UN+RO:SaufadBeIm5uI4U8RO

Entry address:
0x56EFA

Entry point:
E8, 07, 2C, 01, 00, E9, 39, FE, FF, FF, E8, C0, 42, 00, 00, 85, C0, 75, 06, B8, 54, EB, 4B, 00, C3, 83, C0, 0C, C3, 55, 8B, EC, 56, E8, E4, FF, FF, FF, 8B, 4D, 08, 51, 89, 08, E8, 66, 00, 00, 00, 59, 8B, F0, E8, 05, 00, 00, 00, 89, 30, 5E, 5D, C3, E8, 8C, 42, 00, 00, 85, C0, 75, 06, B8, 50, EB, 4B, 00, C3, 83, C0, 08, C3, 55, 8B, EC, 56, 8B, 75, 08, 85, F6, 75, 0A, E8, 2C, 06, 00, 00, 6A, 16, 58, EB, 0B, E8, 9F, FF, FF, FF, 8B, 00, 89, 06, 33, C0, 5E, 5D, C3, 55, 8B, EC, 56, 8B, 75, 08, 85, F6, 75, 0A, E8...
 
[+]

Entropy:
6.2859

Code size:
655.5 KB (671,232 bytes)

Service
Display name:
winsaber

Type:
Win32OwnProcess


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-54-230-216-87.mrs50.r.cloudfront.net  (54.230.216.87:80)

TCP (HTTP):
Connects to server-54-230-216-205.mrs50.r.cloudfront.net  (54.230.216.205:80)

TCP (HTTP):
Connects to server-54-230-163-33.jax1.r.cloudfront.net  (54.230.163.33:80)

TCP (HTTP):
Connects to server-54-230-122-60.dfw50.r.cloudfront.net  (54.230.122.60:80)

TCP (HTTP):
Connects to server-52-84-126-101.iad16.r.cloudfront.net  (52.84.126.101:80)

TCP (HTTP):
Connects to server-52-84-246-72.sfo20.r.cloudfront.net  (52.84.246.72:80)

TCP (HTTP):
Connects to server-52-84-246-244.sfo20.r.cloudfront.net  (52.84.246.244:80)

TCP (HTTP):
Connects to server-52-84-132-244.atl52.r.cloudfront.net  (52.84.132.244:80)

TCP (HTTP):
Connects to server-52-84-25-115.sea32.r.cloudfront.net  (52.84.25.115:80)

TCP (HTTP):
Connects to server-52-85-173-240.fra6.r.cloudfront.net  (52.85.173.240:80)

TCP (HTTP):
Connects to server-52-85-173-22.fra6.r.cloudfront.net  (52.85.173.22:80)

TCP (HTTP):
Connects to server-54-230-216-149.mrs50.r.cloudfront.net  (54.230.216.149:80)

TCP (HTTP):
Connects to server-52-85-133-63.iad53.r.cloudfront.net  (52.85.133.63:80)

TCP (HTTP):
Connects to server-52-84-25-40.sea32.r.cloudfront.net  (52.84.25.40:80)

TCP (HTTP):
Connects to server-52-84-25-240.sea32.r.cloudfront.net  (52.84.25.240:80)

TCP (HTTP):
Connects to server-54-192-36-29.jfk1.r.cloudfront.net  (54.192.36.29:80)

TCP (HTTP):
Connects to server-52-85-133-82.iad53.r.cloudfront.net  (52.85.133.82:80)

TCP (HTTP):
Connects to server-52-85-133-26.iad53.r.cloudfront.net  (52.85.133.26:80)

TCP (HTTP):
Connects to server-52-85-133-160.iad53.r.cloudfront.net  (52.85.133.160:80)

TCP (HTTP):
Connects to server-52-85-133-115.iad53.r.cloudfront.net  (52.85.133.115:80)

Remove winsaber.exe - Powered by Reason Core Security