Home Malware Programs Malware Luhe.Morphex

Luhe.Morphex

Posted: May 31, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 59
First Seen: May 31, 2012
Last Seen: October 21, 2022
OS(es) Affected: Windows

Luhe.Morphex is known to be a malicious Morphex package that belongs to the Trojan family of Luhe.Morphex and is categorized as malware. In general, the Morphex packer is usually used for packing malware and is used only very occasionally for legitimate software programs. The Morphex packer contains the certain features including execution flow interference, encryption and injection. The first and the last features makes the Morphex packer more suspicious than typical packers, and it's also the reason to give a particular detection name for it, specifically Luhe.Morphex. It's unclear, whether the injection part is incorporated as intended behavior in Luhe.Morphex, or if it's just a component of the payload of the unpacked file. However, numerous Morphex samples that have injection behavior have been noticed. Also, this type of injection is very similar to the DLL component of Duqu. Luhe.Morphex creates a process using a normal system file, and then injects a code to that memory and covers the entry point of the target process.

Technical Details

Additional Information

The following URL's were detected:
softster.site
Loading...