MALICIOUS — 0207060c5611cfac6ede7c0ce643b29be14fd9bcd3304f5728deacfc37b32c03
MALICIOUS — 0207060c5611cfac6ede7c0ce643b29be14fd9bcd3304f5728deacfc37b32c03 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the HUILoader family. 5 of 56 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
0207060c5611cfac6ede7c0ce643b29be14fd9bcd3304f5728deacfc37b32c03 - SHA-1:
2f07082070de9f3089ed879ce78ababa10e46452 - MD5:
b8331e1b67ade1d18114e801d3db9198 - imphash:
68008b0072eac0c79e8f98a8f9b60f70 - ssdeep:
24576:4oRLRu55goRLjNppoR7doGw1oRpLJYIdoRcsrPEUpoRt3MAVu3oRh2iIV+tOoRp:Iydz/f8rEUGMbjiKUdr/6rrIjD - TLSH:
T1A45CD09E3F1B2202CBF4D114DD127DAD222A64A468AD784EC54A953C5EF10F39A63C27 - Submitted as: 0207060c5611cfac6ede7c0ce643b29be14fd9bcd3304f5728deacfc37b32c03
- File type: pe · Size: 2412544 bytes
- Verdict: malicious (99/100) · Family: HUILoader
Detections (5 of 56 engines)
- capa (capabilities): capability:collection/keylog
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Emsisoft (Emergency Kit): Gen:Variant.Adware.GenericFCA.1848
- Kaspersky (KVRT): UDS:Trojan.Win32.Injuke.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 14 weighted signals:
- Emsisoft (Emergency Kit) flagged Gen:Variant.Adware.GenericFCA.1848 (rule
Gen:Variant.Adware.GenericFCA.1848) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:Trojan.Win32.Injuke.gen (rule
UDS:Trojan.Win32.Injuke.gen) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s) across 1 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 17 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082, T1622, T1497, T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- capa (capabilities) flagged capability:collection/keylog (rule
capability:collection/keylog) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-sections:.text (rule
high-entropy-sections:.text) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://www.izarc.org, https://www.virustotal.com/en/about/privacy - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
24071 behavior events · 2 ATT&CK techniques · 4 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- nikolakigreate.live
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
Dropped files
- c20d694cf12394e6f37a48933efb48e0584ec88dff76fce9c5e0c1adee40851c -
c20d694cf12394e6f37a48933efb48e0584ec88dff76fce9c5e0c1adee40851c - f1ee954a9e96a52bfdba42b832ee068811c4080fae967241fe2820fa65ebeb70 -
f1ee954a9e96a52bfdba42b832ee068811c4080fae967241fe2820fa65ebeb70 - 844770449b2d14abbd61263ce0b32201a312cbf1c9765312d8f7b828d022306a -
844770449b2d14abbd61263ce0b32201a312cbf1c9765312d8f7b828d022306a - 0921ca3c8caf5b5ecf4642a011f0d77d7e279227cf59e6fc2006614a77b1411c -
0921ca3c8caf5b5ecf4642a011f0d77d7e279227cf59e6fc2006614a77b1411c
Embedded URLs
- https://www.izarc.org
- https://www.virustotal.com/en/about/privacy
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- www.izarc.org
- izarc.org
- www.virustotal.com
- nikolakigreate.live
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 20.42.73.28
- 4.230.171.124
- 57.154.63.210
- 74.178.240.61
- 74.178.240.51
- 40.79.141.153
- 20.247.184.197
- 52.168.112.67
- 20.42.179.192
- 72.153.5.134
- 52.148.114.188
- 52.110.12.2
- 52.110.12.51
File paths
- u:\3
- D:\Programming\Projects\IZArc
- C:\Users\Administrator\AppData\Local\Temp\
- C:\WINDOWS\System32\
- C:\Windows\system32\
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report