MALICIOUS — 07ce232c5ca744280c829ebaa1bbf04ff3bae12b08ec7953c7be156b0daae32e
MALICIOUS — 07ce232c5ca744280c829ebaa1bbf04ff3bae12b08ec7953c7be156b0daae32e is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the HUILoader family. 9 of 55 detection engines flagged it.
Identification
- SHA-256:
07ce232c5ca744280c829ebaa1bbf04ff3bae12b08ec7953c7be156b0daae32e - SHA-1:
040cd9a700206a6d06de889b3845dd072fbbe54f - MD5:
c1357bb4a2d4588ef44cc21d6b8753e8 - imphash:
01392ca861cf87b8d28ad9ea90016bb4 - ssdeep:
6144:cDIv+UDIv+5+TyiuhzVCTB92Z1LONIwi8EJN:cbUbAXuhzVCTeiNIw - TLSH:
T147489E8C53217346D2F6D62068ACCE5CA013A8FA317A4B5EA302C33E65E753775395A8 - Submitted as: 07ce232c5ca744280c829ebaa1bbf04ff3bae12b08ec7953c7be156b0daae32e
- File type: pe · Size: 379680 bytes
- Verdict: malicious (96/100) · Family: HUILoader
Detections (9 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): ASPack
- ClamAV (daily): Win.Malware.Generic-9875035-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Worm:Win32/AutoRun!pz
- Emsisoft (Emergency Kit): Gen:Heur.Mint.Autorunner.1
- Trellix Stinger (McAfee): Vindor-FTWO!C1357BB4A2D4
- Kaspersky (KVRT): Worm.Win32.AutoRun.vx
Why this verdict
The malicious score of 96/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Malware.Generic-9875035-0 (rule
Win.Malware.Generic-9875035-0) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.gnu.org/software/coreutils/, http://translationproject.org/team/, http://gnu.org/licenses/gpl.html - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: ASPack, high-entropy-sections:.text, Microsoft Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/windows0
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
- http://www.gnu.org/software/coreutils/
- http://translationproject.org/team/
- http://gnu.org/licenses/gpl.html
- http://www.gnu.org/gethelp/
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://office.microsoft.com
Embedded domains
- www.microsoft.com
- crl.microsoft.com
- www.gnu.org
- translationproject.org
- gnu.org
- cygwin.com
- office.microsoft.com
File paths
- F:\Office\Target\x86\ship\postc2r\x-none\csisyncclient.pdb
- X:\:`:d:l:p:t:x:
- P:\:
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report