SUSPICIOUS — 0ac20275a4568a688b35b219f5ad983888e3fd6c4e714a63ced1b77a719259ab
SUSPICIOUS — 0ac20275a4568a688b35b219f5ad983888e3fd6c4e714a63ced1b77a719259ab is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (55/100), attributed to the HUILoader family. 3 of 52 detection engines flagged it.
Identification
- SHA-256:
0ac20275a4568a688b35b219f5ad983888e3fd6c4e714a63ced1b77a719259ab - SHA-1:
7961acce88ea93a55a9cd9f7b19535c579ab5074 - MD5:
eff3a1663f893acdd9e8ac02d5e6091c - imphash:
a6e4db6d0301308509a7f5737a79f454 - ssdeep:
6144:wQeNai17Y56rKnBfWhveajzxwIEWVnk5kPFOM+jDAD6Whzr8SfxL/2Dc33Cy:wQeN/7YkrWBfWhvRhTVSkiUmAwSfxL/B - TLSH:
T12649AE8D81051786E1B1CB652A8C4E4D1063F8DE617A298CA28BD41E33FDD97A07D2FD - Submitted as: 0ac20275a4568a688b35b219f5ad983888e3fd6c4e714a63ced1b77a719259ab
- File type: pe · Size: 388608 bytes
- Verdict: suspicious (55/100) · Family: HUILoader
Detections (3 of 52 engines)
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: flagged
Why this verdict
The suspicious score of 55/100 is the fusion of 3 weighted signals:
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.symauth.com/cps0, http://www.symauth.com/rpa04, http://www.symauth.com/cps09 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://crl.thawte.com/ThawteTimestampingCA.crl0
- http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
- http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
- http://crl.verisign.com/pca3.crl0
- https://www.verisign.com/cps0
- http://logo.verisign.com/vslogo.gif04
- http://www.symauth.com/cps0
- http://www.symauth.com/rpa04
- http://crl.verisign.com/pca3-g5.crl0
- http://www.symauth.com/cps09
- http://evcs-crl.ws.symantec.com/evcs.crl0
- http://evcs-aia.ws.symantec.com/evcs.cer0
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/windows0
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
Embedded domains
- crl.thawte.com
- ts-aia.ws.symantec.com
- ts-crl.ws.symantec.com
- crl.verisign.com
- www.verisign.com
- logo.verisign.com
- www.symauth.com
- evcs-crl.ws.symantec.com
- evcs-aia.ws.symantec.com
- www.microsoft.com
- crl.microsoft.com
File paths
- C:\\cygwin64\bin\grops.exe
- C:\\Program
- f:\CB\ARM_Sustaining\BuildResults\bin\Win32\Release\armsvc.pdb
- C:\\$SysReset\Scratch\csrss.exe
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report