MALICIOUS — 2305fa5ace80fa86ca105adcba1ae23932e78c507a9400b48e720501be2a8346
MALICIOUS — 2305fa5ace80fa86ca105adcba1ae23932e78c507a9400b48e720501be2a8346 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100), attributed to the HUILoader family. 4 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2305fa5ace80fa86ca105adcba1ae23932e78c507a9400b48e720501be2a8346 - SHA-1:
028198b1b1495c7a35bdfd8afc10a82ba0a1d40f - MD5:
f18ff2f58e826414269c6e9c9468d8d1 - imphash:
3f34dc1401b498affe4f4057d6ccbb64 - ssdeep:
196608:CkpU9xzn/RNrlHAjoG+II9onJ5hrZEKte9tGPqKNkSEaTb8TLF9e5xcH9D8:DU9xbZxlHOFI9c5hlEKdPN/v3Are5M9 - TLSH:
T15869330E45B1A2E3EAB9F5215DA09CBCCB7EB17DA8B0F11C4583C57810C7867B27164A - Submitted as: 2305fa5ace80fa86ca105adcba1ae23932e78c507a9400b48e720501be2a8346
- File type: pe · Size: 8274019 bytes
- Verdict: malicious (71/100) · Family: HUILoader
Detections (4 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Kaspersky (KVRT): HEUR:Trojan.Python.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 71/100 is the fusion of 5 weighted signals:
- Contacted 18 external host(s) at runtime (16 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Dropped 30 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
1735 behavior events · 0 ATT&CK techniques · 31 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- settings-win.data.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\_MEI16682\api-ms-win-core-datetime-l1-1-0.dll -
3b68d7ab0641de6b3e81d209b7c0d3896e4ffa76617bbadd01eb54036cdd1b07 - C:\Users\analyst\AppData\Local\Temp\_MEI16682\api-ms-win-core-file-l1-1-0.dll -
56de091efe467fe23cc989c1ee21f3249a1bdb2178b51511e3bd514df12c5ccb - C:\Users\analyst\AppData\Local\Temp\_MEI16682\api-ms-win-core-rtlsupport-l1-1-0.dll -
cdc4cfebf9cba85b0d3979befdb258c1f2cfcb79edd00da2dfbf389d080e4379 - C:\Users\analyst\AppData\Local\Temp\_MEI16682\aEo28c-as1iap-Aamjpr-k3jWIT4177A081-523E-11CB-9966-DA86F34BA630Monkid.exe.manifest -
ca620e093ef0e8111fb2d6fd76182afbeda8f2784263579d2ca85831d72a8590 - C:\Users\analyst\AppData\Local\Temp\_MEI16682\api-ms-win-core-processenvironment-l1-1-0.dll -
ea2972fec12305825162ae3e1ae2b6c140e840be0e7ebb51a7a77b7feeda133a - C:\Users\analyst\AppData\Local\Temp\_MEI16682\api-ms-win-core-synch-l1-1-0.dll -
50a1542d16b42ecb3edc1edd0881744171ea52f7155e5269ad39234f0ea691de - C:\Users\analyst\AppData\Local\Temp\_MEI16682\api-ms-win-core-string-l1-1-0.dll -
854db7d2085caacf83d6616761d8bdcbacb54a06c9a9b171b1c1a15e7dc10908 - C:\Users\analyst\AppData\Local\Temp\_MEI16682\api-ms-win-core-libraryloader-l1-1-0.dll -
8e01eb923fc453f927a7eca1c8aa5643e43b360c76b648088f51b31488970aa0 - C:\Users\analyst\AppData\Local\Temp\_MEI16682\api-ms-win-core-console-l1-1-0.dll -
9f3608c15c5de2f577a2220ce124b530825717d778f1e3941e536a3ab691f733 - C:\Users\analyst\AppData\Local\Temp\_MEI16682\api-ms-win-core-debug-l1-1-0.dll -
55574f9e80d313048c245acefd21801d0d6c908a8a5049b4c46253efaf420f89 - C:\Users\analyst\AppData\Local\Temp\_MEI16682\api-ms-win-core-memory-l1-1-0.dll -
c2e887a17875d39099d662a42f58c120b9cc8a799afd87a9e49adf3faddd2b68 - C:\Users\analyst\AppData\Local\Temp\_MEI16682\api-ms-win-crt-heap-l1-1-0.dll -
af47aebe065af2f045a19f20ec7e54a6e73c0c3e9a5108a63095a7232b75381a - C:\Users\analyst\AppData\Local\Temp\_MEI16682\api-ms-win-crt-filesystem-l1-1-0.dll -
610332203d29ab218359e291401bf091bb1db1a6d7ed98ab9a7a9942384b8e27 - C:\Users\analyst\AppData\Local\Temp\_MEI16682\api-ms-win-core-interlocked-l1-1-0.dll -
5cd00ff4731691f81ff528c4b5a2e408548107efc22cc6576048b0fdce3dfbc9 - C:\Users\analyst\AppData\Local\Temp\_MEI16682\api-ms-win-core-localization-l1-2-0.dll -
a07cc878ab5595aacd4ab229a6794513f897bd7ad14bcec353793379146b2094
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787857625&P2=404&P3=2&P4=cu%2f9e3dbw7q763vqc6KkZyaxJgCG6MY3Zqx0zHWqtrxCyH9twu6pCnfkWfaW9CxsWVlM0hR8DcSOviQjW%2bnhlQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- 4.ml
- 6.fi
- t.cn
- 20u.gg
- cryptography.x509.name
Embedded IP addresses
- 13.89.179.15
- 52.123.252.230
- 57.154.63.210
- 4.230.171.124
- 4.144.132.114
- 74.178.76.128
- 135.232.92.97
- 51.104.15.252
- 20.231.239.246
- 52.123.129.14
- 52.123.128.14
- 135.233.45.221
- 203.26.79.13
- 74.178.76.44
- 52.148.114.188
- 52.110.12.52
- 52.110.12.15
- 72.145.35.98
File paths
- C:\-r
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report