MALICIOUS — 2438779c375d622307c64d4b88ba3672494d08cf689f5acfcab5df93ef19bada
MALICIOUS — 2438779c375d622307c64d4b88ba3672494d08cf689f5acfcab5df93ef19bada is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the HUILoader family. 5 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2438779c375d622307c64d4b88ba3672494d08cf689f5acfcab5df93ef19bada - SHA-1:
44fb79503503361d474c65df87ad54d2644cbd35 - MD5:
aab50cd2f9571aaf1834b4599595d677 - imphash:
7561708a4d76393e3992ac2ea91e3cf6 - ssdeep:
49152:h+5iYUHF+3j5D78OBUocq8CXJlfmXtPT:IiYYCs1XCzeN - TLSH:
T1E659CFDD410B2611D2FEEE10A8148CAD8813F09C6075678C574BEA7E14F5E3BE9F906A - Submitted as: 2438779c375d622307c64d4b88ba3672494d08cf689f5acfcab5df93ef19bada
- File type: pe · Size: 1824296 bytes
- Verdict: malicious (97/100) · Family: HUILoader
Detections (5 of 51 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Malware.Genpack-9875154-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Trellix/McAfee ATR: ATR_LockBit_Ransomware
- YARA: Yara-Rules community: YR_AntiDebug_Checks
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Malware.Genpack-9875154-0 (rule
Win.Malware.Genpack-9875154-0) - engine signal, weight 0.90, confidence 0.95 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Trellix/McAfee ATR flagged ATR_LockBit_Ransomware (rule
ATR_LockBit_Ransomware) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://creativecommons.org/publicdomain/zero/1.0/, https://www.gnu.org/software/automake/manual/automake.html, http://fsmsh.com/2753 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- https://www.gnu.org/software/automake/manual/automake.html
- http://fsmsh.com/2753
- https://autotools.io/index.html
- http://miller.emu.id.au/pmiller/books/rmch/
- http://crl.thawte.com/ThawteTimestampingCA.crl0
- http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
- http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
- http://ocsp.startssl.com/ca00
- http://aia.startssl.com/certs/ca.crt02
- http://crl.startssl.com/sfsca.crl0C
- http://www.startssl.com/policy.pdf0
- http://crl.startssl.com/crtc2-crl.crl0
- http://ocsp.startssl.com/sub/class2/code/ca0@
- http://www.startssl.com/0
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
Embedded domains
- creativecommons.org
- geocities.com
- www.gnu.org
- fsmsh.com
- autotools.io
- miller.emu.id.au
- crl.thawte.com
- ts-aia.ws.symantec.com
- ts-crl.ws.symantec.com
- ocsp.startssl.com
- aia.startssl.com
- crl.startssl.com
- www.startssl.com
- sub.class2.code.ca
- schemas.microsoft.com
- www.drdump.com
File paths
- C:\Users\
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report