MALICIOUS — 29f283507b101a6c82b5399e08abd63f44144dce3491dfb3c3a81b9a95efaaf5
MALICIOUS — 29f283507b101a6c82b5399e08abd63f44144dce3491dfb3c3a81b9a95efaaf5 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (82/100), attributed to the HUILoader family. 6 of 55 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
29f283507b101a6c82b5399e08abd63f44144dce3491dfb3c3a81b9a95efaaf5 - SHA-1:
9ea1b4b2dd5f129de864e02bcec60f188da0cfa4 - MD5:
f85fd594ec76515a39c65cb4d2ad4938 - imphash:
7af2fe87a3ab930007d141d21c36ceda - ssdeep:
196608:xW5PhdAAZiVqnJLWe20OIzpRUMSSaL98N+G:xW7dAhcYCpRbCCP - TLSH:
T1A26D9EE99108321BDDF2EA1229818A5F347398E9E4751D69AED7C14763B8CBBD03431C - Submitted as: 29f283507b101a6c82b5399e08abd63f44144dce3491dfb3c3a81b9a95efaaf5
- File type: pe · Size: 12654373 bytes
- Verdict: malicious (82/100) · Family: HUILoader
Detections (6 of 55 engines)
- capa (capabilities): capability:collection/keylog
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Kaspersky (KVRT): HEUR:Backdoor.OSX.Agent.n
MITRE ATT&CK
Why this verdict
The malicious score of 82/100 is the fusion of 8 weighted signals:
- capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://python.org/dev/peps/pep-0263/, http://curl.haxx.se/rfc/cookie_spec.html, http://wwwsearch.sf.net/ - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://python.org/dev/peps/pep-0263/
- http://curl.haxx.se/rfc/cookie_spec.html
- http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd
- http://wwwsearch.sf.net/
- http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd
- http://ucsub.colorado.edu/~kominek/rot13/
- http://lists.sourceforge.net/lists/listinfo/optik-users
- http://www.rgaros.nl/gestalt/
- http://www.apple.com/DTDs/PropertyList-1.0.dtd
- http://en.wikipedia.org/wiki/Triangular_distribution
- http://www.faqs.org/rfcs/rfc2822.html
- http://www.faqs.org/rfcs/rfc822.html
- http://www.iana.org/assignments/tls-parameters/tls-parameters.xml#tls-parameters-6
- http://tools.ietf.org/html/rfc6125#section-6.4.3
- http://bugs.python.org/issue2550
- http://msdn2.microsoft.com/en-us/library/ms740621
- http://docs.python.org/library/unittest.html
- http://www.w3.org/pub/WWW/Addressing/Overview.html
- http://www.w3.org/pub/WWW/Protocols/
- http://www.python.org/
- http://proxy.example.com/
- http://proxy.example.com:3128/
- http://joe:password@proxy.example.com/
- http://joe:password@proxy.example.com:3128
- http://joe:password@proxy.example.com
Embedded domains
- command.com
- x.name
- python.org
- r.name
- curl.haxx.se
- www.w3.org
- lemburg.com
- wwwsearch.sf.net
- x.y.com
- a.b.c.com
- c.com
- www.acme.com
- acme.com
- test.name
- nightshade.la.mastaler.com
- skippinet.com.au
- acm.org
- ucsub.colorado.edu
- v.loewis.de
- sweetapp.com
- ftp.python.org
- lfw.org
- gmail.com
- zen.co.uk
- pitrou.net
Embedded IP addresses
- 123.45.67.89
- 0.2.4.6
- 2.7.227.1
- 1.9.16.1
- 1.12.1.3
- 1.12.1.6
- 1.12.1.5
- 1.12.1.4
- 1.12.1.2
- 1.12.1.1
- 1.101.3.4
- 1.7.1.1
- 1.9.16.3
- 1.101.2.1
- 3.2.8.1
- 1.1.2.1
- 1.9.15.1
- 10.3.3.1
- 10.3.4.1
- 5.2.3.5
- 10.3.5.1
- 10.3.33.1
- 10.3.33.2
- 10.3.33.3
- 10.3.33.4
File paths
- R:\Sg
- C:\build27\cpython\PCBuild\python27.pdb
- V:\:}:
- W:\:
- X:\:
- K:\:i:z:
- X:\:`:d:h:l:p:t:x:
- X:\:`:d:h:l:p:t:)
- S:\:j:q:
- F:\:
- T:\:a:f:k:q:z:
- D:\:t:
- D:\:
- X:\:h:l:p:,=4=
- X:\:`:
- X:\:d:h:l:t:x:
- X:\:d:
- X:\:h:l:x:
- T:\:`:d:l:p:t:
- C:\Python27\lib\site-packages\py2exe\boot_common.pyR
- C:\Python27\lib\site-packages\py2exe\boot_common.pyt
- C:\bint
- c:\temps
- c:\tmps
- C:\build27\cpython\PCBuild\_ctypes.pdb
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report