SUSPICIOUS — virussign.com_b2860c08c839b6265fd4889022f72470.vir
SUSPICIOUS — virussign.com_b2860c08c839b6265fd4889022f72470.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (55/100), attributed to the HUILoader family. 2 of 51 detection engines flagged it.
Identification
- SHA-256:
3008bd3ef9a55d4b78d238655e60f0568a41b5991275587c4e54af90599d2b4e - SHA-1:
38cad342d6ae45343eee68fef74fc7448d08c59b - MD5:
b2860c08c839b6265fd4889022f72470 - imphash:
0f943c6ca2e074efcb07e25913e54055 - ssdeep:
49152:H1cDw97qGFVGPYPqElw3vubrJdUS1XO2ARnw/kLwc0:iDsJd12+ - TLSH:
T1755C6D9A41172022D0FAED45F421C9DCD063F859D9349ACE9202DF1BD1A9EBB7BB00E5 - Submitted as: virussign.com_b2860c08c839b6265fd4889022f72470.vir
- File type: pe · Size: 2531144 bytes
- Verdict: suspicious (55/100) · Family: HUILoader
Source: VirusSign · first seen 2026-08-01T00:00:00.000Z · SHA-256 verified
Detections (2 of 51 engines)
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
Why this verdict
The suspicious score of 55/100 is the fusion of 3 weighted signals:
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://perfetto.dev/docs/contributing/getting-started#community - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://perfetto.dev/docs/contributing/getting-started#community
- https://www.microsoft.com
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
Embedded domains
- openssl.org
- mutex.cc
- field.cc
- time.cc
- utils.cc
- rds.descriptor.name
- descriptor.name
- perfetto.dev
- regex.cc
- allocator.cc
- executor.cc
- parser.cc
- registry.cc
- thread.cc
- sequence.cc
- values.cc
- mem.cc
- regexp.cc
- re2.cc
- tostring.cc
- simplify.cc
- parse.cc
- onepass.cc
- nfa.cc
- dfa.cc
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report