MALICIOUS — 30d0602f1a1133524235824bea88ab2786455ce777b672d7b7b122d96b59eaf2
MALICIOUS — 30d0602f1a1133524235824bea88ab2786455ce777b672d7b7b122d96b59eaf2 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100), attributed to the HUILoader family. 8 of 55 detection engines flagged it.
Identification
- SHA-256:
30d0602f1a1133524235824bea88ab2786455ce777b672d7b7b122d96b59eaf2 - SHA-1:
7c7db8645c4a7db9b54943c49daf3d0404b6cc4f - MD5:
ff4f61d4a6554b03f32e3340583e803c - imphash:
7af2fe87a3ab930007d141d21c36ceda - ssdeep:
98304:AJQaLXTZx9lyUZJ0HArfMgHHIpP3VdXVQ//i6rQUKx44bacL7Z1:AJQaLnyUE8ERdXVQhroxXbZ3L - TLSH:
T19563CEED5144E663E4ABFE8419928D4F2C4F6844E0F019B952C6E00E77E9D2BD8C13AD - Submitted as: 30d0602f1a1133524235824bea88ab2786455ce777b672d7b7b122d96b59eaf2
- File type: pe · Size: 4730812 bytes
- Verdict: malicious (71/100) · Family: HUILoader
Detections (8 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Worm:Win32/FakeFolder.KAA!MTB
- Emsisoft (Emergency Kit): Trojan.Agent.FKUK
- Trellix Stinger (McAfee): Trojan-FLOM!FF4F61D4A655
- Kaspersky (KVRT): HEUR:Worm.Python.Generic
Why this verdict
The malicious score of 71/100 is the fusion of 5 weighted signals:
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://python.org/dev/peps/pep-0263/ - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://python.org/dev/peps/pep-0263/
Embedded domains
- command.com
- x.name
- python.org
- r.name
- 69.sh
- v.ua
File paths
- R:\Sg
- C:\build27\cpython\PCBuild\python27.pdb
- C:\:!;0;:;_;n;x;
- X:\:`:d:h:l:p:t:x:
- X:\:`:d:h:l:p:
- V:\:
- D:\:t:
- D:\:
- X:\:d:h:l:t:x:
- T:\:`:d:l:p:t:
- T:\:
- H:\:`:d:h:
- C:\Python27\lib\site-packages\py2exe\boot_common.pyR
- C:\Python27\lib\site-packages\py2exe\boot_common.pyt
- C:\\bootss
- C:\boots\u
- D:\\bootss
- D:\boots\i
- C:\txt.txti
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report