MALICIOUS — 5d7bc43d7a3c17a0ae69aa23cc282fb850166f3b7e154c724d536b0ed7d7f882
MALICIOUS — 5d7bc43d7a3c17a0ae69aa23cc282fb850166f3b7e154c724d536b0ed7d7f882 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the HUILoader family. 4 of 56 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
5d7bc43d7a3c17a0ae69aa23cc282fb850166f3b7e154c724d536b0ed7d7f882 - SHA-1:
3bc6bbee989526f40c27126aef765b858b5ce085 - MD5:
dbacca7d7418bf74580a4bf6ffd4e5b8 - imphash:
eb5bc6ff6263b364dfbfb78bdb48ed59 - ssdeep:
98304:y1QTgUubIxLYzHfABSt9yeJgnQjRGCcPxdoZ+W/6YK2BKI1j45kJJijC1H:OFH0xsDt0Qjk6P/XK2BF1jdkIH - TLSH:
T1FD6412DEB11AB932C76BD72063A2BD7F44EBEC7703BB444849E1CA2EC5D4653152210A - Submitted as: 5d7bc43d7a3c17a0ae69aa23cc282fb850166f3b7e154c724d536b0ed7d7f882
- File type: pe · Size: 5401915 bytes
- Verdict: malicious (100/100) · Family: HUILoader
Detections (4 of 56 engines)
- ClamAV (daily): Win.Malware.Generic-9908426-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Emsisoft (Emergency Kit): Trojan.Generic.38041895
- Kaspersky (KVRT): UDS:DangerousObject.Multi.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Win.Malware.Generic-9908426-0 (rule
Win.Malware.Generic-9908426-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged Trojan.Generic.38041895 (rule
Trojan.Generic.38041895) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:DangerousObject.Multi.Generic (rule
UDS:DangerousObject.Multi.Generic) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s) across 1 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 18 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1497, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Embedded network infrastructure: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdline - static signal, weight 0.35, confidence 0.60
- Dropped 9 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
13215 behavior events · 2 ATT&CK techniques · 23 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- olustgtapi.live
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- officeclient.microsoft.com
- www.msn.com
- odc.officeapps.live.com
- assets.msn.com
Dropped files
- c:\program files (x86)\clhunter\clhunter.exe -
a22d63b585a6e06f8cd275b9f0c08b8f96be7f767548a5d7b1dc2e15df5af394 - C:\Users\analyst\AppData\Local\Temp\is-M2NST.tmp\_isetup\_setup64.tmp -
388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95 - C:\Users\analyst\AppData\Local\Temp\is-OUJDI.tmp\tsk_ff29c41d653c4cd7.tmp -
42fdacf5ad89105002f396de1147be9e68f139e941024d3e5db4721521db91a0 - c:\program files (x86)\clhunter\crdllunload64.dll -
0b28d446fdd3eae2c6532cf4611765fa4ca9fedfba6fb564ad1e4eb46420613a - c:\program files (x86)\clhunter\history.txt -
59df86ecd4822f5fe077ca078dae25bfd19d052b6bb375c8e9010c7b86244ee2 - c:\program files (x86)\clhunter\usrfindhandle64.sys -
b288dfec2bb19509eca5b659c022db1ac80534c2eb06f6f792d563e655cd5a71 - C:\Users\analyst\AppData\Local\Temp\{a76845fd-0825-4fb2-b745-265ec9a622e5}.png -
f3335e652639a387b7532280039027c9102a7da2b28ce72b336c4634b002c768 - C:\Users\analyst\AppData\Local\Temp\is-M2NST.tmp\_isetup\_iscrypt.dll -
2f6294f9aa09f59a574b5dcd33be54e16b39377984f3d5658cda44950fa0f8fc - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\clHunter\clHunter.lnk -
404058a2eae26752cc730511c05729ac9a19369a1987d21fa8ad9b95a3f2056c - c:\program files (x86)\clhunter\crdllunload32.dll -
6468cb2a3d578efba32239c1c2c4676b4ddc3af4da59c8a3cec1adb6adf76930 - C:\Users\analyst\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000025.db -
dcccac3b5c3f5d76a9319d51e8ea0f824525f5360f13f043adeb8dcfd5ab8bf2 - c:\program files (x86)\clhunter\unins000.exe -
76d5c382604718e5a84ead5330224cf761e8087eee797a6b30c6b16c76f07ec4 - c:\program files (x86)\clhunter\lhshellext32.dll -
d0894fb05471025253d7d002678157ace15d5e1d960a2470ee1f83f2d9a9a4d5 - C:\Users\analyst\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000023.db -
e93cde66b5ca18dd71fa7461456ca1908bdd6fe38a642624ec1fcac975d026ae - c:\program files (x86)\clhunter\lhshellext64.dll -
b18e15ba181c0ded42e179babad2900ec54e410329cdd4bf67e9f64bb6f3d1bf
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdline
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- schemas.microsoft.com
- nw.eu
- www.jrsoftware.org
- olustgtapi.live
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 13.89.179.15
- 4.144.132.114
- 4.230.171.124
- 135.233.45.223
- 57.154.63.210
- 40.84.85.40
- 72.145.35.108
- 92.223.78.30
- 52.148.114.188
- 52.110.12.50
- 52.110.12.16
File paths
- f:\OC
- x:\dirname
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report