MALICIOUS — wwb9_64.dll
MALICIOUS — wwb9_64.dll is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100), attributed to the HUILoader family. 4 of 55 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
671ba5caae316b8abe01e4961eb48c9f5e4eac5a957619b30c18fc3d2f72966c - SHA-1:
984eb450d0d34431478d9db11422c371597e3786 - MD5:
99b80a1ee18e33af9825b873537278a8 - imphash:
ff4e98f9d3002465a9067b298f013a54 - ssdeep:
49152:Q4VYiF7hGZoJ/jtVu3GmADYriIRcgdIWLggLvUv5HZi/w2QJUoJUYFtC8cmsTE2:XZAZ+/Pu3+gdIWXvUv5qO9cz - TLSH:
T1BF5F3B4152072376F1F7D810AC8287AD991271BC93B55D887203DCBE62EAD3B9AD0793 - Submitted as: wwb9_64.dll
- File type: pe · Size: 3163264 bytes
- Verdict: malicious (72/100) · Family: HUILoader
Detections (4 of 55 engines)
- capa (capabilities): capability:collection/keylog
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: flagged
MITRE ATT&CK
Why this verdict
The malicious score of 72/100 is the fusion of 6 weighted signals:
- capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://certs.starfieldtech.com/repository/1402, https://certs.starfieldtech.com/repository/0, https://www.winwrap.com/web/basic/support/annual-fee.asp - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://msdl.microsoft.com/download/symbols
- http://ocsp.godaddy.com/02
- http://crl.godaddy.com/gdroot.crl0F
- https://certs.godaddy.com/repository/0
- http://certs.godaddy.com/repository/1301
- http://ocsp.godaddy.com/05
- http://crl.godaddy.com/gdroot-g2.crl0F
- http://certs.starfieldtech.com/repository/1402
- http://ocsp.starfieldtech.com/0
- http://crl.starfieldtech.com/sfroot-g2.crl0L
- https://certs.starfieldtech.com/repository/0
- http://crl.godaddy.com/gdig2s5-3.crl0
- http://certificates.godaddy.com/repository/0
- http://ocsp.godaddy.com/0@
- http://ocsp.starfieldtech.com/0H
- http://crl.starfieldtech.com/repository/sf_issuing_ca-g2.crt0T
- http://crl.starfieldtech.com/repository/0
- https://www.winwrap.com/web/basic/support/annual-fee.asp
- http://www.winwrap.com/web/basic/
- http://www.winwrap.com/web/e-sn.asp?code=
Embedded domains
- msdl.microsoft.com
- ocsp.godaddy.com
- crl.godaddy.com
- certs.godaddy.com
- certs.starfieldtech.com
- ocsp.starfieldtech.com
- crl.starfieldtech.com
- certificates.godaddy.com
- www.winwrap.com
- winwrap.com
- wwb.net
File paths
- c:\websymbols
- e:\dev\ww9.30\msvc2005\wwb\x64\Release
- e:\dev\ww9.30\msvc2008\wwbnet\2.0\obj\Release\wwb9_net.pdb
- e:\dev\ww9.30\private
- e:\dev\ww9.30\private\SerialNumber.htm
- c:\CommonLicenses\SerialNumber.htm
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report