MALICIOUS — 77ef54e160ac82ccb126fe90090588ecd2aa01837e94a32cf02c606089395236
MALICIOUS — 77ef54e160ac82ccb126fe90090588ecd2aa01837e94a32cf02c606089395236 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the HUILoader family. 7 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
77ef54e160ac82ccb126fe90090588ecd2aa01837e94a32cf02c606089395236 - SHA-1:
1c8386c876cc39662d60bf225ac73430852bf084 - MD5:
4f33a4d73784377ad7554cd6a9f541b7 - imphash:
3e4757b6c44f364955a909104e3b2b4d - ssdeep:
3072:egwXxL0Uio0G5d89Xxm5Of5QGsljikMTmAcThAkZThMTMz6IhQcIAYfPcUcL:sxL0Sh8SCQGIixTmAcThAkZThMTMnhQU - TLSH:
T18D3E9E27725ECD9FC3158AAA3E40C51F2C82F1CC92B9947046CCD66E4869C7B3B591B2 - Submitted as: 77ef54e160ac82ccb126fe90090588ecd2aa01837e94a32cf02c606089395236
- File type: pe · Size: 145710 bytes
- Verdict: malicious (98/100) · Family: HUILoader
Detections (7 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Genpack-9875154-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:VMProtect
- Microsoft Defender: Trojan:Win32/Ausiv
- Emsisoft (Emergency Kit): GenPack:Trojan.Agent.EXMP
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Win.Malware.Genpack-9875154-0 (rule
Win.Malware.Genpack-9875154-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 26 external host(s) at runtime (25 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:VMProtect (rule
DIE:VMProtect) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://creativecommons.org/publicdomain/zero/1.0/, https://www.gnu.org/software/automake/manual/automake.html, http://fsmsh.com/2753 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-sections:.lol 1, VMProtect - static signal, weight 0.25, confidence 0.55
- Dropped 83 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Extracted generic config (4 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
25475 behavior events · 0 ATT&CK techniques · 98 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Dropped files
- C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\management_ext.dll -
1fb41d05249fe5fdcf3a8383bb6094d061f5b37a9a085fe9eb613444412dc1e9 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-string-l1-1-0.dll -
be7606295de0140dffe8f6cd5515f3cf9d0fa9f79f2a05d0634bbebe0644197b - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\j2gss.dll -
0f67ebb38a8a3f2d6991d0e18599a655216cd45eec8f65d669b94a2632705dbc - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-file-l1-2-0.dll -
65c4b2c24dc10cca951f415965178275cf0c4b41a3b1f9aaf72e5fafff18dec7 - C:\$WinREAgent\RollbackInfo.ini -
8a6942ed510253cc8df9207d00251685443aaa553d58547fe635afb656387876 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-crt-time-l1-1-0.dll -
fe17f3f3ec4c6515f0aca7e1a031fc0c64797cb0f0e277b9b1e77ff17172b077 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-localization-l1-2-0.dll -
1b386324c8b807b4edcc1bf3c626466dcd205094c178ad2062872e662beae217 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-profile-l1-1-0.dll -
c4a489da86c56b1879a472b4a90cec4dc21ef1fd1455d7aa980477918448977e - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\fontmanager.dll -
a41a16c9edbd96091dd54c81cff0d06a0a90288e7ba5b831b1ad7b860b793406 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jaccessinspector.exe -
ee5c4b68d8d868eda40493a57089bbbba6617ce5d525947796c7bf3f477e09a8 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\lcms.dll -
7a14f19494a6e438b086a6e5c013a3310356e9471172d36e30eaea45838bf5a2 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-namedpipe-l1-1-0.dll -
6f684d1fceeccc3acc3d92df71b3ea175c3bf60ba659bcb33fe7cbb5dd8b655b - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-timezone-l1-1-0.dll -
6c18d43d1cb50610a2c7128cdc945265b832fbe8767ebbb4c862e569d5f6e83a - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\javajpeg.dll -
0970c4bba79ec4c2ff1f47d2af17a46325af2b308e69aa6b3577718561a34d06 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jdwp.dll -
973bd150197fe948ab467639d926841cb2899c8bbae23cb5300c3893f5605d23
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- https://www.gnu.org/software/automake/manual/automake.html
- http://fsmsh.com/2753
- https://autotools.io/index.html
- http://miller.emu.id.au/pmiller/books/rmch/
- http://mozilla.org/MPL/2.0/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787875242&P2=404&P3=2&P4=c6WyfxlqsEDoPvGkk5iTpJAhqyDqtSbWt6I7FWwS8lpu2FANXvXY%2fDqjy7JRiESKs6tOhTREhfPg1jRBNBuelw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787875294&P2=404&P3=2&P4=kBeZUG8QrFNR9Ta26B9h1ukXm2TAUNKFIs5B9bHQV3L39biOreKUp1YB1Id%2bXHHyu2dsyXz1uTVF5PSXzD9aOg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- tukaani.org
- gmail.com
- creativecommons.org
- www.gnu.org
- fsmsh.com
- autotools.io
- miller.emu.id.au
- mozilla.org
- packet.name
- e.name
Embedded IP addresses
- 20.42.65.84
- 57.154.63.210
- 4.230.171.124
- 20.247.185.124
- 74.179.77.204
- 20.165.94.54
- 20.184.175.19
- 135.233.95.80
- 104.208.16.94
- 203.26.79.13
- 20.112.250.133
- 52.123.129.14
- 52.123.128.14
- 135.233.45.223
- 52.123.252.197
- 40.84.85.40
- 52.148.114.188
- 135.234.160.244
- 72.153.5.62
- 135.233.45.222
- 20.184.175.14
- 172.175.111.170
- 92.223.78.30
- 4.150.223.96
- 52.110.12.30
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report