MALICIOUS — virussign.com_ed380d191a1bef0b5801093d42a719c0.vir
MALICIOUS — virussign.com_ed380d191a1bef0b5801093d42a719c0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the HUILoader family. 3 of 55 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
8595c13f77a43899cb35bdd704a5c25028cd681a77f34d123d3e22b3ea5a65a5 - SHA-1:
eec066f9a41731d04d11656ea93690816cd7d3f2 - MD5:
ed380d191a1bef0b5801093d42a719c0 - imphash:
88016fcdef7f227c62171d0afad9aae4 - ssdeep:
24576:QXNrSLScusMmOvjjhzvLJy6RrJA1VeQ/+g0Fi4ETLRXuFU6zj8GXYL5GfrIwiCZr:PuI2hr+1l+g0Fi4cRXMsm4MfrIpCqI - TLSH:
T1AD5BBE8E7F1B7522D729D3241060BA7F48E3AC4F037F5A4805A5AB1E96F881715E138B - Submitted as: virussign.com_ed380d191a1bef0b5801093d42a719c0.vir
- File type: pe · Size: 2155944 bytes
- Verdict: malicious (97/100) · Family: HUILoader
Source: VirusSign · first seen 2026-08-18T00:00:00.000Z · SHA-256 verified
Detections (3 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): Turbo Linker
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:Turbo Linker
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 10 weighted signals:
- Memory forensics: 3 finding(s), e.g. RWX/private injected region in tsk_1de3a30c86 (pid 1440) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 25 external host(s) at runtime (25 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1082 - dynamic signal, weight 0.40, confidence 0.75
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://jrsoftware.org/ishelp/index.php?topic=setupcmdline - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: Turbo Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
2843 behavior events · 2 ATT&CK techniques · 9 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- d1bn2x4fexrybh.cloudfront.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\is-8A6PNMIQDO.tmp\_isetup\_setup64.tmp -
388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95 - C:\Users\analyst\AppData\Local\Temp\is-8A6PNMIQDO.tmp\Logo.png -
8a69d3a92582b9dbc334cbd307487e8b4e2ffe3151a18e47cca8a764a6f37217 - C:\Users\analyst\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db -
0dc9e64e2b9e237739a6d816d97177119857a547689e610a2087e165833e1d46 - C:\Users\analyst\AppData\Local\Microsoft\Windows\Explorer\iconcache_256.db -
5ae1ef3a14c4bdbe43481898b4307ba4966a461bb873b2c29a340ca89c9d7333 - C:\Users\analyst\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db -
ade733aed23095ff718b43add6abb301d50ca0f2a474688ba3a4363ca53c7bdb - C:\Users\analyst\AppData\Local\Temp\is-03W2EF9185.tmp\tsk_1de3a30c86004abe.tmp -
bc475d8c7bb2aab62adc06f7be24c7856d72ad80fe4a5c5b8c3996e9d03b2107 - C:\Users\analyst\AppData\Local\Temp\is-8A6PNMIQDO.tmp\license.rtf -
eca753676c5c71d7be141451cd6d1426a08ed5c254078bc585d9ba91395a971a - b7808bce9be4af863a17d9a169adea730f33f11d5f3d1e1355f491394df0c9fe -
b7808bce9be4af863a17d9a169adea730f33f11d5f3d1e1355f491394df0c9fe - ac5bfabd3928f061a3d090f53527d9c077a9379004debc2f16092ed81588f082 -
ac5bfabd3928f061a3d090f53527d9c077a9379004debc2f16092ed81588f082
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://www.digicert.com/CPS0
- https://jrsoftware.org/ishelp/index.php?topic=setupcmdline
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787732176&P2=404&P3=2&P4=Sj3phtOtVXGrYWWIEUd%2bMRukHSfhbmXjHVZn7E%2b%2bqYDbj57jJkcLf2mAR6pXxRHPT3XB0QQ%2fcrnnk%2fvHeBcl0g%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787732260&P2=404&P3=2&P4=V750gehQq6x%2bzqvn0So2LDctsx0eafqOdZQgEvk3yC5Pra86XPFsY%2bdvLBaJA8Pnfk5A1nMndzAz5pn5eEN2NQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- schemas.microsoft.com
- f.hk
- www.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- cacerts.digicert.com
- jrsoftware.org
Embedded IP addresses
- 51.104.15.253
- 4.247.188.224
- 4.144.132.114
- 4.230.171.124
- 52.123.252.239
- 135.233.95.144
- 4.150.223.103
- 74.178.240.51
- 52.123.128.14
- 20.231.239.246
- 52.123.129.14
- 4.207.44.76
- 203.26.79.13
- 135.233.45.222
- 20.165.94.46
- 92.223.78.30
- 52.148.114.188
- 18.65.243.17
- 40.84.97.4
- 72.154.7.102
- 4.150.223.113
- 51.11.192.48
- 74.178.76.44
- 52.110.12.22
- 52.110.12.25
File paths
- T:\:d:l:p:t:x:
- X:\:`:d:h:l:p:t:x:
- N:\:k:
- E:\:
- X:\:`:h:p:x:
- U:\:c:j:t:
- T:\:j:x:
- X:\:d:h:p:t:x:
- T:\:d:l:t:
- D:\Coding\Is\issrc-build\Components\ChaCha20.pas
- x:\dirname
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report