MALICIOUS — 873d4d51b4d4731068282ed3e42187bfd3d6fe1772acebecc738965ee47b4208
MALICIOUS — 873d4d51b4d4731068282ed3e42187bfd3d6fe1772acebecc738965ee47b4208 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (78/100), attributed to the HUILoader family. 2 of 29 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
873d4d51b4d4731068282ed3e42187bfd3d6fe1772acebecc738965ee47b4208 - SHA-1:
226b84e33fe2831ec7f3a5053fee09d6e2ca68ac - MD5:
9be0cc78fb87dbaa255fd3a561e61f17 - imphash:
8b1fc5c989964e6fc1675250748f63dc - ssdeep:
49152:VKA0D2itrqEUKA0D2itrqElQB7cDkYOMwwnMb4PmyV/HrLYcMkHc:aZvZshYOXwnS4rVn5G - TLSH:
T1535DAD8D41646715C6F3CF705995C6AD3DA2B0E8B1BC1A4C5687C17E21E2CB3B8370AA - Submitted as: 873d4d51b4d4731068282ed3e42187bfd3d6fe1772acebecc738965ee47b4208
- File type: pe · Size: 2645317 bytes
- Verdict: malicious (78/100) · Family: HUILoader
Detections (2 of 29 engines)
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
MITRE ATT&CK
Why this verdict
The malicious score of 78/100 is the fusion of 6 weighted signals:
- Contacted 23 external host(s) at runtime (18 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://purl.org/atom/ns#, http://purl.org/atom/ns#modified, http://purl.org/atom/ns#id - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Embedded URLs
- http://ns.adobe.com/Acrobat/RSS/Inbox/feedUI
- http://ns.adobe.com/Acrobat/RSS/Inbox/icon
- http://ns.adobe.com/synchronizer/ttl
- http://ns.adobe.com/synchronizer/dependency
- http://www.w3.org/2005/Atom
- http://purl.org/atom/ns#
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://www.w3.org/2005/Atommodifled
- http://www.w3.org/2005/Atomid
- http://www.w3.org/2005/Atomsummary
- http://www.w3.org/2005/Atomcontent
- http://www.w3.org/2005/Atomentry
- http://purl.org/atom/ns#modified
- http://purl.org/atom/ns#id
- http://purl.org/atom/ns#summary
- http://purl.org/atom/ns#content
- http://purl.org/atom/ns#entry
- http://www.w3.org/1999/xhtmlbody
- http://purl.org/rss/1.0/modules/content/encoded
- http://purl.org/rss/1.0/description
- http://purl.org/rss/1.0/title
- http://purl.org/rss/1.0/item
- http://www.w3.org/XML/1998/namespace
- http://crl.verisign.com/tss-ca.crl0
- https://www.verisign.com/rpa
Embedded domains
- ns.adobe.com
- www.w3.org
- purl.org
- crl.verisign.com
- www.verisign.com
- crl.microsoft.com
- www.microsoft.com
- office.microsoft.com
- tempuri.org
- schemas.microsoft.com
- go.microsoft.com
- csc3-2004-crl.verisign.com
Embedded IP addresses
- 20.42.72.131
- 52.123.252.213
- 20.247.184.197
- 4.230.171.124
- 48.211.4.16
- 52.123.252.194
- 20.165.94.46
- 52.123.252.195
- 20.165.94.63
- 74.179.77.164
- 203.26.79.13
- 40.99.133.226
- 20.236.44.162
- 52.123.129.14
- 52.123.128.14
- 40.99.133.242
- 172.66.2.5
- 135.234.160.244
- 52.148.114.188
- 52.110.12.20
- 52.110.12.32
- 92.223.78.30
- 72.153.5.138
Registry keys
- HKEY_LOCAL_MACHINE\Software\Classes\{0}.
- HKCU\Software
- HKCU\Software\Policies
- HKLM\Software
- HKLM\Software\Policies
File paths
- F:\dd\Tools\devdiv\FinalPublicKey.snk
- g:\acro_root_at\acrobat\systemsynchronizer\synchronizerapp\build\win\release\AdobeCollabSync.pdb
- f:\RedBits\Tools\devdiv\FinalPublicKey.snk
- d:\sp1.public.x86fre\internal\strongnamekeys\fake\windows.snk
- f:\binaries.x86ret\bin\i386\Optimization\opt\bin\i386\csc.pdb
- c:\video_ts\video_ts.ifo
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report