MALICIOUS — 8e6edc67cf9fbfb04e3e4329b34c72369b2e6cde2c68721067f5f17d4affc851.bin
MALICIOUS — 8e6edc67cf9fbfb04e3e4329b34c72369b2e6cde2c68721067f5f17d4affc851.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (76/100), attributed to the HUILoader family. 4 of 52 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
8e6edc67cf9fbfb04e3e4329b34c72369b2e6cde2c68721067f5f17d4affc851 - SHA-1:
811063917d7602c3625605d1c1382a3d54ad7b5b - MD5:
92583130c29b3d3bf3602ecfca2c3453 - imphash:
63ed59597dad42eeec3f01fae0ba2a2e - ssdeep:
393216:yZNVjchuWAR4qmAvLKS93U1jTIRD5+86VYGWE2+uPQshn:WNVjchuWARCPBjsRf6KlEiVhn - TLSH:
T1616FF19C20097A1FE4E5889A78900B2C9417E1C139B7345CFF97E42967DBCA390B857B - Submitted as: 8e6edc67cf9fbfb04e3e4329b34c72369b2e6cde2c68721067f5f17d4affc851.bin
- File type: pe · Size: 14950688 bytes
- Verdict: malicious (76/100) · Family: HUILoader
Source: MalShare · first seen 2026-08-15T08:25:58.960Z · SHA-256 verified
Detections (4 of 52 engines)
- capa (capabilities): capability:collection/keylog
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Trellix/McAfee ATR: ATR_LockBit_Ransomware
- YARA: Yara-Rules community: YR_AntiDebug_Checks
MITRE ATT&CK
Why this verdict
The malicious score of 76/100 is the fusion of 7 weighted signals:
- capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Trellix/McAfee ATR flagged ATR_LockBit_Ransomware (rule
ATR_LockBit_Ransomware) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/winfx/2006/xaml/presentation
- http://schemas.microsoft.com/winfx/2006/xaml
- http://schemas.microsoft.com/expression/blend/2008
- http://schemas.openxmlformats.org/markup-compatibility/2006
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://www.digicert.com/CPS0
Embedded domains
- schemas.microsoft.com
- schemas.openxmlformats.org
- c.9.co
- 7w.sh
- f.mx
- n.fi
- 3e.us
- cacerts.digicert.com
- crl3.digicert.com
- www.digicert.com
- crl4.digicert.com
- dev.mysql.com
File paths
- R:\2
- C:\ReleaseAI\win\Release\stubs\x86\ExternalUi.pdb
- O:\:
- U:\:i:q:
- N:\:a:g:k:w:
- W:\:c:x:
- X:\:`:d:
- X:\:`:d:h:l:p:t:x:
- T:\:d:l:t:
- T:\:h:p:
- T:\:h:
- T:\:d:
- T:\:d:p:
- P:\:d:l:t:
- T:\:d:t:
- T:\:d:l:x:
- P:\:
- T:\:d:l:
- a:\z@
- C:\ReleaseAI\platform\ui\controls\mshtml\GenericAxControl.cpp
- C:\ReleaseAI\stubs\setup\controls\InstancesListControl.cpp
- C:\ReleaseAI\stubs\setup\controls\generic\VisualStyleBorder.h
- C:\ReleaseAI\stubs\setup\controls\QuickSelectionListControl.cpp
- C:\ReleaseAI\stubs\setup\controls\TabControl.cpp
- C:\ReleaseAI\stubs\setup\core\TabControlCore.h
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report