MALICIOUS — SCUT.exe
MALICIOUS — SCUT.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100), attributed to the HUILoader family. 2 of 55 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
93738d32867abee458e40975b31313f9da240ce9e2a8a9b5b7457debd77d6e3d - SHA-1:
018ef704dfc28d46b0aabc6c97cf9babad52c732 - MD5:
3ec951651deea90f3ee36302eb720a22 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
196608:nwzl0oB9uXyE/T5uypwquCpPhQ3HRB2I/eZ9reB053hl:nwR0oB9y75u7quCt8HRB2I/k9rx - TLSH:
T1046DAE59421B3652E5F6CA58BC700E9CA437F4EC5039B58C1B43C86EA2D3E3BD9B0196 - Submitted as: SCUT.exe
- File type: pe · Size: 12307880 bytes
- Verdict: malicious (75/100) · Family: HUILoader
Detections (2 of 55 engines)
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 6 weighted signals:
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://sv.symcb.com/sv.crl0a, https://d.symcb.com/rpa0, http://sv.symcb.com/sv.crt0 - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.digicert.com/CPS0
- http://crl3.digicert.com/ha-cs-2011a.crl0
- http://crl4.digicert.com/ha-cs-2011a.crl0L
- https://www.digicert.com/CPS0
- http://www.digicert.com/ssl-cps-repository.htm0
- http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
- http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
- http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
- http://sv.symcb.com/sv.crl0a
- https://d.symcb.com/rpa0
- http://sv.symcb.com/sv.crt0
- http://crl.verisign.com/pca3.crl0
- https://www.verisign.com/cps0
- http://logo.verisign.com/vslogo.gif04
- http://www.symauth.com/cps0
- http://www.symauth.com/rpa00
- http://s1.symcb.com/pca3-g5.crl0
- http://oneocsp.microsoft.com/ocsp0f
- http://oneocsp.microsoft.com/ocsp0
- http://www.microsoft.com/pkiops/crl/Microsoft%20Public%20RSA%20Timestamping%20CA%202020.crl0y
- http://www.microsoft.com/pkiops/certs/Microsoft%20Public%20RSA%20Timestamping%20CA%202020.crt0
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
- http://crl.thawte.com/ThawteTimestampingCA.crl0
- http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
Embedded domains
- cacerts.digicert.com
- crl3.digicert.com
- www.digicert.com
- crl4.digicert.com
- dsa.pro
- sv.symcb.com
- d.symcb.com
- crl.verisign.com
- www.verisign.com
- logo.verisign.com
- www.symauth.com
- s1.symcb.com
- www.microsoft.com
- oneocsp.microsoft.com
- crl.thawte.com
- ts-aia.ws.symantec.com
- ts-crl.ws.symantec.com
- sf.symcb.com
- s.symcb.com
- www.w3.org
- pool.ntp.org
Embedded IP addresses
- 3.6.1.4
- 16.5.42.43
Registry keys
- HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\IDF
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ds_agent
- HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\Vulnerability
- HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\Deep
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TrendMicro\PC-cillinNTCorp\CurrentVersion
- HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TrendMicro\OfficeScan\DE\
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
- HKLM\SOFTWARE\TrendMicro\ESC
- HKLM\SOFTWARE\TrendMicro\ESE
- HKLM\SOFTWARE\TrendMicro\ESEStatus
- HKLM\SOFTWARE\TrendMicro\TMESD
- HKLM\SOFTWARE\TrendMicro\WL
- HKLM\SYSTEM\CurrentControlSet\services\TMESC
- HKLM\SYSTEM\CurrentControlSet\services\TMESE
- HKLM\SOFTWARE\Classes\Installer\Products\2D1CB2D6B8C10FA43ACA77698976AC49
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6CA07BA236710B54E9B14748FBB06294
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2D1CB2D6B8C10FA43ACA77698976AC49
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6D2BC1D2-1C8B-4AF0-A3AC-77969867CA94}
- HKLM\%s.
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall
- HKCU\Software\Classes\Installer
File paths
- C:\Program
- C:\Temp
- C:\Temp\H
- C:\actions-runner\_work\CommonUninstall\CommonUninstall\CommonUninstall\build\src\CommonUninstall\cmnunins_CommonUninstall.cpp
- C:\actions-runner\_work\CommonUninstall\CommonUninstall\CommonUninstall\build\src\CommonUninstall\cmnunins_CommonUtil.cpp
- C:\Temp\
- C:\actions-runner\_work\CommonUninstall\CommonUninstall\CommonUninstall\build\src\CommonUninstall\cmnunins_Uninstall.cpp
- C:\actions-runner\_work\CommonUninstall\CommonUninstall\CommonUninstall\build\src\CommonUninstall\cmnunins_UninstallTrend95Client31x.cpp
- C:\actions-runner\_work\CommonUninstall\CommonUninstall\CommonUninstall\build\src\CommonUninstall\cmnunins_UninstallTrend95Client35.cpp
- C:\actions-runner\_work\CommonUninstall\CommonUninstall\CommonUninstall\build\src\CommonUninstall\cmnunins_UninstallTrendNTClient31x.cpp
- C:\actions-runner\_work\CommonUninstall\CommonUninstall\CommonUninstall\build\src\CommonUninstall\cmnunins_UninstallTrendNTClient35.cpp
- C:\actions-runner\_work\OSCE_common\OSCE_common\OSCE_Common\build\src\Server\libDesEncrypt\de_DesEncrypt.cpp
- C:\actions-runner\_work\OSCE_common\OSCE_common\OSCE_Common\build\src\Client\libStdMisUtils\smu_CTmNotifyDLL.cpp
- C:\actions-runner\_work\OSCE_common\OSCE_common\OSCE_Common\build\src\Server\libMBAndWC\mbwc_MBWC.cpp
- C:\actions-runner\_work\OSCE_common\OSCE_common\OSCE_Common\build\src\Server\libFileIO\MultiPleSignCheck.cpp
- C:\actions-runner\_work\CommonUninstall\CommonUninstall\CommonUninstall\build\src\CommonUninstall\x64\Release\CommonUninstall.pdb
- d:\actions-runner\_work\osce_common\osce_common\osce_common\build\src\server\libdesencrypt\de_desencrypt.cpp
- d:\actions-runner\_work\osce_common\osce_common\osce_common\build\src\server\libmbandwc\mbwc_mbwc.cpp
- d:\actions-runner\_work\osce_common\osce_common\osce_common\build\src\client\libstdmisutils\smu_ctmnotifydll.cpp
- d:\actions-runner\_work\osce_common\osce_common\osce_common\build\src\server\libfileio\multiplesigncheck.cpp
- C:\actions-runner\_work\CommonUninstall\CommonUninstall\CommonUninstall\build\src\CommonUninstall\ARM64\Release\CommonUninstall.pdb
- C:\Tj
- C:\TW
- C:\actions-runner\_work\CommonUninstall\CommonUninstall\CommonUninstall\build\src\CommonUninstall\Win32\Release\CommonUninstall.pdb
- L:\:f:~:
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report