MALICIOUS — 9626184a3a0e74a12313f48efe3ba8a1dd3a8de160c21d8f1663a8cb75186aed
MALICIOUS — 9626184a3a0e74a12313f48efe3ba8a1dd3a8de160c21d8f1663a8cb75186aed is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the HUILoader family. 8 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9626184a3a0e74a12313f48efe3ba8a1dd3a8de160c21d8f1663a8cb75186aed - SHA-1:
3fb6a7bdbbac258812763e5f6815a2647425304f - MD5:
8f390f29d3b11f5637b8733b883bc5e5 - imphash:
38aa7c2ff6ef0e48a9520d6702d08df4 - ssdeep:
3072:NnEOtEEquM++FFhNGpWDO5+TyidFhNGpWZljikMTmAcThAkZThMTMz6Riv:TeEk+0FhNGpWu+TyidFhNGpWjixTmAcF - TLSH:
T1EF416D5F1125D92FD1E08E57290CD5AE8C83E0688575875A52CCF2BC806C83F7B6FAA1 - Submitted as: 9626184a3a0e74a12313f48efe3ba8a1dd3a8de160c21d8f1663a8cb75186aed
- File type: pe · Size: 182658 bytes
- Verdict: malicious (98/100) · Family: HUILoader
Detections (8 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Agent-6943819-1
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:UPX
- Microsoft Defender: Virus:Win32/Sivis.A
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Trellix Stinger (McAfee): PolyPatch-UPX
- Kaspersky (KVRT): Virus.Win32.Agent.es
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Agent-6943819-1 (rule
Win.Trojan.Agent-6943819-1) - engine signal, weight 0.90, confidence 0.95 - Contacted 28 external host(s) at runtime (22 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:UPX (rule
DIE:UPX) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.gnu.org/software/coreutils/, http://translationproject.org/team/, http://gnu.org/licenses/gpl.html - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: UPX - static signal, weight 0.25, confidence 0.55
- Dropped 83 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Extracted generic config (5 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
25559 behavior events · 0 ATT&CK techniques · 97 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- settings-win.data.microsoft.com
- www.msn.com
Dropped files
- C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-synch-l1-1-0.dll -
c55ec802b54776cb561e36375e16dafbdbf9f28a6370e494e57be6acb51c3b85 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-localization-l1-2-0.dll -
b4b52722d64f33c671e3b3867ad414aad89f165d23d58d8155dc2433b6de2dc4 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\instrument.dll -
2d241215c216cd40880006c6eed48c22e81be352eae221548b6537f1b6193d88 - 91cd04dc0bbff60744f9b0c7ca00b2726f97cfcd9d9b3a95886186011b48140c -
91cd04dc0bbff60744f9b0c7ca00b2726f97cfcd9d9b3a95886186011b48140c - C:\$WinREAgent\RollbackInfo.ini -
edb04f2afc6b005a496998c94f9aaff6406683fbb0639df48a0cdf93993cc3ae - C:\$Recycle.Bin\S-1-5-21-976637724-599762485-334819845-1001\desktop.ini -
8074146fa02a9801cb7d300807f68f495f92921a35564bbd8243aad110f49062 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-crt-math-l1-1-0.dll -
d601ebf23d9b263df2254e7077d5005d4ed857ac588276982b8eee40add4e2af - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-handle-l1-1-0.dll -
9d151bc26e55de8150b395b85e261655d9604cea371ff649baf61426444596ca - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-heap-l1-1-0.dll -
d2102746f6fbb77889e3bab6a2e0f7aed57b55302bc562d4ece2317ff06315d9 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-crt-heap-l1-1-0.dll -
6bc6f3c7a509692abbbd6f6169c1ce6f5f0401d975c3c1d0cd3e193397345880 - 0277405e9e37e408a862a78a4bdc4e4ae8299a46f05ee0ef18c09cc9dca970da -
0277405e9e37e408a862a78a4bdc4e4ae8299a46f05ee0ef18c09cc9dca970da - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-processenvironment-l1-1-0.dll -
96df397200ac34976e2ffd6490c6051a0faeec041a49f03a49c43e4ee7878092 - 22f129dbc34721dc0fe047a7fffcf02c53db3a658b5be2dfbe155a201c87db4b -
22f129dbc34721dc0fe047a7fffcf02c53db3a658b5be2dfbe155a201c87db4b - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-fibers-l1-1-1.dll -
731db91819b76f41aecd350abfaeb2a41892ad4d5c92a7c312c9900f64c09c5c - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-crt-string-l1-1-0.dll -
d00f0303196ae38efa17027cb1cb3a96af409b70009089ef8da851236c5f332b
Embedded URLs
- http://www.gnu.org/software/coreutils/
- http://translationproject.org/team/
- http://gnu.org/licenses/gpl.html
- http://www.gnu.org/gethelp/
- https://www.gnu.org/software/automake/manual/automake.html
- http://fsmsh.com/2753
- https://autotools.io/index.html
- http://miller.emu.id.au/pmiller/books/rmch/
- http://creativecommons.org/publicdomain/zero/1.0/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787907045&P2=404&P3=2&P4=XVtk%2fhPBTyIiTRSXlKs5uzwE9EKIF7NCvUm3oDc08SWm1oxxeCf33ajTcrPdkg57bw63SmnbB1pKmIcAOff7cQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787907079&P2=404&P3=2&P4=Ces3niEaPaJU39hRGn04UDG%2fZS12vU58lXZWHKxlcLtmiYQMjZY9hx6x6zocQCHX8qM8XW2%2bimEvVAk6o1d4yA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- www.gnu.org
- translationproject.org
- gnu.org
- cygwin.com
- fsmsh.com
- autotools.io
- miller.emu.id.au
- creativecommons.org
- geocities.com
Embedded IP addresses
- 20.184.175.1
- 20.42.179.204
- 4.230.171.124
- 20.42.179.192
- 4.144.132.223
- 135.233.95.144
- 74.178.240.51
- 40.79.150.120
- 135.232.92.137
- 20.231.239.246
- 40.99.133.226
- 52.123.129.14
- 52.123.128.14
- 203.26.79.13
- 135.233.45.221
- 74.178.232.29
- 52.123.252.226
- 52.148.114.188
- 52.110.12.30
- 135.234.160.245
- 52.110.12.28
- 172.215.188.232
- 72.145.35.110
- 52.168.112.67
- 172.170.180.133
File paths
- X:\windows\system32\sysreset.exe
- C:\Windows.old\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim]
- C:\Windows\containers\serviced\WindowsDefenderApplicationGuard.wim]
- C:\Windows.old\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.1120_none_c3e
- C:\Windows.old\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.1_none_eedfed
- X:\SysResetTrace-Tel-Merge.etl,
- C:\$WINDOWS.~BT\Sources\Panther\SysResetTrace-Tel-Merge.etl)
- C:\Windows.old
- C:\.
- C:\Windows.old\Windows\System32\Config\Software.
- C:\\Windows\System32\Config\Software.
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report