MALICIOUS — 9768b7e31324805672cfcba91cf4d6da91494e9899db58f22da9dda6c91931d6.exe
MALICIOUS — 9768b7e31324805672cfcba91cf4d6da91494e9899db58f22da9dda6c91931d6.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the HUILoader family. 7 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
9768b7e31324805672cfcba91cf4d6da91494e9899db58f22da9dda6c91931d6 - SHA-1:
f768749575653ba3b83b46633fe57c477a58624e - MD5:
725eed1a191ecf0e74d7c382e12242a1 - imphash:
c2d457ad8ac36fc9f18d45bffcd450c2 - ssdeep:
49152:24DPhAZ6Yb4/wv5AxkbDcRsM3Ll2ylEK46Aq+hanB5Enki500rk8Vg2i:e6+B2sM3ETKGSEnhtQ - TLSH:
T120647CA956532112E1F9CD48F031C0DC8847B85ED2B11F8D0387E47951EAFAFEAE50A9 - Submitted as: 9768b7e31324805672cfcba91cf4d6da91494e9899db58f22da9dda6c91931d6.exe
- File type: pe · Size: 5564416 bytes
- Verdict: malicious (100/100) · Family: HUILoader
Detections (7 of 55 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- Hash: abuse.ch ThreatFox: known-malicious-hash
- Microsoft Defender: Trojan:Win32/Malgent
- Emsisoft (Emergency Kit): Trojan.GenericKD.81114627
- Kaspersky (KVRT): Trojan.Win64.Agent.smhdbb
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- Hash: abuse.ch ThreatFox flagged known-malicious-hash (rule
known-malicious-hash) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - Microsoft Defender flagged Trojan:Win32/Malgent (rule
Trojan:Win32/Malgent) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.GenericKD.81114627 (rule
Trojan.GenericKD.81114627) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win64.Agent.smhdbb (rule
Trojan.Win64.Agent.smhdbb) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - YARA: MalwareAnalyser built-in flagged Windows_Injection_Api_Combo (rule
Windows_Injection_Api_Combo) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.30, confidence 0.70 - Embedded network infrastructure: https://dubl2allremriki.com/api/v2, 5.4.62.5, 4.32.5.4 - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - inject code into another process (rule
inject code into another process) - capa signal, weight 0.12, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://dubl2allremriki.com/api/v2
Embedded domains
- big.int
- abi.name
- pkix.name
- godebugs.info
- golang.org
- api.ipify.org
- runtime.link
- reflectlite.name.name
- reflectlite.rtype.name
- unicode.to
- unicode.to
- go.shape.int
- eq.io
- eq.net
- hash.net
- dubl2allremriki.com
Embedded IP addresses
- 5.4.62.5
- 4.32.5.4
- 52.5.4.72
- 5.4.82.5
- 5.4.102.5
- 4.112.5.4
- 1.1.1.1
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report