MALICIOUS — 9b055ccdd200af47df2e89f7f2f238ec3618f18352d430ce4da91213c38ab450
MALICIOUS — 9b055ccdd200af47df2e89f7f2f238ec3618f18352d430ce4da91213c38ab450 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the HUILoader family. 8 of 55 detection engines flagged it.
Identification
- SHA-256:
9b055ccdd200af47df2e89f7f2f238ec3618f18352d430ce4da91213c38ab450 - SHA-1:
0dc1b087ea09414d63cae7f9260a97c448654601 - MD5:
78ea761fd525a32d8ced70a40d427d13 - imphash:
fff777f42c1e485850e1fdc0085a1692 - ssdeep:
98304:EihQh+nIxQ/mDXYNafHQ/wDIbzuuDMc3GF3hjt:EiqM6XYNUQ/MP63GF3Vt - TLSH:
T11A6233EC433E7B80D9578F2AFC265E2E1521A16768695C8CAF0BD02C66F61DBD1B0019 - Submitted as: 9b055ccdd200af47df2e89f7f2f238ec3618f18352d430ce4da91213c38ab450
- File type: pe · Size: 4397096 bytes
- Verdict: malicious (93/100) · Family: HUILoader
Detections (8 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): Win.Malware.Generic-9908035-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- LIEF (executable format parser): lief:invalid-authenticode
- Microsoft Defender: Ransom:Win32/StopCrypt.MSK!MTB
- Emsisoft (Emergency Kit): Trojan.Crypt
- Trellix Stinger (McAfee): Lockbit-FSWW!78EA761FD525
- Kaspersky (KVRT): UDS:DangerousObject.Multi.Generic
Why this verdict
The malicious score of 93/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Malware.Generic-9908035-0 (rule
Win.Malware.Generic-9908035-0) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- r1.pw
File paths
- R:\oOU
- C:\nicagileluvi\tulu-kezocetu\zozohitodicahi\sahicokol42\bag.pdb
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report