MALICIOUS — 9f49039c43b603e699c25d00d42fa70b6d0f78bfba984bb69f1b365d1048f7dc
MALICIOUS — 9f49039c43b603e699c25d00d42fa70b6d0f78bfba984bb69f1b365d1048f7dc is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the HUILoader family. 6 of 55 detection engines flagged it, exhibiting 6 ATT&CK techniques.
Identification
- SHA-256:
9f49039c43b603e699c25d00d42fa70b6d0f78bfba984bb69f1b365d1048f7dc - SHA-1:
99cf2d55e5ece3e8ba2d8cabc141538f2dd85e0b - MD5:
2b9bd506e701dc406544c1863722d95c - imphash:
f5e2fae08fb1c8fba965c988eb10e880 - ssdeep:
24576:8uPmLDUMihIXCE5mpJE4VDd+U+f8LBOchzz9uRDFPFYI3Z6xh+8AGjagvGwee:8u+LIIX78JE4VBn+f8LIchzzIRDFPFnM - TLSH:
T18D56D06817D7B663C5F7EB180542EFDD10205C96617B188DA3A380BD72E7CAF2286346 - Submitted as: 9f49039c43b603e699c25d00d42fa70b6d0f78bfba984bb69f1b365d1048f7dc
- File type: pe · Size: 1469535 bytes
- Verdict: malicious (100/100) · Family: HUILoader
Detections (6 of 55 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Malware.Generickdz-9832066-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Trojan:Win32/Vindor!pz
- Emsisoft (Emergency Kit): Gen:Variant.Ransom.Phobos.154
- Kaspersky (KVRT): HEUR:Trojan.Win32.Scar.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Malware.Generickdz-9832066-0 (rule
Win.Malware.Generickdz-9832066-0) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 25 external host(s) at runtime (19 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1497, T1082 - dynamic signal, weight 0.40, confidence 0.75
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://http.proxy.icq.com/hello - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Dropped 8 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
91399 behavior events · 3 ATT&CK techniques · 9 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- settings-win.data.microsoft.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- officeclient.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileSyncHelper.exe -
cf5eae933f9f8b56fb5fea6a66b412d36e889430a64d1594acf17b3b766d2d46 - C:\Users\analyst\AppData\Local\Temp\UCEQA -
9f79443007dac54b548672517f288638086e43765b19c65e73aab11ad002a933 - C:\ThreatLens\agent.exe -
b4562bb2c67368d8183870943bad2b77095d01afb39845686f58f438b1f7b72d - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileSyncConfig.exe -
974a8cdb704a9d01196ef456fe89f8ba09470936d1c68d8e3a38e7a8991b2397 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileCoAuth.exe -
0c0af939dfe42d90d251a7a4e865b76f789705078b0100981f7586d420ed0294 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\Microsoft.SharePoint.NativeMessagingClient.exe -
f642e523cacc0ec732eaa4a38e48b00b2bc23300cb0243de2685d8c19b21b748 - C:\Sysmon64.exe -
543bc0aedb87eda3fedcfcf75a99249c3636eb10e6382eb8914cf5a7223e32f8 - C:\Users\analyst\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\OneDrive.Sync.Service.exe -
dc0d428c72b299c52dd13c6242e9d320c79796277307d60e6cc8e299ad4895f7 - C:\Users\Public\Microsoft Build\Isass.exe -
c8f53b5a4385b0078f5cf7b8996be515ae44ecb7e2ba4d4e6da82416b8ba0528
Embedded URLs
- http://http.proxy.icq.com/hello
- http://crl.verisign.com/tss-ca.crl0
- http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl0O
- http://office.microsoft.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787798783&P2=404&P3=2&P4=Iayj%2bW7tNSW%2f1lAVrMHtKuouGcNoZR4%2fUlbUn9OVylYxnIDwN%2fnXeth4%2fZIyVFr9gtl3OVzcRNlKv6NgZcKgHA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- http.proxy.icq.com
- login.icq.com
- crl.verisign.com
- crl.microsoft.com
- www.microsoft.com
- office.microsoft.com
Embedded IP addresses
- 0.0.0.1
- 85.210.196.11
- 20.184.175.22
- 52.123.252.218
- 4.230.171.124
- 20.247.184.197
- 40.84.85.40
- 135.233.95.144
- 74.178.240.51
- 51.104.15.253
- 52.123.128.14
- 20.236.44.162
- 52.123.129.14
- 40.104.4.2
- 135.233.45.222
- 52.123.252.215
- 203.26.79.13
- 52.148.114.188
- 40.84.97.4
- 52.110.12.14
- 52.110.12.32
- 52.123.252.195
- 74.179.71.159
- 72.145.35.105
- 52.110.12.4
File paths
- R:\Sg
- X:\:`:d:h:l:p:t:x:
- V:\:a:g:r:x:
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report