MALICIOUS — b8d17ac80ddc58836ca0232122835f80b6dfd223e76abcbfd04004fbacca4a64.dll
MALICIOUS — b8d17ac80ddc58836ca0232122835f80b6dfd223e76abcbfd04004fbacca4a64.dll is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the HUILoader family. 7 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
b8d17ac80ddc58836ca0232122835f80b6dfd223e76abcbfd04004fbacca4a64 - SHA-1:
ce9bb0cbb258d7117e0f2544d5e0a0b2d3261126 - MD5:
67ed4c26a82da8b364fb925774d95506 - imphash:
dae02f32a21e03ce65412f6e56942daa - ssdeep:
6144:JRuOthJoa3HUcDW6ydqJtfyyHs29TujqsiRGfAuHOgYdHcb31fSgZY:JmMW3sJ7793J0f/0d2SgZ - TLSH:
T1864D05D88E2E5315DDFA2342618268FFF9E65DCCD8B517EE6488ADB12ADC703812411C - Submitted as: b8d17ac80ddc58836ca0232122835f80b6dfd223e76abcbfd04004fbacca4a64.dll
- File type: pe · Size: 577592 bytes
- Verdict: malicious (95/100) · Family: HUILoader
Source: MalwareBazaar · first seen 2026-08-01T00:00:00.000Z · SHA-256 verified
Detections (7 of 52 engines)
- YARA: MalwareAnalyser built-in: Suspicious_PowerShell_Download_Exec
- capa (capabilities): capability:execution/powershell
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- Microsoft Defender: Trojan:MSIL/Lausivloader.WEQ!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Lausivloader.1
- Kaspersky (KVRT): HEUR:Trojan.MSIL.Kryptik.gen
MITRE ATT&CK
YARA
- Suspicious_PowerShell_Download_Exec
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 95/100 is the fusion of 6 weighted signals:
- Encoded/hidden PowerShell download-and-exec (rule
Suspicious_PowerShell_Download_Exec) - yara signal, weight 0.70, confidence 0.90 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 4.5.6.7 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- schemas.microsoft.com
Embedded IP addresses
- 0.1.2.3
- 4.5.6.7
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report