MALICIOUS — b8f2ff3468ed55571eb03cab29a1728dfccdfea0b59104b78d73fdc96ae0b8bb
MALICIOUS — b8f2ff3468ed55571eb03cab29a1728dfccdfea0b59104b78d73fdc96ae0b8bb is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the HUILoader family. 4 of 52 detection engines flagged it.
Identification
- SHA-256:
b8f2ff3468ed55571eb03cab29a1728dfccdfea0b59104b78d73fdc96ae0b8bb - SHA-1:
48d35fc5a793533ce13aade2cb7d35ef6d2ad708 - MD5:
1767d9b9b64058fc5d7a89c0940d66e7 - imphash:
5e6e11e480893ab99caa150e4d20b3e1 - ssdeep:
24576:esZ+m88g3v/xyzHQCFZYyOf30pCqV+DgG2OEcJ35WL91LXe:esZ23xyLpFeD304qVqgfPcJJAy - TLSH:
T1375412DD41197A84D6B7CA242C505F1EC072B4DE61BE150C0A83D6AF3AF7993FAB410A - Submitted as: b8f2ff3468ed55571eb03cab29a1728dfccdfea0b59104b78d73fdc96ae0b8bb
- File type: pe · Size: 1110528 bytes
- Verdict: malicious (93/100) · Family: HUILoader
Detections (4 of 52 engines)
- ClamAV (daily): Win.Trojan.XXMM-6736056-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Kaspersky (KVRT): UDS:Backdoor.Win32.CosmicDuke.gen
Why this verdict
The malicious score of 93/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Trojan.XXMM-6736056-0 (rule
Win.Trojan.XXMM-6736056-0) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://www.facebook.com - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://www.facebook.com
- https://www.google.com
Embedded domains
- www.facebook.com
- www.google.com
- y5.cc
File paths
- C:\Users\Katy\Desktop\project\poratable
- C:\Users\123\Documents\Visual
- z:\ta6F
- C:\a5pN
- T:\:d:l:t:
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report