SUSPICIOUS — libiomp5md.dll
SUSPICIOUS — libiomp5md.dll is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (40/100), attributed to the HUILoader family. 1 of 55 detection engines flagged it.
Identification
- SHA-256:
d41a71c38f627a95748596820ab380135dcccc4ceecd6fe7d4e247d015bf55a4 - SHA-1:
98cccbad77d72d69109eb2ff5e6381da0b6f99bc - MD5:
255ca84d684e4f32d257bc3a175d4cdf - imphash:
cefec6f899125b6b6fe0dfc2573aae33 - ssdeep:
49152:8MCN+VX7r+c4zRp5jzDTjzDx5wGv7mkk:8yVmTZj7mkk - TLSH:
T171576AA500173221E5F3AC65F820D9EDE013B954F4711DCAC30BEA2691A9EB7B1F14E9 - Submitted as: libiomp5md.dll
- File type: pe · Size: 1614192 bytes
- Verdict: suspicious (40/100) · Family: HUILoader
Detections (1 of 55 engines)
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
Why this verdict
The suspicious score of 40/100 is the fusion of 2 weighted signals:
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.intel.com/software/products/support/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.intel.com/software/products/support/
- https://sectigo.com/CPS0
- http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
- http://crl.sectigo.com/SectigoPublicTimeStampingRootR46.crl0
- http://crt.sectigo.com/SectigoPublicTimeStampingRootR46.p7c0#
- http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl05
Embedded domains
- www.intel.com
- crl.comodoca.com
- sectigo.com
- crl.sectigo.com
- crt.sectigo.com
- crl.usertrust.com
File paths
- O:\promo\20250910\tmp\win_32e-rtl_int_5_nor_dyn.rel.c0.s0.tcm1.t1..h1.u1-anompclxwin01\libiomp5md.pdb
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report