SUSPICIOUS — virussign.com_2a86deb6a50417b7d741e9b443070d70.vir
SUSPICIOUS — virussign.com_2a86deb6a50417b7d741e9b443070d70.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (40/100), attributed to the HUILoader family. 2 of 52 detection engines flagged it.
Identification
- SHA-256:
d4c949390a610f3de7815f1a359b5b227fa78be1ab42bad0b0cf239295e2eac3 - SHA-1:
2306803dd3d40e47bb25594f5c23a5c31e95f2b4 - MD5:
2a86deb6a50417b7d741e9b443070d70 - imphash:
40ab50289f7ef5fae60801f88d4541fc - ssdeep:
49152:K+MRvHGjV7R4AZYoF67MZ2Z9ftchfudg87dqn7iMK7tX:KrAJWYxF+MYchXqdnMO5 - TLSH:
T1E25BCFAA971A3D32DBA797212862BE3E08F7AC5B03F7C84841E1C61FC5F5817256111E - Submitted as: virussign.com_2a86deb6a50417b7d741e9b443070d70.vir
- File type: pe · Size: 2174502 bytes
- Verdict: suspicious (40/100) · Family: HUILoader
Source: VirusSign · first seen 2026-08-11T00:00:00.000Z · SHA-256 verified
Detections (2 of 52 engines)
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Kaspersky (KVRT): Trojan-Dropper.Win32.Sysn.duqe
Why this verdict
The suspicious score of 40/100 is the fusion of 2 weighted signals:
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://jrsoftware.org/ishelp/index.php?topic=setupcmdline, 6.4.0.1 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- https://jrsoftware.org/ishelp/index.php?topic=setupcmdline
Embedded domains
- schemas.microsoft.com
- jrsoftware.org
Embedded IP addresses
- 6.4.0.1
File paths
- G:\:n:t:
- T:\:`:h:l:t:x:
- X:\:`:d:h:l:p:t:x:
- T:\:d:l:p:t:x:
- X:\:t:
- X:\:`:d:h:l:p:
- X:\:`:d:h:l:p:t:
- G:\:j:
- T:\:j:
- L:\:`:d:l:t:x:
- N:\:l:}:
- X:\:`:d:h:l:p:x:
- T:\:d:l:t:
- x:\dirname
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report