MALICIOUS — db2660a02c76125cdd1b203cfd20bdab4ecaa51e8739765ca6713b1549460056
MALICIOUS — db2660a02c76125cdd1b203cfd20bdab4ecaa51e8739765ca6713b1549460056 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the HUILoader family. 7 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
db2660a02c76125cdd1b203cfd20bdab4ecaa51e8739765ca6713b1549460056 - SHA-1:
62210c2c65ff3a802847392e32db82938bd1ca04 - MD5:
7c3cf926261f4ec07d41f9fa9bf63cbb - imphash:
3e4757b6c44f364955a909104e3b2b4d - ssdeep:
3072:egwXxL0Uio0G5d89Xxm5Of5QGsljikMTmAcThAkZThMTMz62hrN+8d7G:sxL0Sh8SCQGIixTmAcThAkZThMTMbtG - TLSH:
T1713FAF5B602FEC5FC3165A9F3E40862E2C4EE1C4A2B4B8E043CDD91D4469C6BFA59076 - Submitted as: db2660a02c76125cdd1b203cfd20bdab4ecaa51e8739765ca6713b1549460056
- File type: pe · Size: 151112 bytes
- Verdict: malicious (99/100) · Family: HUILoader
Detections (7 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Genpack-9875154-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:VMProtect
- Microsoft Defender: Trojan:Win32/Ausiv
- Emsisoft (Emergency Kit): GenPack:Trojan.Agent.EXMP
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Win.Malware.Genpack-9875154-0 (rule
Win.Malware.Genpack-9875154-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - Contacted 29 external host(s) at runtime (21 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:VMProtect (rule
DIE:VMProtect) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://creativecommons.org/publicdomain/zero/1.0/, https://www.gnu.org/software/automake/manual/automake.html, http://fsmsh.com/2753 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-sections:.lol 1, VMProtect - static signal, weight 0.25, confidence 0.55
- Dropped 83 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Extracted generic config (4 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
25470 behavior events · 0 ATT&CK techniques · 98 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Dropped files
- C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\java.dll -
edb57fb9a6ba20598e63f2269882c0021557bd00979ef5bd90cc697e7a8bd96f - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\kinit.exe -
59cf08c4d9f0cdc20218c6536aa9bb939730e4ce37ca73be0b1df134f87a5dd6 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\keytool.exe -
29f3d67dc1470265f341d8af52e143802238164ca2768317a5483ee510e2fa52 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-interlocked-l1-1-0.dll -
a718322f072566cf65e496468e636f2ce54f2ad1c479ac6990905feee5983353 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-fibers-l1-1-0.dll -
f53e97c6ee87e01b83890b373796e194e5627338cbbc98a9801116e4ec5b38c4 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-fibers-l1-1-1.dll -
afa4f9c421467a339f70eee3c33e9836c8495453467865334229274b09a2517d - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jaas.dll -
37016b28cac4e2414730c8eef8ca57883bd6e147732975d75b5e2c090e1639ae - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-file-l1-1-0.dll -
666633c96ee2052e6e8a7b928b8b737d625503d45322e768c8fdc560e558ad60 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\javaw.exe -
6a8cf31f0be94d15a0b7a77acaac192a87398eb9683986a59602aab6476f57b5 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-synch-l1-2-0.dll -
e13facbdd5c2f7bd96dc549241822c768078cb9d60a9958433e4af400a98cb1b - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-crt-stdio-l1-1-0.dll -
db803b13beaff8ef251bf7b71b5ff10b0f898a8ffd84ab8baf8ac13bfe5f7079 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-crt-conio-l1-1-0.dll -
63089f1dd348d8094898bb8ddc80483ecd76dcf23b2b96a5a52dc5f2b86e86c0 - C:\$Recycle.Bin\S-1-5-21-976637724-599762485-334819845-1001\desktop.ini -
c3e50cf4f8aa34afe4a88c0c013ee4a99aae8ed8a1234a1608955cc033652b36 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\dt_socket.dll -
55f24defb9d4a42f4fb651d25f08ea8ad76da52da074eb5eddfe995ac3356abf - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\api-ms-win-core-synch-l1-1-0.dll -
4bbdf861eb5e3911b208514e552ddd7eec476b972a7d1247324b0a3db8ac52f0
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- https://www.gnu.org/software/automake/manual/automake.html
- http://fsmsh.com/2753
- https://autotools.io/index.html
- http://miller.emu.id.au/pmiller/books/rmch/
- http://mozilla.org/MPL/2.0/
- https://developer.mozilla.org/en-US/docs/SpiderMonkey/Parser_API
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787847648&P2=404&P3=2&P4=jreIcnwP47PDM4oad3D8ANX%2bbkw1Lc7Mdpj2Yb%2bdL8%2bHYTMA1gqNOa6g4pfDB45oBl6zYY2ThUJXUMpxJbXyEQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787847719&P2=404&P3=2&P4=Xyjb1t5mVSEWzTmYSyarcK94l8nmoAS7sS%2bMXRpgzpEOxv8IOGtzsP5K6qqL2KNjijM8w7Z7yx8Q46N%2bDOPLzw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- tukaani.org
- gmail.com
- creativecommons.org
- www.gnu.org
- fsmsh.com
- autotools.io
- miller.emu.id.au
- mozilla.org
- developer.mozilla.org
- tt.name
- dummy.name
- node.name
- tt.in
- prop.key.name
Embedded IP addresses
- 13.69.239.69
- 52.123.252.216
- 20.247.185.124
- 52.123.252.244
- 4.230.171.124
- 48.211.4.16
- 52.123.252.202
- 74.178.240.61
- 74.178.232.29
- 4.150.223.112
- 52.123.252.225
- 203.26.79.13
- 20.231.239.246
- 52.123.128.14
- 40.99.134.18
- 52.123.129.14
- 40.99.134.2
- 20.165.94.54
- 20.42.73.30
- 135.234.160.245
- 52.110.12.14
- 52.110.12.37
- 52.148.114.188
- 52.123.252.240
- 172.215.188.232
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report