SUSPICIOUS — virussign.com_9038758bff170371c6196ffceb5839a0.vir
SUSPICIOUS — virussign.com_9038758bff170371c6196ffceb5839a0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (40/100), attributed to the HUILoader family. 2 of 51 detection engines flagged it.
Identification
- SHA-256:
e22ae9b54baf6409b90c7c0b06e72f037ea80fbc1321e63c07082df5868e0e9d - SHA-1:
e616b4c9982ffa0f43b9b3dcda88893728a8c6ca - MD5:
9038758bff170371c6196ffceb5839a0 - imphash:
40ab50289f7ef5fae60801f88d4541fc - ssdeep:
49152:n+MRvH2xlAqkmH31f767MZ2Z9ftchfudg87dqn7iMk:nrejAqBf7+MYchXqdnMk - TLSH:
T1405CD0AA971A3D32CBA797212462BE3E08F7AC4B03F7CC4846E1861FC5F5817256151E - Submitted as: virussign.com_9038758bff170371c6196ffceb5839a0.vir
- File type: pe · Size: 2452336 bytes
- Verdict: suspicious (40/100) · Family: HUILoader
Source: VirusSign · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (2 of 51 engines)
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Kaspersky (KVRT): Backdoor.Win32.Xkcp.dih
Why this verdict
The suspicious score of 40/100 is the fusion of 2 weighted signals:
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://jrsoftware.org/ishelp/index.php?topic=setupcmdline, 6.4.0.1 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- https://jrsoftware.org/ishelp/index.php?topic=setupcmdline
Embedded domains
- schemas.microsoft.com
- jrsoftware.org
Embedded IP addresses
- 6.4.0.1
File paths
- G:\:n:t:
- T:\:`:h:l:t:x:
- X:\:`:d:h:l:p:t:x:
- T:\:d:l:p:t:x:
- X:\:t:
- X:\:`:d:h:l:p:
- X:\:`:d:h:l:p:t:
- G:\:j:
- T:\:j:
- L:\:`:d:l:t:x:
- N:\:l:}:
- X:\:`:d:h:l:p:x:
- T:\:d:l:t:
- s:\8`
- x:\dirname
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report