SUSPICIOUS — WinSCP.com
SUSPICIOUS — WinSCP.com is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (59/100), attributed to the HUILoader family. 2 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f1c35da6c40b6a59a7c90af257b06f725f71f329831214a9d752efdb9aead3d6 - SHA-1:
e5a48da33c7d7c5d744b9da96ae05133b050fcf4 - MD5:
b4a2a324ff6bfeb6363dee01e65d62c3 - imphash:
cd85ea9f90ff4cc6db76ce254dc32721 - ssdeep:
6144:HB4I919IMtpYS93NmjQ5veNbR9AsVUB6:SI919IMt+S93NmjQ5S9AkQ6 - TLSH:
T10B458E04620B52DBF9E79968D5623F4CC072F0AF507E109C59B7E10E6BBB4CB905E21A - Submitted as: WinSCP.com
- File type: pe · Size: 283328 bytes
- Verdict: suspicious (59/100) · Family: HUILoader
Detections (2 of 55 engines)
- capa (capabilities): capability:collection/keylog
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
MITRE ATT&CK
Why this verdict
The suspicious score of 59/100 is the fusion of 3 weighted signals:
- capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://winscp.net/eng/docs/executables, https://winscp.net/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://www.digicert.com/CPS0
- https://winscp.net/eng/docs/executables
- https://winscp.net/
Embedded domains
- cacerts.digicert.com
- crl3.digicert.com
- www.digicert.com
- crl4.digicert.com
- winscp.net
- winscp.com
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report