MALICIOUS — fdde7d6ec77be3320761a543cca1f715a2527a3462537ec104ad918d65ff6755
MALICIOUS — fdde7d6ec77be3320761a543cca1f715a2527a3462537ec104ad918d65ff6755 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the HUILoader family. 7 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
fdde7d6ec77be3320761a543cca1f715a2527a3462537ec104ad918d65ff6755 - SHA-1:
c201674b4765c58fefecf22353f8cf1f4e912128 - MD5:
18aba2ecd7c743683eb88aa11986fcbf - imphash:
3e4757b6c44f364955a909104e3b2b4d - ssdeep:
3072:egwXxL0Uio0G5d89Xxm5Of5QGsljikMTmAcThAkZThMTMz6IhQcIAYfPcUcUzr0Q:sxL0Sh8SCQGIixTmAcThAkZThMTMnhQD - TLSH:
T1AB407D1772AECD8FC3568EAA3D40951E5893F1CE51B544B086CCEA9E4C69C373E181B2 - Submitted as: fdde7d6ec77be3320761a543cca1f715a2527a3462537ec104ad918d65ff6755
- File type: pe · Size: 174594 bytes
- Verdict: malicious (100/100) · Family: HUILoader
Detections (7 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Genpack-9875154-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:VMProtect
- Microsoft Defender: Trojan:Win32/Ausiv
- Emsisoft (Emergency Kit): GenPack:Trojan.Agent.EXMP
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 14 weighted signals:
- ClamAV (daily) flagged Win.Malware.Genpack-9875154-0 (rule
Win.Malware.Genpack-9875154-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Ausiv (rule
Trojan:Win32/Ausiv) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged GenPack:Trojan.Agent.EXMP (rule
GenPack:Trojan.Agent.EXMP) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win32.Generic (rule
HEUR:Trojan.Win32.Generic) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Contacted 26 external host(s) and 13 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:VMProtect (rule
DIE:VMProtect) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-sections:.lol
1 (rule
high-entropy-sections:.lol 1) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://creativecommons.org/publicdomain/zero/1.0/, https://www.gnu.org/software/automake/manual/automake.html, http://fsmsh.com/2753 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-sections:.lol 1, VMProtect - static signal, weight 0.25, confidence 0.55
- Dropped 10 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (4 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
27408 behavior events · 1 ATT&CK techniques · 98 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- 1.0.240.10.in-addr.arpa.
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 252.0.0.224.in-addr.arpa.
- v10.events.data.microsoft.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 103.223.150.4.in-addr.arpa.
- 167.142.190.20.in-addr.arpa.
- settings-win.data.microsoft.com
- 224.188.247.4.in-addr.arpa.
- nexusrules.officeapps.live.com
- 194.110.171.150.in-addr.arpa.
- _dosvc._tcp.local
- ecs.office.com
- update.googleapis.com
- desktop-hsgcbep
Dropped files
- C:\Program Files\7-Zip\Lang\bn.txt -
a30be99e9e4895831426be40113ce7aaf1d8f7a6cd1dd930f6ad77e14b51d361 - C:\Program Files\7-Zip\Lang\be.txt -
789583c78b0e6b8e8a8760c72074a36ba3cd11c91c774cd1d5043a7c70beb559 - C:\Program Files\7-Zip\Lang\gu.txt -
74d95715a287d639af7e24286eb1c5e0084c849f0efe5ffa9ec7506bd432e937 - C:\Program Files\7-Zip\Lang\nb.txt -
a756330ceca798229210ed05e54f1951d1dfa2f97a466b6df760dd7206e333b3 - C:\Program Files\7-Zip\Lang\gl.txt -
5689db8c9adf099cfa5aebf6128a0e9873d19b4bbe9c52431aeb693642d7454f - C:\bake.ps1 -
3951585165011509e4cafcd4f027818f2d2c1125fb6e02f1cc4e09ca7ae87e23 - 8efbf7a975f393a10eae460d0064466fe948670f70160b2f25b71cb900409242 -
8efbf7a975f393a10eae460d0064466fe948670f70160b2f25b71cb900409242 - C:\Program Files\7-Zip\History.txt -
b362c0339d239a718a6af299220dc1f614036889acf5be26d189517f34a0a376 - C:\Program Files\7-Zip\Lang\fa.txt -
75c75583f472b862a725744885ff028e2295bd1b688f2c8b53ed4a5f39d84244 - C:\Program Files\7-Zip\7-zip.chm -
330180f4c61a40d6a61482ba3f40848b3c92fc106f581e1065bc0aba286f471e - C:\Program Files\7-Zip\Lang\fur.txt -
673b89c231fb872dbc2f0d8b26dd79b745658a3dd430d5817c971146fd5a2c48 - C:\Program Files\7-Zip\Lang\ka.txt -
7a5ca841a16c15bdf6c5a01eabc8610e62b3761b7d8e98bf9d620abf437b5499 - C:\Program Files\7-Zip\descript.ion -
4448e4e08fd05fdb21cfe8592fbad285eb16bbdaf0cf78643299218700be1a7a - C:\Config.Msi\PTA956.tmp -
8fb427bce77966a4e6228c3bf734c563798bcc9d174c926a7d89e7e9a937bb21 - C:\Program Files\7-Zip\Lang\fr.txt -
6e29be9ddf375e0315311eb6d1eea52189fef1dd3fbc71d28329e42c87d1ffe9
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- https://www.gnu.org/software/automake/manual/automake.html
- http://fsmsh.com/2753
- https://autotools.io/index.html
- http://miller.emu.id.au/pmiller/books/rmch/
- http://mozilla.org/MPL/2.0/
- http://developer.mozilla.org/En/DragDrop/Drag_and_Drop
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- tukaani.org
- gmail.com
- creativecommons.org
- www.gnu.org
- fsmsh.com
- autotools.io
- miller.emu.id.au
- mozilla.org
- packet.name
- e.name
- developer.mozilla.org
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 92.223.78.30
- 172.215.188.225
- 172.172.255.218
- 203.26.79.13
- 57.154.63.210
- 57.155.104.224
- 52.123.128.14
- 52.168.117.171
- 4.150.223.103
- 4.247.188.224
- 172.215.188.232
- 20.42.179.204
- 4.150.223.109
- 40.84.85.40
- 4.150.223.106
- 172.178.240.163
- 57.155.101.212
- 172.83.156.122
- 72.145.35.97
- 52.148.114.188
- 135.234.160.245
- 20.42.65.91
- 4.150.223.96
- 13.89.179.12
- 48.211.4.16
File paths
- c:\NetExpressBuild\mozilla-release\services\common\observers.js
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report