MALICIOUS — 4507816e4942a66caa4986c5e732386aea8679f9b5253a5e17959416825e6b08.bin
MALICIOUS — 4507816e4942a66caa4986c5e732386aea8679f9b5253a5e17959416825e6b08.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the HUILoader family. 1 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
4507816e4942a66caa4986c5e732386aea8679f9b5253a5e17959416825e6b08 - SHA-1:
feb0a5a4280eef41b7fa96be26e4698eb30804a2 - MD5:
d101c0eeb89ce736928a061f100337de - imphash:
658d5752126daf1d08b007afbea71e97 - File type: pe · Size: 767488 bytes
- Verdict: malicious (89/100) · Family: HUILoader
Source: MalShare · first seen 2026-08-05T16:59:18.449Z · SHA-256 verified
Detections (1 of 52 engines)
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
MITRE ATT&CK
Dynamic analysis (windows)
1925 behavior events · 1 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- c.pki.goog
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- assets.msn.com
- msedge.api.cdp.microsoft.com
- tas02.sls.update.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
Dropped files
- a2bdfb5ef3ecf3c4cfa3569e87dcab7626d5ad3cfd70dc9d58b89ce33e600b09 —
a2bdfb5ef3ecf3c4cfa3569e87dcab7626d5ad3cfd70dc9d58b89ce33e600b09 - 46f8788685d144576ddfdef2e93770f27682745659143dbe55e92049995362ae —
46f8788685d144576ddfdef2e93770f27682745659143dbe55e92049995362ae
Embedded URLs
- https://curl.se/docs/http-cookies.html
- https://curl.se/docs/alt-svc.html
- https://curl.se/docs/hsts.html
- https://api.prestigeclient.vip
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786554107&P2=404&P3=2&P4=IxHhzTYzm5%2bFyT0yRMUeMDWcEdHfZXDHKxeqUYXKRvgR2RP0Q25bWxPNtixoYfbMg1lU0hjWIJkkDGM3kNx6WA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://c.pki.goog/r/gsr1.crl
- http://c.pki.goog/r/r4.crl
- http://c.pki.goog/we1/BwYkd5XkY8c.crl
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786554165&P2=404&P3=2&P4=eiWZ%2bYiygLP0Cya2gnn8aTL1vCJqJQp4FWxe2xYUOUcNm5dH%2fu5yPRNNOO6BVa0CMK7C3nHk8XsD0d%2fNNvhknw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- curl.se
- example.com
- api.prestigeclient.vip
- oneclient.sfx.ms
Embedded IP addresses
- 1.101.3.4
- 172.67.137.182
- 20.42.73.30
- 4.230.171.124
- 48.211.4.16
- 52.230.60.54
- 135.233.95.144
- 74.178.76.54
- 13.69.239.69
- 52.110.12.24
- 20.184.175.19
- 74.178.76.44
- 52.110.12.20
- 203.26.79.13
- 52.253.84.76
- 4.144.132.223
- 135.233.45.223
- 92.223.78.30
- 20.184.175.3
- 52.168.117.168
- 142.251.42.99
- 172.66.2.5
- 72.145.35.101
- 20.184.175.0
- 52.123.129.14
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report