MALICIOUS — FastFlagManager_Installer.exe
MALICIOUS — FastFlagManager_Installer.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (77/100), attributed to the HUILoader family. 3 of 56 detection engines flagged it.
Identification
- SHA-256:
f8364e020bfd2ce12cf2bdc95782d8d2875b708f0321e5904725d02c59983a24 - SHA-1:
dd94257dd396fda83f367d8422c241ec0469a561 - MD5:
6970b1c189d7890631fd756969720d52 - imphash:
88016fcdef7f227c62171d0afad9aae4 - ssdeep:
393216:ccDW8GZfzYxAMXQIgHowmBR+2+h+CcR5IHqfw6Ao02WY:jGZfzS9KHfmBY3Hkw6A9O - TLSH:
T12671238A7F5B7612D72A97201160B97E04F3AC4F47BF4A8801A5AB2FD2F481714D139B - Submitted as: FastFlagManager_Installer.exe
- File type: pe · Size: 18048708 bytes
- Verdict: malicious (77/100) · Family: HUILoader
Detections (3 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): Turbo Linker
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:Turbo Linker
Why this verdict
The malicious score of 77/100 is the fusion of 5 weighted signals:
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged Turbo Linker (rule
Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://jrsoftware.org/ishelp/index.php?topic=setupcmdline - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: Turbo Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- https://jrsoftware.org/ishelp/index.php?topic=setupcmdline
Embedded domains
- schemas.microsoft.com
- r.za
- 4.xyz
- 5.eu
- w.to
- n.ca
- n.fr
- d.it
- jrsoftware.org
File paths
- T:\:d:l:p:t:x:
- X:\:`:d:h:l:p:t:x:
- N:\:k:
- E:\:
- X:\:`:h:p:x:
- U:\:c:j:t:
- T:\:j:x:
- X:\:d:h:p:t:x:
- T:\:d:l:t:
- S:\\m
- p:\!
- E:\mT
- H:\U80s
- D:\Coding\Is\issrc-build\Components\ChaCha20.pas
- x:\dirname
More HUILoader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report