Suspicious
Signed Huorong tool with PUA detection, direct-IP behavior, and UPX packing raises moderate concern.
d7212aa08e8b02523f…4eed174edcThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The combination of a verified Huorong signature, Sophos recognizing the product, and absence of malicious sandbox or child verdicts points away from outright malware. However, the Microsoft Trojan flag, UPX packing, direct-IP contact without DNS, and two triggered heuristics create a borderline profile typical of either a legitimate security utility or a signed dropper. No prior signer history or similar-hash precedents exist to resolve the ambiguity.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
Sophos tier1 detection 'Huorong HRSword (PUA)' directly names the signer vendor
Microsoft tier1 'Trojan:Win32/Wacatac.B!ml' + 2 low-trust malicious labels
triggeredHeuristics: MalwareTips.Synth.DirectIpC2 and DropperNetworkProfile (high severity)
signing.verified=true by 北京火绒网络科技有限公司 with offensive MITRE techniques present
- Verified signature from Huorong
- Sophos explicitly names Huorong product
- No malicious sandbox verdict
- No malicious dropped children
- Direct IP contact without DNS resolution
- UPX packing + high entropy code
- Microsoft Trojan detection
- Offensive MITRE techniques present
- Rare new prevalence
Treat as suspicious; do not execute on production systems until independently verified as an official Huorong utility.
Huorong HRSword corroborated by 1 source
- MT AI EngineHuorong HRSword
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
- C:\Users\<USER>\AppData\Local\Temp\BF87.tmp
- C:\Windows\sysnative\drivers\3PMQFOOk.sys
- C:\Users\<USER>\AppData\Local\Temp\D0CE.tmp
- C:\Users\<USER>\AppData\Local\Temp\E0FB.tmp
- C:\Windows\System32\drivers\dgZBNTjlSM.sys
- C:\Users\<USER>\AppData\Local\Temp\E0FB.tmp
- C:\Users\user\AppData\Local\Temp\206F.tmp
- C:\Users\user\AppData\Local\Temp\BC93.tmp
- C:\Windows\System32\drivers\5vz_Sv1qdyfY3K.sys
- C:\Windows\System32\drivers\UYAjTEAZmNf1Ml.sys
- HRKILLUI
- \Sessions\1\BaseNamedObjects\HRKILLUI
Files this sample writes at runtime
This file drops 4 children at runtime. None are currently flagged malicious in our cache.
- 114b0d6799ec2563969c…cd4e5cNever scannednever seen before
- 6272e419c24523f3e0a1…b556d5Never scannednever seen before
- d3bd429836092aa05c3d…473796Never scannednever seen before
- 23b8be7673546c504142…e072c1Never scannednever seen before
YARA + heuristic rules that fired
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence162.159.36.2Packed PE with sandbox-observed network activity AND engine flags. Signed packed software exists legitimately, but a signed + packed + flagged binary is a signed dropper pattern.
Evidence162.159.36.2
4 detections across 75 engines
Section entropy & packers
Executable sections have high entropy (7.2+) — the code is compressed or encrypted and only decrypted at runtime. Classic packing behaviour.
How often this file shows up in the wild
Barely seen in the wild and first surfaced recently. This is the footprint of targeted malware the AV industry hasn't signatured yet — extra scrutiny is warranted.
Forensic fingerprint
- File name
- HRKill.exe
- Size
- 1.92 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- d7212aa08e8b02523f616b5890ce3b36fa0b175ce610ba43eca4ec4eed174edc
- MD5
- c6f185c1f4a91b6781dfc1cc066a383c
- SHA-1
- 84575c61ef1716f4893e6122feac196143008d6f
- PE imphash
- 08a50973e4f11e1488878b3c6f569bf8
- First seen (VT)
- 5/19/2026, 3:19:43 AM
- Last analysis (VT)
- 5/19/2026, 12:02:04 PM
- First scan (MalwareTips)
- 5/19/2026, 12:27:21 PM
- Last scan (MalwareTips)
- 5/19/2026, 1:34:23 PM
- Code signer
- 北京火绒网络科技有限公司verified
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.