Hostile 92% windows Download

cakhiatvz.vc_hyber.exe

.NET AES bulk file encryptor with ransom contextfodhelper DelegateExecute hijack

Evidence

.NET AES bulk file encryptor with ransom context 0x4738–0x48b8
⋯7 more rows
0x47a800000a801f0000041480200000042a00.......... ...*.
0x47b842534a4201000100000000000c000000BSJB............
0x47c876342e302e3330333139000000000500v4.0.30319......
⋯15 more rows
Paired debugger-check API strings 0x694f–0x6b8f
⋯4 more rows
0x698f556e686f6f6b57696e646f7773486f6fUnhookWindowsHoo
0x699f6b45780043616c6c4e657874486f6f6bkEx.CallNextHook
0x69af4578004765744d6f64756c6548616e64Ex.GetModuleHand
0x69bf6c65004765744173796e634b65795374le.GetAsyncKeySt
0x69cf617465004f70656e436c6970626f6172ate.OpenClipboar
0x69df6400436c6f7365436c6970626f617264d.CloseClipboard
0x69ef00476574436c6970626f617264446174.GetClipboardDat
0x69ff6100476c6f62616c4c6f636b00476c6fa.GlobalLock.Glo
0x6a0f62616c556e6c6f636b00497344656275balUnlock.IsDebu
0x6a1f6767657250726573656e740053686f77ggerPresent.Show
0x6a2f57696e646f770046696e6457696e646fWindow.FindWindo
0x6a3f770047657443757272656e7450726f63w.GetCurrentProc
0x6a4f65737300436865636b52656d6f746544ess.CheckRemoteD
0x6a5f6562756767657250726573656e740042ebuggerPresent.B
0x6a6f6c6f636b496e70757400566972747561lockInput.Virtua
0x6a7f6c416c6c6f6345780057726974655072lAllocEx.WritePr
0x6a8f6f636573734d656d6f72790043726561ocessMemory.Crea
0x6a9f746552656d6f7465546872656164004fteRemoteThread.O
0x6aaf70656e50726f63657373004e74536574penProcess.NtSet
⋯14 more rows
.NET downloads remote EXE and launches hidden 0x7b24–0x7e14
⋯7 more rows
0x7b945f45786563757461626c655061746800_ExecutablePath.
0x7ba452656164416c6c427974657300436f6eReadAllBytes.Con
0x7bb47665727400546f426173653634537472vert.ToBase64Str
⋯3 more rows
0x7bf40045786973747300496e74333200436f.Exists.Int32.Co
0x7c046d62696e65005772697465416c6c5465mbine.WriteAllTe
0x7c1478740050726f63657373005374617274xt.Process.Start
0x7c24004472697665496e666f004765744472.DriveInfo.GetDr
0x7c3469766573004472697665547970650067ives.DriveType.g
0x7c4465745f44726976655479706500676574et_DriveType.get
0x7c545f526f6f744469726563746f72790046_RootDirectory.F
⋯5 more rows
0x7cb474655375624b65790053657456616c75teSubKey.SetValu
0x7cc46500436f7079006765745f4973526561e.Copy.get_IsRea
0x7cd464790044656275676765725374657054dy.DebuggerStepT
0x7ce468726f75676841747472696275746500hroughAttribute.
⋯12 more rows
0x7db4706172616d30005365617263684f7074param0.SearchOpt
0x7dc4696f6e0047657446696c657300456e64ion.GetFiles.End
0x7dd4735769746800436f6e7461696e730057sWith.Contains.W
0x7de472697465416c6c42797465730044656criteAllBytes.Del
0x7df46574650044656c617900476574417761ete.Delay.GetAwa
0x7e0469746572006765745f4973436f6d706citer.get_IsCompl
0x7e1465746564004177616974556e73616665eted.AwaitUnsafe
References DisableRegistryTools policy key 0x9c6c–0x9dac
⋯6 more rows
0x9ccc0063006900650073005c005300790073.c.i.e.s.\.S.y.s
0x9cdc00740065006d00002944006900730061.t.e.m..)D.i.s.a
0x9cec0062006c006500520065006700690073.b.l.e.R.e.g.i.s
0x9cfc0074007200790054006f006f006c0073.t.r.y.T.o.o.l.s
0x9d0c00001d440069007300610062006c0065...D.i.s.a.b.l.e
0x9d1c005400610073006b004d006700720000.T.a.s.k.M.g.r..
0x9d2c6953004f004600540057004100520045iS.O.F.T.W.A.R.E
⋯8 more rows
vssadmin delete shadows 0xa4c2–0xa7a2
⋯10 more rows
0xa562000f640065006c002e00620061007400..d.e.l...b.a.t.
0xa5720077760073007300610064006d006900.wv.s.s.a.d.m.i.
0xa5826e002000640065006c00650074006500n. .d.e.l.e.t.e.
0xa592200073006800610064006f0077007300 .s.h.a.d.o.w.s.
0xa5a220002f0061006c006c0020002f007100 ./.a.l.l. ./.q.
0xa5b275006900650074000a0077006d006900u.i.e.t...w.m.i.
⋯18 more rows
0xa6e272002d004100670065006e0074000180r.-.A.g.e.n.t...
0xa6f2e74d006f007a0069006c006c0061002f.M.o.z.i.l.l.a./
0xa7020035002e00300020002800570069006e.5...0. .(.W.i.n
⋯10 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.