Hostile 93% windows Download

socolivesa.io_chrome.exe

Ransomware, keylogger, stealer, AV evasion

.NET AES bulk file encryptor with ransom contextRansomware disables Registry Editor and Task Manager

Evidence

.NET AES bulk file encryptor with ransom context 0x54d4–0x5654
⋯7 more rows
0x554400000472ff01007080340000042a0000...r...p.4...*..
0x555442534a4201000100000000000c000000BSJB............
0x556476342e302e3330333139000000000500v4.0.30319......
⋯15 more rows
Paired debugger-check API strings 0x755a–0x77da
⋯4 more rows
0x759a556e686f6f6b57696e646f7773486f6fUnhookWindowsHoo
0x75aa6b45780043616c6c4e657874486f6f6bkEx.CallNextHook
0x75ba4578004765744d6f64756c6548616e64Ex.GetModuleHand
0x75ca6c65004765744173796e634b65795374le.GetAsyncKeySt
0x75da61746500476574466f726567726f756eate.GetForegroun
0x75ea6457696e646f770053797374656d2e54dWindow.System.T
0x75fa65787400537472696e674275696c6465ext.StringBuilde
0x760a720047657457696e646f775465787400r.GetWindowText.
0x761a4f70656e436c6970626f61726400436cOpenClipboard.Cl
0x762a6f7365436c6970626f61726400476574oseClipboard.Get
0x763a436c6970626f6172644461746100476cClipboardData.Gl
0x764a6f62616c4c6f636b00476c6f62616c55obalLock.GlobalU
0x765a6e6c6f636b0049734465627567676572nlock.IsDebugger
0x766a50726573656e740053686f7757696e64Present.ShowWind
0x767a6f770046696e6457696e646f77004765ow.FindWindow.Ge
0x768a7443757272656e7450726f6365737300tCurrentProcess.
0x769a436865636b52656d6f74654465627567CheckRemoteDebug
0x76aa67657250726573656e7400426c6f636bgerPresent.Block
0x76ba496e707574005669727475616c416c6cInput.VirtualAll
0x76ca6f63457800577269746550726f636573ocEx.WriteProces
0x76da734d656d6f7279004372656174655265sMemory.CreateRe
0x76ea6d6f7465546872656164004f70656e50moteThread.OpenP
0x76fa726f63657373004e74536574496e666frocess.NtSetInfo
0x770a726d6174696f6e546872656164004765rmationThread.Ge
0x771a7443757272656e745468726561640053tCurrentThread.S
0x772a797374656d506172616d657465727349ystemParametersI
0x773a6e666f004578697457696e646f777345nfo.ExitWindowsE
0x774a7800536574437572736f72506f73006dx.SetCursorPos.m
0x775a6f7573655f6576656e74005f6b657962ouse_event._keyb
0x776a6f61726450726f63005f686f6f6b4944oardProc._hookID
⋯7 more rows
Ransomware disables Registry Editor and Task Manager 0xb3ea–0xb59a
⋯7 more rows
0xb45a5c00530079007300740065006d000029\.S.y.s.t.e.m..)
0xb46a440069007300610062006c0065005200D.i.s.a.b.l.e.R.
0xb47a65006700690073007400720079005400e.g.i.s.t.r.y.T.
0xb48a6f006f006c007300001d440069007300o.o.l.s...D.i.s.
0xb49a610062006c0065005400610073006b00a.b.l.e.T.a.s.k.
0xb4aa4d0067007200006953004f0046005400M.g.r..iS.O.F.T.
⋯15 more rows
Hosts file modification to block AV domains 0xb6d6–0xb896
⋯3 more rows
0xb70653006500720076006900630065000013S.e.r.v.i.c.e...
0xb716570069006e0044006500660065006e00W.i.n.D.e.f.e.n.
0xb7266400000f4d0073004d00700053007600d...M.s.M.p.S.v.
⋯3 more rows
0xb76674003d00200064006900730061006200t.=. .d.i.s.a.b.
0xb7766c0065006400001b6b00610073007000l.e.d...k.a.s.p.
0xb7866500720073006b0079002e0063006f00e.r.s.k.y...c.o.
0xb7966d0000156d0063006100660065006500m...m.c.a.f.e.e.
0xb7a62e0063006f006d000019730079006d00..c.o.m...s.y.m.
0xb7b661006e007400650063002e0063006f00a.n.t.e.c...c.o.
0xb7c66d000013610076006100730074002e00m...a.v.a.s.t...
0xb7d663006f006d00001f6200690074006400c.o.m...b.i.t.d.
0xb7e66500660065006e006400650072002e00e.f.e.n.d.e.r...
0xb7f663006f006d0000116500730065007400c.o.m...e.s.e.t.
0xb8062e0063006f006d00001d740072006500..c.o.m...t.r.e.
0xb8166e0064006d006900630072006f002e00n.d.m.i.c.r.o...
0xb82663006f006d0000216d0061006c007700c.o.m..!m.a.l.w.
0xb83661007200650062007900740065007300a.r.e.b.y.t.e.s.
0xb8462e0063006f006d00001d760069007200..c.o.m...v.i.r.
0xb8567500730074006f00740061006c002e00u.s.t.o.t.a.l...
0xb86663006f006d0000153100320037002e00c.o.m...1.2.7...
⋯3 more rows
Kernel driver tooling references 0xc34f–0xc48f
⋯3 more rows
0xc37f740065006300740069006f006e00000ft.e.c.t.i.o.n...
0xc38f7400610073006b006d0067007200000ft.a.s.k.m.g.r...
0xc39f700072006f006300650078007000001bp.r.o.c.e.x.p...
0xc3af700072006f0063006500730073006800p.r.o.c.e.s.s.h.
0xc3bf610063006b0065007200001370007200a.c.k.e.r...p.r.
0xc3cf6f006300650078007000360034000077o.c.e.x.p.6.4..w
0xc3df48004b00450059005f004c004f004300H.K.E.Y._.L.O.C.
0xc3ef41004c005f004d004100430048004900A.L._.M.A.C.H.I.
0xc3ff4e0045005c0053005900530054004500N.E.\.S.Y.S.T.E.
0xc40f4d005c00430075007200720065006e00M.\.C.u.r.r.e.n.
0xc41f740043006f006e00740072006f006c00t.C.o.n.t.r.o.l.
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.