2026-04-25_6e79dd9710c59dcc64b9022172ee3213_agent-tesla_amadey_cobalt-strike_darkgate_glassworm_hawkeye_hellokitty_hijackloader_luca-stealer_njrat_remcos_satacom_smoke-loader_stealc_stop_vidar
Multi-malware dropper with embedded payloads
Windows binary downloads a file, executes a process, and cleans up a fileDrive walker stages multi-PE stack via Temp execute
SHA-2561ac441c452d2a7f45cf6dfd2a9a29c13515a1f207487d242f2cfb998861c5117
Evidence
0x04d5a90000300000004000000ffff0000MZ..............
0x10b8000000000000004000000000000000........@.......
0x2000000000000000000000000000000000................
0x30000000000000000000000000f0000000................
0x400e1fba0e00b409cd21b8014ccd215468........!..L.!Th
0x5069732070726f6772616d2063616e6e6fis program canno
⋯13 more rows
⋯3 more rows
0x4ff000010203060708090e0f0a0b0c0d0e0f................
0x50000203060708090e0f08090a0b0c0d0e0f................
0x50100001060708090e0f08090a0b0c0d0e0f................
0x5020060708090e0f060708090a0b0c0d0e0f................
0x503000010203040508090e0f0a0b0c0d0e0f................
0x50400203040508090e0f08090a0b0c0d0e0f................
0x50500001040508090e0f08090a0b0c0d0e0f................
0x5060040508090e0f060708090a0b0c0d0e0f................
0x50700001020308090e0f08090a0b0c0d0e0f................
0x5080020308090e0f060708090a0b0c0d0e0f................
0x5090000108090e0f060708090a0b0c0d0e0f................
0x50a008090e0f0405060708090a0b0c0d0e0f................
0x50b000010203040506070e0f0a0b0c0d0e0f................
0x50c00203040506070e0f08090a0b0c0d0e0f................
0x50d00001040506070e0f08090a0b0c0d0e0f................
⋯15 more rows
⋯3 more rows
0x7680de0043726561746546696c6541009d01..CreateFileA...
0x769046696e64436c6f736500a10146696e64FindClose...Find
0x76a0466972737446696c65410000b2014669FirstFileA....Fi
0x76b06e644e65787446696c65410059024765ndNextFileA.Y.Ge
0x76c074447269766554797065410077024765tDriveTypeA.w.Ge
0x76d07446696c6553697a650094024765744ctFileSize...GetL
0x76e06f676963616c4472697665730000a904ogicalDrives....
0x76f05265616446696c650000600657726974ReadFile..`.Writ
0x77006546696c6500280347657454656d7050eFile.(.GetTempP
0x7710617468410000240347657454656d7046athA..$.GetTempF
0x7720696c654e616d654100009d00436c6f73ileNameA....Clos
0x77306548616e646c6500a0024765744d6f64eHandle...GetMod
0x7740756c6546696c654e616d654100004b45uleFileNameA..KE
0x7750524e454c33322e646c6c000092024d65RNEL32.dll....Me
0x77607373616765426f784100555345523332ssageBoxA.USER32
0x77702e646c6c0000ac015368656c6c457865.dll....ShellExe
0x77806375746541005348454c4c33322e646ccuteA.SHELL32.dl
0x77906c008e023f5f586c656e6774685f6572l...?_Xlength_er
⋯8 more rows
⋯7 more rows
0x87f000000000000000000000000000000000................
0x88004d5a90000300000004000000ffff0000MZ..............
0x8810b8000000000000004000000000000000........@.......
0x882000000000000000000000000000000000................
0x8830000000000000000000000000e8000000................
⋯32 more rows
⋯3 more rows
0x3b6bb84f4c4541555433322e646c6c00006800OLEAUT32.dll..h.
0x3b6bc855524c446f776e6c6f6164546f46696cURLDownloadToFil
0x3b6bd86557000075726c6d6f6e2e646c6c0000eW..urlmon.dll..
0x3b6be800000000000000000000000000000000................
⋯7 more rows