108783

Browser hijacker, embedded payload, admin

Mislabeled PE hides an encrypted resource and executes a shell stageRewrites start pages in unrelated browsers
SHA-2561b25b4b600555d93e48bcfa1638dca8c60618308e0064a09d41d4240a1b17fdd

Evidence

Chromium extension enable-warning pref 0x11fb88–0x11fca8
⋯3 more rows
0x11fbb8000000006c6f636174696f6e00000000....location....
0x11fbc8696e7374616c6c5f7761726e696e675finstall_warning_
0x11fbd86f6e5f656e61626c6500000031333030on_enable...1300
0x11fbe8343031373434303636343130340000004017440664104...
⋯12 more rows
Firefox selected search engine preference 0x120b2d–0x120e1d
⋯3 more rows
0x120b5d00610072006300680050006c00750067.a.r.c.h.P.l.u.g
0x120b6d0069006e00200078006d006c006e0073.i.n. .x.m.l.n.s
0x120b7d003d00270068007400740070003a002f.=.'.h.t.t.p.:./
0x120b8d002f007700770077002e006d006f007a./.w.w.w...m.o.z
0x120b9d0069006c006c0061002e006f00720067.i.l.l.a...o.r.g
⋯15 more rows
0x120c9d46696c65206661696c65642028256429File failed (%d)
0x120cad0a00002a000000000000002200680074...*.......".h.t
0x120cbd00740070003a002f002f007300650061.t.p.:././.s.e.a
0x120ccd007200630068002e00620031002e006f.r.c.h...b.1...o
0x120cdd00720067002f003f0062007300720063.r.g./.?.b.s.r.c
⋯8 more rows
0x120d6d0029003b000d000a0000007500730065.).;.......u.s.e
0x120d7d0072005f007000720065006600280022.r._.p.r.e.f.(."
0x120d8d00620072006f0077007300650072002e.b.r.o.w.s.e.r..
0x120d9d007300650061007200630068002e0073.s.e.a.r.c.h...s
0x120dad0065006c006500630074006500640045.e.l.e.c.t.e.d.E
⋯7 more rows
Internet Explorer Main settings key 0x12545b–0x12552b
⋯3 more rows
0x12548b006600740077006100720065005c004d.f.t.w.a.r.e.\.M
0x12549b006900630072006f0073006f00660074.i.c.r.o.s.o.f.t
0x1254ab005c0049006e007400650072006e0065.\.I.n.t.e.r.n.e
0x1254bb00740020004500780070006c006f0072.t. .E.x.p.l.o.r
⋯7 more rows
Firefox startup homepage preference name 0x125553–0x125683
⋯3 more rows
0x125583000000000075007300650072005f0070.....u.s.e.r._.p
0x1255930072006500660028002200620072006f.r.e.f.(.".b.r.o
0x1255a30077007300650072002e007300740061.w.s.e.r...s.t.a
0x1255b30072007400750070002e0068006f006d.r.t.u.p...h.o.m
0x1255c3006500700061006700650022002c0020.e.p.a.g.e.".,.
0x1255d300220025007300220029003b000d000a.".%.s.".).;....
0x1255e3000000000075007300650072005f0070.....u.s.e.r._.p
0x1255f30072006500660028002200620072006f.r.e.f.(.".b.r.o
0x1256030077007300650072002e007300740061.w.s.e.r...s.t.a
0x1256130072007400750070002e0068006f006d.r.t.u.p...h.o.m
⋯7 more rows
Windows uninstall registry key path string 0x1256e8–0x1258e8
⋯3 more rows
0x125718260063006800690064003d0063000000&.c.h.i.d.=.c...
0x12572853004f00460054005700410052004500S.O.F.T.W.A.R.E.
0x1257385c004d006900630072006f0073006f00\.M.i.c.r.o.s.o.
0x125748660074005c00570069006e0064006f00f.t.\.W.i.n.d.o.
0x125758770073005c0043007500720072006500w.s.\.C.u.r.r.e.
0x1257686e007400560065007200730069006f00n.t.V.e.r.s.i.o.
⋯3 more rows
0x1257a872006300680020004200310000000000r.c.h. .B.1.....
0x1257b853004f00460054005700410052004500S.O.F.T.W.A.R.E.
0x1257c85c004d006900630072006f0073006f00\.M.i.c.r.o.s.o.
0x1257d8660074005c00570069006e0064006f00f.t.\.W.i.n.d.o.
0x1257e8770073005c0043007500720072006500w.s.\.C.u.r.r.e.
0x1257f86e007400560065007200730069006f00n.t.V.e.r.s.i.o.
0x1258086e005c0055006e0069006e0073007400n.\.U.n.i.n.s.t.
0x12581861006c006c005c0049006d0070007200a.l.l.\.I.m.p.r.
0x1258286f007600650064002000730065006100o.v.e.d. .s.e.a.
0x125838720063006800000053004f0046005400r.c.h...S.O.F.T.
0x12584857004100520045005c004d0069006300W.A.R.E.\.M.i.c.
0x12585872006f0073006f00660074005c005700r.o.s.o.f.t.\.W.
0x12586869006e0064006f00770073005c004300i.n.d.o.w.s.\.C.
0x12587875007200720065006e00740056006500u.r.r.e.n.t.V.e.
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.