Suspicious 85% vxunderground-inthewild Download

2026-04-25_40d61aa97ca1ee887dfd3f36de9da508_agent-tesla_amadey_cobalt-strike_darkgate_elex_glassworm_hawkeye_hijackloader_icedid_luca-stealer_njrat_remcos_smoke-loader_stealc_vidar_wannacry

Stolen certs, keylogging, and embedded malware

Detects executables signed with stolen, revoked or invalid certificatesOffice Source Engine service description

Evidence

Execute shell command (ShellExecuteA) 0x21b8–0x2218
0x21b8c228000002290000de2a000000000000.(...)...*......
0x21c8c22a000000000000302a00003e2a0000.*......0*..>*..
0x21d84e2a00005a2a0000202a00007e2a0000N*..Z*.. *..~*..
0x21e88a2a0000962a0000a62a00006a2a0000.*...*...*..j*..
0x21f8142a0000042a0000f829000000000000.*...*...)......
0x220800104000102240001101000000000000..@.."@.........
0x221846e1000046e100000c00000010164000F...F.........@.
Embedded PE binary at file offset 0x5000 (~262144 bytes) 0x4ff0–0x5040
0x4ff000000000000000000000000000000000................
0x50004d5a90000300000004000000ffff0000MZ..............
0x5010b8000000000000004000000000000000........@.......
0x502000000000000000000000000000000000................
0x503000000000000000000000000010010000................
0x50400e1fba0e00b409cd21b8014ccd2154 ........!..L.!T
Encoded payload detected: hex 0x2c723–0x2c763
0x2c7236f73652e706462006f73652e70646200ose.pdb.ose.pdb.
0x2c733303030303030303030303030303030300000000000000000
0x2c743303030303030303030303030303030300000000000000000
0x2c753303030303030303030303030303030300000000000000000
0x2c763303030 000
Office Source Engine service description 0x3dd98–0x3ddf8
0x3dd986e3d22312e302e302e3022202f3e0d0an="1.0.0.0" />..
0x3dda8093c6465736372697074696f6e3e4d69.<description>Mi
0x3ddb863726f736f6674204f66666963652053crosoft Office S
0x3ddc86f7572636520456e67696e653c2f6465ource Engine</de
0x3ddd8736372697074696f6e3e0d0a093c7472scription>...<tr
0x3dde8757374496e666f20786d6c6e733d2275ustInfo xmlns="u
0x3ddf8726e3a736368656d61 rn:schema
RunDll32Main export token inside stage 0x1f61ea–0x1f621a
0x1f61ea000055534552454e562e646c6c000200..USERENV.dll...
0x1f61fa52756e446c6c33324d61696e00006469RunDll32Main..di
0x1f620a6167747261636b2e646c6c007005536cagtrack.dll.p.Sl
0x1f621a65657000a105556e68616e64 eep...Unhand

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.