Hostile 100% vxunderground-inthewild Download

2026-04-25_92a5d73e502866b727416ceeedc7f3ce_agent-tesla_amadey_cobalt-strike_darkgate_glassworm_hawkeye_hellokitty_hijackloader_luca-stealer_njrat_remcos_satacom_smoke-loader_stop_vidar

Embedded malware with stolen signatures

Detects executables signed with stolen, revoked or invalid certificatesComputer-is-done-for infection taunt

Evidence

Signed PE with multiple appended payload binaries (signature-append) 0x0–0xd0
0x04d5a90000300000004000000ffff0000MZ..............
0x10b8000000000000004000000000000000........@.......
0x2000000000000000000000000000000000................
0x30000000000000000000000000f0000000................
⋯10 more rows
MigHost volatile registry write log 0xf519b–0xf51eb
0xf519b494473416e6454797065496e666f3a20IDsAndTypeInfo:
0xf51ab437265617465566f6c6174696c655265CreateVolatileRe
0xf51bb6756616c75652825732c2025732c2025gValue(%s, %s, %
0xf51cb7329206661696c656420676c653d5b30s) failed gle=[0
0xf51db7825785d2e000000005c0000005c0050x%x].....\...\.P
0xf51eb0072 .r
MigHost surrogate command template 0xf5589–0xf5609
0xf558900000000000000550073006100670065.......U.s.a.g.e
0xf5599003a0020000a000a004d006900670048.:. .....M.i.g.H
0xf55a9006f00730074002e0065007800650020.o.s.t...e.x.e.
0xf55b9007b0053007500720072006f00670061.{.S.u.r.r.o.g.a
0xf55c9007400650043004c005300490044007d.t.e.C.L.S.I.D.}
0xf55d90020002f0049006e006900740044006f. ./.I.n.i.t.D.o
0xf55e9006e0065004500760065006e0074003a.n.e.E.v.e.n.t.:
0xf55f9003c006500760065006e0074005f006e.<.e.v.e.n.t._.n
0xf56090061006d0065003e .a.m.e.>
MigHost surrogate DLL server loader path 0xf5fc0–0xf6010
0xf5fc0726f676174652e000000000000000000rogate..........
0xf5fd043004d006900670050006c0075006700C.M.i.g.P.l.u.g.
0xf5fe069006e0053007500720072006f006700i.n.S.u.r.r.o.g.
0xf5ff06100740065003a003a004c006f006100a.t.e.:.:.L.o.a.
0xf6000640044006c006c005300650072007600d.D.l.l.S.e.r.v.
0xf60106500 e.
Parent process watchdog termination string 0xf62e6–0xf6346
0xf62e66f73745465726d696e6174696f6e3a20ostTermination:
0xf62f6506172656e742070726f636573732075Parent process u
0xf63066e65787065637465646c792065786974nexpectedly exit
0xf631665642e205465726d696e6174696e6720ed. Terminating
0xf6326686f73742e000000000043004d006900host......C.M.i.
0xf6336670050006c007500670069006e005300g.P.l.u.g.i.n.S.
0xf63467500720072 u.r.r
Antimalware service executable FileDescription embedded:pe:MsMpEngCP.exe@0x11000 · 0x33d0–0x36c0
⋯8 more rows
0x345000000000000000000000000000000000................
0x3460d80334000000560053005f0056004500..4...V.S._.V.E.
0x34705200530049004f004e005f0049004e00R.S.I.O.N._.I.N.
⋯6 more rows
0x34e014030000010030003400300039003000......0.4.0.9.0.
0x34f034006200300000004c001600010043004.b.0...L.....C.
0x35006f006d00700061006e0079004e006100o.m.p.a.n.y.N.a.
0x35106d006500000000004d00690063007200m.e.....M.i.c.r.
0x35206f0073006f0066007400200043006f00o.s.o.f.t. .C.o.
0x3530720070006f0072006100740069006f00r.p.o.r.a.t.i.o.
0x35406e00000086002f000100460069006c00n...../...F.i.l.
0x355065004400650073006300720069007000e.D.e.s.c.r.i.p.
0x3560740069006f006e000000000041006e00t.i.o.n.....A.n.
0x3570740069006d0061006c00770061007200t.i.m.a.l.w.a.r.
0x358065002000530065007200760069006300e. .S.e.r.v.i.c.
0x359065002000450078006500630075007400e. .E.x.e.c.u.t.
0x35a0610062006c006500200043006f006e00a.b.l.e. .C.o.n.
0x35b0740065006e0074002000500072006f00t.e.n.t. .P.r.o.
0x35c06300650073007300000000003c000e00c.e.s.s.....<...
0x35d0010049006e007400650072006e006100..I.n.t.e.r.n.a.
0x35e06c004e0061006d00650000004d007300l.N.a.m.e...M.s.
⋯14 more rows
Signed PE with multiple appended payload binaries (signature-append) 2026-04-25_92a5d73e502866b727416ceeedc7f3ce_agent-tesla_amadey_cobalt-strike_darkgate_glassworm_hawkeye_hellokitty_hijackloader_luca-stealer_njrat_remcos_satacom_smoke-loader_stop_vidar · 0x0–0xd0
0x04d5a90000300000004000000ffff0000MZ..............
0x10b8000000000000004000000000000000........@.......
0x2000000000000000000000000000000000................
0x30000000000000000000000000f0000000................
⋯10 more rows
MigHost volatile registry write log 2026-04-25_92a5d73e502866b727416ceeedc7f3ce_agent-tesla_amadey_cobalt-strike_darkgate_glassworm_hawkeye_hellokitty_hijackloader_luca-stealer_njrat_remcos_satacom_smoke-loader_stop_vidar · 0xf519b–0xf51eb
0xf519b494473416e6454797065496e666f3a20IDsAndTypeInfo:
0xf51ab437265617465566f6c6174696c655265CreateVolatileRe
0xf51bb6756616c75652825732c2025732c2025gValue(%s, %s, %
0xf51cb7329206661696c656420676c653d5b30s) failed gle=[0
0xf51db7825785d2e000000005c0000005c0050x%x].....\...\.P
0xf51eb0072 .r
MigHost surrogate command template 2026-04-25_92a5d73e502866b727416ceeedc7f3ce_agent-tesla_amadey_cobalt-strike_darkgate_glassworm_hawkeye_hellokitty_hijackloader_luca-stealer_njrat_remcos_satacom_smoke-loader_stop_vidar · 0xf5589–0xf5609
0xf558900000000000000550073006100670065.......U.s.a.g.e
0xf5599003a0020000a000a004d006900670048.:. .....M.i.g.H
0xf55a9006f00730074002e0065007800650020.o.s.t...e.x.e.
0xf55b9007b0053007500720072006f00670061.{.S.u.r.r.o.g.a
0xf55c9007400650043004c005300490044007d.t.e.C.L.S.I.D.}
0xf55d90020002f0049006e006900740044006f. ./.I.n.i.t.D.o
0xf55e9006e0065004500760065006e0074003a.n.e.E.v.e.n.t.:
0xf55f9003c006500760065006e0074005f006e.<.e.v.e.n.t._.n
0xf56090061006d0065003e .a.m.e.>
Computer-is-done-for infection taunt embedded:pe:MsMpEngCP.exe@0x8800 · 0x3ec8–0x4088
⋯9 more rows
0x3f58737472696e6720746f6f206c6f6e6700string too long.
0x3f6857454c4300000000594f552041524520WELC....YOU ARE
0x3f7857454c434f4d452c20594f555220434fWELCOME, YOUR CO
0x3f884d505554455220495320444f4e452046MPUTER IS DONE F
0x3f984f522e20474f4f444259452e00000000OR. GOODBYE.....
0x3fa86e6f74657061642e657865006f70656enotepad.exe.open
0x3fb800000000000000005c77696e646f7773........\windows
0x3fc85c000000000000005c70726f6772616d\.......\program
0x3fd82066696c65735c005c70726f6772616d files\.\program
0x3fe82066696c65732028783836295c000000 files (x86)\...
0x3ff85c73797374656d20766f6c756d652069\system volume i
0x40086e666f726d6174696f6e5c0000000000nformation\.....
0x40185c2472656379636c652e62696e5c0000\$recycle.bin\..
⋯7 more rows

Showing the top 5 files — 13 more files (506 regions) not shown.

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.