Hostile 93% windows Download

happytreasure.io_ransome.exe

Ransomware with stealer, C2, evasion

fodhelper DelegateExecute hijackHosts file modification to block AV domains

Evidence

.NET AES/Rijndael crypto evidence 0x39c4–0x3a84
⋯3 more rows
0x39f467320105010000011e02282600000a2ag2........(&...*
0x3a0442534a4201000100000000000c000000BSJB............
0x3a1476342e302e3330333139000000000500v4.0.30319......
⋯7 more rows
Video for Windows capture window 0x517a–0x546a
⋯12 more rows
0x523a444f574e005f70726f63005f686f6f6bDOWN._proc._hook
0x524a49440053797374656d2e546578740053ID.System.Text.S
0x525a7472696e674275696c646572005f6275tringBuilder._bu
0x526a66666572005f61637469766557696e64ffer._activeWind
0x527a6f77005f6c6f636b0053657457696e64ow._lock.SetWind
0x528a6f7773486f6f6b457800556e686f6f6bowsHookEx.Unhook
0x529a57696e646f7773486f6f6b4578004361WindowsHookEx.Ca
0x52aa6c6c4e657874486f6f6b457800476574llNextHookEx.Get
0x52ba4d6f64756c6548616e646c6500476574ModuleHandle.Get
⋯9 more rows
0x535a5645525f434f4e4e45435400574d5f43VER_CONNECT.WM_C
0x536a41505f53415645444942006361704372AP_SAVEDIB.capCr
0x537a656174654361707475726557696e646feateCaptureWindo
0x538a77410053656e644d6573736167650044wA.SendMessage.D
0x539a657374726f7957696e646f7700776176estroyWindow.wav
0x53aa65496e4765744e756d44657673005357eInGetNumDevs.SW
0x53ba5f484944450050524f434553535f4352_HIDE.PROCESS_CR
0x53ca454154455f5448524541440050524f43EATE_THREAD.PROC
⋯8 more rows
0x545a5554444f574e004557585f5245424f4fUTDOWN.EWX_REBOO
0x546a54004557585f464f524345005350495fT.EWX_FORCE.SPI_
PE combines PowerShell and stdio 0x6425–0x66b5
⋯3 more rows
0x6455690049734e756c6c4f72456d70747900i.IsNullOrEmpty.
0x6465507472546f537472696e67416e736900PtrToStringAnsi.
0x64753c537461727453637265656e73686f74<StartScreenshot
0x64854c6f6f703e625f5f35004353243c3e39Loop>b__5.CS$<>9
0x64955f5f436163686564416e6f6e796d6f75__CachedAnonymou
0x64a5734d6574686f6444656c656761746536sMethodDelegate6
0x64b50053637265656e006765745f5072696d.Screen.get_Prim
0x64c561727953637265656e0053797374656daryScreen.System
0x64d52e44726177696e670052656374616e67.Drawing.Rectang
⋯4 more rows
0x65256765006765745f58006765745f590053ge.get_X.get_Y.S
0x6535697a65006765745f53697a6500436f70ize.get_Size.Cop
0x65457946726f6d53637265656e004d656d6fyFromScreen.Memo
0x6555727953747265616d0053797374656d2eryStream.System.
0x656544726177696e672e496d6167696e6700Drawing.Imaging.
0x6575496d616765466f726d6174006765745fImageFormat.get_
0x65854a7065670053747265616d0053617665Jpeg.Stream.Save
0x659500546f4172726179003c537461727453.ToArray.<StartS
0x65a57465616c65723e625f5f37004353243ctealer>b__7.CS$<
0x65b53e395f5f436163686564416e6f6e796d>9__CachedAnonym
0x65c56f75734d6574686f6444656c65676174ousMethodDelegat
0x65d56538007365745f526564697265637453e8.set_RedirectS
0x65e574616e646172644f7574707574005374tandardOutput.St
0x65f57265616d526561646572006765745f53reamReader.get_S
0x660574616e646172644f7574707574005465tandardOutput.Te
0x661578745265616465720052656164546f45xtReader.ReadToE
0x66256e64005365617263684f7074696f6e00nd.SearchOption.
0x663547657446696c65730046696c65496e66GetFiles.FileInf
0x66456f0046696c6553797374656d496e666fo.FileSystemInfo
⋯7 more rows
fodhelper DelegateExecute hijack 0x753a–0x782a
⋯3 more rows
0x756a61006c006c0044006100740065000011a.l.l.D.a.t.e...
0x757a7300630068007400610073006b007300s.c.h.t.a.s.k.s.
0x758a00552f00630072006500610074006500.U/.c.r.e.a.t.e.
⋯3 more rows
0x75ca6400610074006500220020002f007400d.a.t.e.". ./.t.
0x75da7200200022000021220020002f007300r. ."..!". ./.s.
0x75ea630020006f006e006c006f0067006f00c. .o.n.l.o.g.o.
0x75fa6e0020002f0066000061530059005300n. ./.f..aS.Y.S.
⋯8 more rows
0x768a70002e0065007800650000092f006100p...e.x.e.../.a.
0x769a7500200000196500760065006e007400u. ...e.v.e.n.t.
0x76aa7600770072002e006500780065000080v.w.r...e.x.e...
0x76ba8348004b00450059005f004300550052.H.K.E.Y._.C.U.R
0x76ca00520045004e0054005f005500530045.R.E.N.T._.U.S.E
0x76da0052005c0053006f0066007400770061.R.\.S.o.f.t.w.a
0x76ea00720065005c0043006c006100730073.r.e.\.C.l.a.s.s
0x76fa00650073005c006d0073002d00730065.e.s.\.m.s.-.s.e
0x770a007400740069006e00670073005c0073.t.t.i.n.g.s.\.s
0x771a00680065006c006c005c006f00700065.h.e.l.l.\.o.p.e
0x772a006e005c0063006f006d006d0061006e.n.\.c.o.m.m.a.n
0x773a006400011f440065006c006500670061.d...D.e.l.e.g.a
0x774a00740065004500780065006300750074.t.e.E.x.e.c.u.t
0x775a006500001b66006f006400680065006c.e...f.o.d.h.e.l
0x776a007000650072002e0065007800650000.p.e.r...e.x.e..
0x777a813d2d0043006f006d006d0061006e00.=-.C.o.m.m.a.n.
⋯11 more rows
Hosts file modification to block AV domains 0x7fa8–0x8298
⋯3 more rows
0x7fd87000650072002e006500780065000017p.e.r...e.x.e...
0x7fe86100750074006f00720075006e002e00a.u.t.o.r.u.n...
0x7ff869006e00660000415b00410075007400i.n.f..A[.A.u.t.
0x80086f00520075006e005d000a006f007000o.R.u.n.]...o.p.
0x801865006e003d0053007900730074006500e.n.=.S.y.s.t.e.
⋯14 more rows
0x8108740046006f006c006400650072000007t.F.o.l.d.e.r...
0x81182a002e002a000017520041004e005300*...*...R.A.N.S.
0x81284f004d005f004e004f00540045000015O.M._.N.O.T.E...
0x8138530079007300740065006d0052006f00S.y.s.t.e.m.R.o.
0x81486f00740000375c005300790073007400o.t..7\.S.y.s.t.
0x815865006d00330032005c00640072006900e.m.3.2.\.d.r.i.
0x816876006500720073005c00650074006300v.e.r.s.\.e.t.c.
0x81785c0068006f00730074007300005f0a00\.h.o.s.t.s.._..
0x81883100320037002e0030002e0030002e001.2.7...0...0...
0x81983100200067006f006f0067006c0065001. .g.o.o.g.l.e.
0x81a82e0063006f006d000a00310032003700..c.o.m...1.2.7.
⋯3 more rows
0x81e873007300610064006d0069006e000035s.s.a.d.m.i.n..5
0x81f8640065006c0065007400650020007300d.e.l.e.t.e. .s.
0x82086800610064006f007700730020002f00h.a.d.o.w.s. ./.
⋯9 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.