Hostile 92% vxunderground-inthewild Download

2026-04-25_5b632befe6a1ca127461d596acfc0bf9_agent-tesla_amadey_cobalt-strike_darkgate_hawkeye_icedid_luca-stealer_njrat_remcos_satacom

Multi-stage malware with injection

Repeated PE images appended by a self-enumerating file rewriterDetects executables signed with stolen, revoked or invalid certificates
SHA-2567fa99e940e7e3d909f5a455e22ade1c3180953801e28fbcd0a028f9abb1d9885

Evidence

English function-word token "this" 0x0–0x120
0x04d5a90000300000004000000ffff0000MZ..............
0x10b8000000000000004000000000000000........@.......
0x2000000000000000000000000000000000................
0x30000000000000000000000000f0000000................
0x400e1fba0e00b409cd21b8014ccd215468........!..L.!Th
0x5069732070726f6772616d2063616e6e6fis program canno
⋯13 more rows
StrStrIW casefold substring scan import 0xefd0–0xf2c0
⋯3 more rows
0xf00000000000000000000000000000000000................
0xf01000000000000000000000000000000000................
0xf02000000000000000000000000000000000................
0xf03000000000000000000000000000000000................
0xf04020002000200020002000200020002000 . . . . . . . .
0xf05020002800280028002800280020002000 .(.(.(.(.(. . .
0xf06020002000200020002000200020002000 . . . . . . . .
0xf07020002000200020002000200020002000 . . . . . . . .
0xf08048001000100010001000100010001000H...............
0xf09010001000100010001000100010001000................
0xf0a084008400840084008400840084008400................
0xf0b084008400100010001000100010001000................
0xf0c010008100810081008100810081000100................
0xf0d001000100010001000100010001000100................
0xf0e001000100010001000100010001000100................
0xf0f001000100010010001000100010001000................
0xf10010008200820082008200820082000200................
0xf11002000200020002000200020002000200................
0xf12002000200020002000200020002000200................
0xf13002000200020010001000100010002000.............. .
0xf14000000000000000000000000000000000................
0xf15000000000000000000000000000000000................
0xf16000000000000000000000000000000000................
0xf17000000000000000000000000000000000................
0xf18000000000000000000000000000000000................
0xf19000000000000000000000000000000000................
0xf1a000000000000000000000000000000000................
0xf1b000000000000000000000000000000000................
0xf1c000000000000000000000000000000000................
0xf1d000000000000000000000000000000000................
0xf1e000000000000000000000000000000000................
0xf1f000000000000000000000000000000000................
0xf20000000000000000000000000000000000................
0xf21000000000000000000000000000000000................
0xf22000000000000000000000000000000000................
0xf23000000000000000000000000000000000................
0xf24000002000200020002000200020002000.. . . . . . . .
0xf25020002000680028002800280028002000 . .h.(.(.(.(. .
0xf26020002000200020002000200020002000 . . . . . . . .
0xf27020002000200020002000200020002000 . . . . . . . .
0xf28020004800100010001000100010001000 .H.............
0xf29010001000100010001000100010001000................
0xf2a010008400840084008400840084008400................
0xf2b084008400840010001000100010001000................
0xf2c010001000810181018101810181018101................
Four or more embedded standard PE images 0x18d80–0x18f20
⋯7 more rows
0x18df000000000000000000000000000000000................
0x18e004d5a90000300000004000000ffff0000MZ..............
0x18e10b8000000000000004000000000000000........@.......
0x18e2000000000000000000000000000000000................
0x18e30000000000000000000000000f0000000................
⋯15 more rows
References GetLogicalDrives API name 0x2041c–0x205fc
⋯6 more rows
0x2047c00000000de0043726561746546696c65......CreateFile
0x2048c41009d0146696e64436c6f736500a101A...FindClose...
0x2049c46696e64466972737446696c65410000FindFirstFileA..
0x204acb20146696e644e65787446696c654100..FindNextFileA.
0x204bc59024765744472697665547970654100Y.GetDriveTypeA.
0x204cc770247657446696c6553697a65009402w.GetFileSize...
0x204dc4765744c6f676963616c447269766573GetLogicalDrives
0x204ec0000a9045265616446696c6500006006....ReadFile..`.
0x204fc577269746546696c6500280347657454WriteFile.(.GetT
0x2050c656d7050617468410000240347657454empPathA..$.GetT
0x2051c656d7046696c654e616d654100009d00empFileNameA....
0x2052c436c6f736548616e646c6500a0024765CloseHandle...Ge
0x2053c744d6f64756c6546696c654e616d6541tModuleFileNameA
0x2054c00004b45524e454c33322e646c6c0000..KERNEL32.dll..
0x2055c92024d657373616765426f7841005553..MessageBoxA.US
0x2056c455233322e646c6c0000ac015368656cER32.dll....Shel
0x2057c6c4578656375746541005348454c4c33lExecuteA.SHELL3
0x2058c322e646c6c008e023f5f586c656e67742.dll...?_Xlengt
⋯7 more rows
Antimalware service executable FileDescription 0x2d30c–0x2d43c
⋯5 more rows
0x2d35c69007000740069006f006e0000000000i.p.t.i.o.n.....
0x2d36c41006e00740069006d0061006c007700A.n.t.i.m.a.l.w.
0x2d37c61007200650020005300650072007600a.r.e. .S.e.r.v.
0x2d38c69006300650020004500780065006300i.c.e. .E.x.e.c.
⋯11 more rows
English function-word token "this" 0x0–0x120
0x04d5a90000300000004000000ffff0000MZ..............
0x10b8000000000000004000000000000000........@.......
0x2000000000000000000000000000000000................
0x30000000000000000000000000f0000000................
0x400e1fba0e00b409cd21b8014ccd215468........!..L.!Th
0x5069732070726f6772616d2063616e6e6fis program canno
⋯13 more rows
StrStrIW casefold substring scan import 0xefd0–0xf2c0
⋯3 more rows
0xf00000000000000000000000000000000000................
0xf01000000000000000000000000000000000................
0xf02000000000000000000000000000000000................
0xf03000000000000000000000000000000000................
0xf04020002000200020002000200020002000 . . . . . . . .
0xf05020002800280028002800280020002000 .(.(.(.(.(. . .
0xf06020002000200020002000200020002000 . . . . . . . .
0xf07020002000200020002000200020002000 . . . . . . . .
0xf08048001000100010001000100010001000H...............
0xf09010001000100010001000100010001000................
0xf0a084008400840084008400840084008400................
0xf0b084008400100010001000100010001000................
0xf0c010008100810081008100810081000100................
0xf0d001000100010001000100010001000100................
0xf0e001000100010001000100010001000100................
0xf0f001000100010010001000100010001000................
0xf10010008200820082008200820082000200................
0xf11002000200020002000200020002000200................
0xf12002000200020002000200020002000200................
0xf13002000200020010001000100010002000.............. .
0xf14000000000000000000000000000000000................
0xf15000000000000000000000000000000000................
0xf16000000000000000000000000000000000................
0xf17000000000000000000000000000000000................
0xf18000000000000000000000000000000000................
0xf19000000000000000000000000000000000................
0xf1a000000000000000000000000000000000................
0xf1b000000000000000000000000000000000................
0xf1c000000000000000000000000000000000................
0xf1d000000000000000000000000000000000................
0xf1e000000000000000000000000000000000................
0xf1f000000000000000000000000000000000................
0xf20000000000000000000000000000000000................
0xf21000000000000000000000000000000000................
0xf22000000000000000000000000000000000................
0xf23000000000000000000000000000000000................
0xf24000002000200020002000200020002000.. . . . . . . .
0xf25020002000680028002800280028002000 . .h.(.(.(.(. .
0xf26020002000200020002000200020002000 . . . . . . . .
0xf27020002000200020002000200020002000 . . . . . . . .
0xf28020004800100010001000100010001000 .H.............
0xf29010001000100010001000100010001000................
0xf2a010008400840084008400840084008400................
0xf2b084008400840010001000100010001000................
0xf2c010001000810181018101810181018101................
Four or more embedded standard PE images 0x18d80–0x18f20
⋯7 more rows
0x18df000000000000000000000000000000000................
0x18e004d5a90000300000004000000ffff0000MZ..............
0x18e10b8000000000000004000000000000000........@.......
0x18e2000000000000000000000000000000000................
0x18e30000000000000000000000000f0000000................
⋯15 more rows
References GetLogicalDrives API name 0x2041c–0x205fc
⋯6 more rows
0x2047c00000000de0043726561746546696c65......CreateFile
0x2048c41009d0146696e64436c6f736500a101A...FindClose...
0x2049c46696e64466972737446696c65410000FindFirstFileA..
0x204acb20146696e644e65787446696c654100..FindNextFileA.
0x204bc59024765744472697665547970654100Y.GetDriveTypeA.
0x204cc770247657446696c6553697a65009402w.GetFileSize...
0x204dc4765744c6f676963616c447269766573GetLogicalDrives
0x204ec0000a9045265616446696c6500006006....ReadFile..`.
0x204fc577269746546696c6500280347657454WriteFile.(.GetT
0x2050c656d7050617468410000240347657454empPathA..$.GetT
0x2051c656d7046696c654e616d654100009d00empFileNameA....
0x2052c436c6f736548616e646c6500a0024765CloseHandle...Ge
0x2053c744d6f64756c6546696c654e616d6541tModuleFileNameA
0x2054c00004b45524e454c33322e646c6c0000..KERNEL32.dll..
0x2055c92024d657373616765426f7841005553..MessageBoxA.US
0x2056c455233322e646c6c0000ac015368656cER32.dll....Shel
0x2057c6c4578656375746541005348454c4c33lExecuteA.SHELL3
0x2058c322e646c6c008e023f5f586c656e67742.dll...?_Xlengt
⋯7 more rows
Antimalware service executable FileDescription 0x2d30c–0x2d43c
⋯5 more rows
0x2d35c69007000740069006f006e0000000000i.p.t.i.o.n.....
0x2d36c41006e00740069006d0061006c007700A.n.t.i.m.a.l.w.
0x2d37c61007200650020005300650072007600a.r.e. .S.e.r.v.
0x2d38c69006300650020004500780065006300i.c.e. .E.x.e.c.
⋯11 more rows

Showing the top 5 files — 2 more files (40 regions) not shown.

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.