Launcher.exe
C2, crypto, anti-analysis, process injection
Native Windows agent fingerprints the host and executes connected commandsNative PE XOR-decodes host-check configuration and probes hardware
SHA-256c337e85053d20bc82aa33114ed1452a452b21f2aea4be4c849181cc982f66c8f
Evidence
⋯8 more rows
0x4608424c000000031c0488d0d39db090048.$....1.H..9...H
0x4708d1560db09004883f82e741c4189c041..`...H...t.A..A
0x48083e00f458a0410443204084488840460...E...D2..D...`
0x49046010048ffc0ebde0f10842460460100F..H.......$`F..
⋯15 more rows
⋯3 more rows
0x75eb003000300030003000300030003000300................
0x75ec0657870616e642033322d62797465206bexpand 32-byte k
0x75ed00a000100000000000000000000000000................
⋯7 more rows
⋯3 more rows
0x106970b0b0cb7b5454fca8bbbbd66d16163a2c...{TT.....m..:,
0x106980637c777bf26b6fc53001672bfed7ab76c|w{.ko.0.g+...v
0x106990ca82c97dfa5947f0add4a2af9ca472c0...}.YG.......r.
0x1069a0b7fd9326363ff7cc34a5e5f171d83115...&6?..4...q.1.
⋯7 more rows
⋯8 more rows
0x10ffec322e646c6c00435259505433322e646c2.dll.CRYPT32.dl
0x10fffc6c005753325f33322e646c6c00000000l.WS2_32.dll....
0x11000c010401000442000001210c0021682b27.....B...!..!h+'
⋯15 more rows