Hostile 100% datamaliciousorder Download

Virus.Hijack_Gen.Trojan.ShellObject.f8W@aSZtDuk_7_1.vir

Trojan downloader with C2 and evasion

WinInet ZIP downloader stages and executes temp payloadExecution capability with minimal imports
SHA-256d46727368a6b822d5d61baffa2be3dbe061afa74fa1be241c73c6e57430b240a

Evidence

Execution capability with minimal imports 0x0–0xd0
0x04d5a90000300000004000000ffff0000MZ..............
0x10b8000000000000004000000000000000........@.......
0x2000000000000000000000000000000000................
⋯11 more rows
HttpQueryInfo API name as string 0x9d0–0xcc0
⋯12 more rows
0xa906b0069006c00660031002e0065007800k.i.l.f.1...e.x.
0xaa0650000006170706c69636174696f6e2fe...application/
0xab02a000000746578742f2a000055007000*...text/*..U.p.
0xac064006100740065007300200064006f00d.a.t.e.s. .d.o.
0xad077006e006c006f006100640065007200w.n.l.o.a.d.e.r.
0xae00000000052746c4465636f6d70726573....RtlDecompres
0xaf073427566666572006e00740064006c00sBuffer.n.t.d.l.
0xb006c002e0064006c006c0000006f007000l...d.l.l...o.p.
⋯17 more rows
0xc209f00496e7465726e6574526561644669..InternetReadFi
0xc306c6500005a0048747470517565727949le..Z.HttpQueryI
0xc406e666f5700005e004874747053656e64nfoW..^.HttpSend
0xc5052657175657374570000570048747470RequestW..W.Http
0xc604f70656e526571756573744100007100OpenRequestA..q.
0xc70496e7465726e6574436f6e6e65637441InternetConnectA
0xc8000009a00496e7465726e65744f70656e....InternetOpen
0xc90570057494e494e45542e646c6c00ce02W.WININET.dll...
0xca04865617044657374726f7900bf014765HeapDestroy...Ge
0xcb07443757272656e744469726563746f72tCurrentDirector
0xcc079570000b204536c6565700062014672yW....Sleep.b.Fr
Embedded manifest literal requests administrator 0x1288–0x1458
⋯7 more rows
0x12f874656450726976696c656765733e0d0atedPrivileges>..
0x130820202020202020203c72657175657374 <request
0x13186564457865637574696f6e4c6576656cedExecutionLevel
0x1328206c6576656c3d227265717569726541 level="requireA
0x1338646d696e6973747261746f7222207569dministrator" ui
0x13484163636573733d2266616c7365223e3cAccess="false"><
⋯17 more rows
Random-named executable in root directory 0x19e6–0x1c56
0x19e663003000340066003000350064003900c.0.4.f.0.5.d.9.
0x19f6310063006400360030003900660030001.c.d.6.0.9.f.0.
0x1a06320063003500320062003300370066002.c.5.2.b.3.7.f.
0x1a1664006200660063003300650000000000d.b.f.c.3.e.....
0x1a2643003a005c0055007300650072007300C.:.\.U.s.e.r.s.
0x1a365c004a006f0065002000430061006700\.J.o.e. .C.a.g.
0x1a4665005c004400650073006b0074006f00e.\.D.e.s.k.t.o.
0x1a5670005c0079004f006f00510043006b00p.\.y.O.o.Q.C.k.
0x1a667000390057004d002e00650078006500p.9.W.M...e.x.e.
0x1a760000000043003a005c00390035004a00....C.:.\.9.5.J.
0x1a86770076004700670043002e0065007800w.v.G.g.C...e.x.
0x1a9665000000000043003a005c0033006500e.....C.:.\.3.e.
0x1aa6390032003300300066006500360037009.2.3.0.f.e.6.7.
0x1ab6340030003100350039006400620033004.0.1.5.9.d.b.3.
0x1ac661003100650034003500370065003800a.1.e.4.5.7.e.8.
0x1ad665006400610030003900660031003200e.d.a.0.9.f.1.2.
0x1ae665003100360066003400650063006600e.1.6.f.4.e.c.f.
0x1af6310065003100660061006200330033001.e.1.f.a.b.3.3.
0x1b0662006300350038003300340032003800b.c.5.8.3.4.2.8.
0x1b16330031003100330034003800000000003.1.1.3.4.8.....
0x1b2643003a005c0035003800330068003100C.:.\.5.8.3.h.1.
0x1b364400520032002e006500780065000000D.R.2...e.x.e...
0x1b46000043003a005c006f00430055004a00..C.:.\.o.C.U.J.
0x1b564d003200560047002e00650078006500M.2.V.G...e.x.e.
0x1b660000000043003a005c00420033007a00....C.:.\.B.3.z.
0x1b76700071006700560069002e0065007800p.q.g.V.i...e.x.
0x1b8665000000000043003a005c005a003000e.....C.:.\.Z.0.
0x1b963800650037004700650044002e0065008.e.7.G.e.D...e.
0x1ba6780065000000000043003a005c005500x.e.....C.:.\.U.
0x1bb673006500720073005c00670065006f00s.e.r.s.\.g.e.o.
0x1bc67200670065005c004400650073006b00r.g.e.\.D.e.s.k.
0x1bd674006f0070005c00700072006f006700t.o.p.\.p.r.o.g.
0x1be6720061006d002e006500780065000000r.a.m...e.x.e...
0x1bf6000043003a005c003800300033006500..C.:.\.8.0.3.e.
0x1c06330064003500610035003100380039003.d.5.a.5.1.8.9.
0x1c1662003000630036006600380066003500b.0.c.6.f.8.f.5.
0x1c26340064003500320065003400390062004.d.5.2.e.4.9.b.
0x1c36350062006600300062003900360034005.b.f.0.b.9.6.4.
0x1c4661003600610031006600660034003300a.6.a.1.f.f.4.3.
0x1c566400310039 d.1.9
Open HTTP request via WinInet 0x2f80–0x3180
0x2f8000000000000000000000000000000000................
0x2f9000000000000000000000000000000000................
0x2fa000000000000000000000000000000000................
0x2fb000000000000000000000000000000000................
0x2fc000000000000000000000000000000000................
0x2fd000000000000000000000000000000000................
0x2fe000000000000000000000000000000000................
0x2ff000000000000000000000000000000000................
0x300043003a005c0055007300650072007300C.:.\.U.s.e.r.s.
0x30105c004600720061006e006b005c004400\.F.r.a.n.k.\.D.
0x3020650073006b0074006f0070005c007a00e.s.k.t.o.p.\.z.
0x30304c006d0049006f00630066006a002e00L.m.I.o.c.f.j...
0x30406500780065000000000043003a005c00e.x.e.....C.:.\.
0x3050550073006500720073005c0061006400U.s.e.r.s.\.a.d.
0x30606d0069006e005c0044006f0077006e00m.i.n.\.D.o.w.n.
0x30706c006f006100640073005c0066003400l.o.a.d.s.\.f.4.
0x308064003100620062003700640034006400d.1.b.b.7.d.4.d.
0x309062003900310034003100630035003800b.9.1.4.1.c.5.8.
0x30a0390036006500370066006500620030009.6.e.7.f.e.b.0.
0x30b0370063003600360032006300300035007.c.6.6.2.c.0.5.
0x30c064003800660031006600300062003600d.8.f.1.f.0.b.6.
0x30d066003000660039003500300036006100f.0.f.9.5.0.6.a.
0x30e0310034006500390031003300330032001.4.e.9.1.3.3.2.
0x30f03400300033006300340062002e0065004.0.3.c.4.b...e.
0x3100780065000000000043003a005c005500x.e.....C.:.\.U.
0x311073006500720073005c0072002e007600s.e.r.s.\.r...v.
0x312075006c0074005c004100700070004400u.l.t.\.A.p.p.D.
0x31306100740061005c004c006f0063006100a.t.a.\.L.o.c.a.
0x31406c005c00540065006d0070005c006300l.\.T.e.m.p.\.c.
0x3150360033006400330037003500300032006.3.d.3.7.5.0.2.
0x3160350062006600630066003800630034005.b.f.c.f.8.c.4.
0x3170330065006500360038003500650064003.e.e.6.8.5.e.d.
0x3180660063003500370036003500 f.c.5.7.6.5.

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.