Classification:
rans.troj.spyw.expl.evad
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
AI detected malicious Powershell script
Antivirus detection for dropped file
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Contains functionality to register a low level keyboard hook
Contains functionality to steal Chrome passwords or cookies
Contains functionality to steal Firefox passwords or cookies
Contains functionalty to change the wallpaper
Creates an autostart registry key pointing to binary in C:\Windows
Creates autostart registry keys with suspicious values (likely registry only malware)
Creates multiple autostart registry keys
Delayed program exit found
Found malware configuration
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Installs a global keyboard hook
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: Potentially Suspicious Malware Callback Communication
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Rare Remote Thread Creation By Uncommon Source Image
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Executable File Creation
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Tries to delay execution (extensive OutputDebugStringW loop)
Tries to harvest and steal browser information (history, passwords, etc)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
WScript reads language and country specific registry keys (likely country aware script)
Yara detected UAC Bypass using CMSTP
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
1922640
Sample:
payment. 001 11436-06-03-20...
Startdate:
04/06/2026
Architecture:
WINDOWS
Score:
100
104
keyauth.win
2->104
106
geoplugin.net
2->106
114
Suricata IDS alerts
for network traffic
2->114
116
Found malware configuration
2->116
118
Malicious sample detected
(through community Yara
rule)
2->118
120
29 other signatures
2->120
10
payment. 001 11436-06-03-2026.bat.exe
1
7
2->10
started
14
powershell.exe
2->14
started
16
powershell.exe
2->16
started
18
4 other processes
2->18
signatures3
process4
dnsIp5
94
C:\Users\user\AppData\Roaming\HBAoCdxD.exe, PE32
10->94
dropped
96
C:\Users\...\HBAoCdxD.exe:Zone.Identifier, ASCII
10->96
dropped
98
C:\Users\user\AppData\...\dqswgsijdor.ps1, ASCII
10->98
dropped
100
payment. 001 11436...03-2026.bat.exe.log, ASCII
10->100
dropped
142
Creates autostart registry
keys with suspicious
values (likely registry
only malware)
10->142
144
Creates multiple autostart
registry keys
10->144
146
Creates an autostart
registry key pointing
to binary in C:\Windows
10->146
150
2 other signatures
10->150
21
payment. 001 11436-06-03-2026.bat.exe
4
21
10->21
started
26
powershell.exe
23
10->26
started
28
HBAoCdxD.exe
14->28
started
30
conhost.exe
14->30
started
32
HBAoCdxD.exe
16->32
started
34
conhost.exe
16->34
started
108
127.0.0.1
unknown
unknown
18->108
148
Detected Remcos RAT
18->148
36
HBAoCdxD.exe
18->36
started
38
conhost.exe
18->38
started
file6
signatures7
process8
dnsIp9
110
155.103.71.146, 49681, 777
WHITELABELUS
Turkey
21->110
84
C:\Users\user\AppData\Roaming\system32.exe, PE32
21->84
dropped
86
C:\Users\user\AppData\Local\Temp\msuqmy.exe, PE32
21->86
dropped
122
Tries to harvest and
steal browser information
(history, passwords,
etc)
21->122
124
Loading BitLocker PowerShell
Module
21->124
40
msuqmy.exe
21->40
started
44
csc.exe
4
21->44
started
46
csc.exe
21->46
started
56
4 other processes
21->56
48
conhost.exe
26->48
started
50
HBAoCdxD.exe
28->50
started
126
Multi AV Scanner detection
for dropped file
32->126
128
Injects a PE file into
a foreign processes
32->128
52
HBAoCdxD.exe
32->52
started
54
HBAoCdxD.exe
36->54
started
file10
signatures11
process12
file13
88
C:\Users\user\AppData\Local\...\windows32.exe, PE32
40->88
dropped
90
C:\Users\user\AppData\Local\...\install.vbs, data
40->90
dropped
130
Antivirus detection
for dropped file
40->130
132
Multi AV Scanner detection
for dropped file
40->132
134
Detected Remcos RAT
40->134
136
6 other signatures
40->136
58
wscript.exe
40->58
started
92
C:\...\payment. 001 11436-06-03-2026.bat.exe, PE32
44->92
dropped
61
conhost.exe
44->61
started
63
cvtres.exe
44->63
started
65
conhost.exe
46->65
started
67
cvtres.exe
46->67
started
69
cmd.exe
50->69
started
71
conhost.exe
56->71
started
73
cvtres.exe
56->73
started
75
2 other processes
56->75
signatures14
process15
signatures16
138
Windows Scripting host
queries suspicious COM
object (likely to drop
second stage)
58->138
140
WScript reads language
and country specific
registry keys (likely
country aware script)
58->140
77
windows32.exe
69->77
started
82
conhost.exe
69->82
started
process17
dnsIp18
112
geoplugin.net
178.237.33.50
ATOM86-ASATOM86NL
Netherlands
77->112
102
C:\ProgramData\windows32\logs.dat, data
77->102
dropped
152
Antivirus detection
for dropped file
77->152
154
Multi AV Scanner detection
for dropped file
77->154
156
Detected Remcos RAT
77->156
158
Installs a global keyboard
hook
77->158
file19
signatures20
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.