Threat name:
Clipboard Hijacker, Sirius Rat, XWorm
Alert
Classification:
rans.troj.spyw.expl.evad
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
Antivirus detection for dropped file
Antivirus detection for URL or domain
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Contains functionality to hide user accounts
Contains functionality to start a terminal service
Creates processes via WMI
Deletes shadow drive data (may be related to ransomware)
Detected large data written to user environment variables, potentially indicating payload staging for fileless execution
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for submitted file
Obfuscated command line found
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sigma detected: Capture Wi-Fi password
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: Potential PowerShell Command Line Obfuscation
Sigma detected: Potentially Suspicious Malware Callback Communication
Sigma detected: Potentially Suspicious PowerShell Child Processes
Sigma detected: PowerShell DownloadFile
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: Windows Shell/Scripting Application File Write to Suspicious Folder
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
Tries to access browser extension known for cryptocurrency wallets
Tries to detect sandboxes / dynamic malware analysis system (Installed program check)
Tries to download and execute files (via powershell)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal WLAN passwords
Tries to steal Mail credentials (via file / registry access)
Uses an obfuscated file name to hide its real file extension (double extension)
Uses netsh to modify the Windows network and firewall settings
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Yara detected Clipboard Hijacker
Yara detected Generic Stealer
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
1964577
Sample:
inv-2026-06.PDF.vbs
Startdate:
27/08/2026
Architecture:
WINDOWS
Score:
100
81
ryanborn.net
2->81
83
www.google.com
2->83
85
8 other IPs or domains
2->85
111
Suricata IDS alerts
for network traffic
2->111
113
Found malware configuration
2->113
115
Malicious sample detected
(through community Yara
rule)
2->115
117
31 other signatures
2->117
12
powershell.exe
14
15
2->12
started
16
wscript.exe
1
2->16
started
18
powershell.exe
3
17
2->18
started
21
powershell.exe
2->21
started
signatures3
process4
dnsIp5
89
195.177.94.230, 49745, 49746, 49753
STELLARGROUPSASFR
France
12->89
91
ryanborn.net
66.96.131.133, 443, 49744, 49752
BIZLAND-SD-NewfoldDigitalIncUS
United States
12->91
135
Found many strings related
to Crypto-Wallets (likely
being stolen)
12->135
137
Writes to foreign memory
regions
12->137
139
Injects a PE file into
a foreign processes
12->139
23
CasPol.exe
1
9
12->23
started
28
conhost.exe
12->28
started
141
Windows Scripting host
queries suspicious COM
object (likely to drop
second stage)
16->141
143
Creates processes via
WMI
16->143
145
Detected large data
written to user environment
variables, potentially
indicating payload staging
for fileless execution
16->145
69
C:\Users\Public\Libraries\nvshLwYPPZ.vbs, ASCII
18->69
dropped
30
wscript.exe
1
18->30
started
file6
signatures7
process8
dnsIp9
87
31.40.204.71, 49747, 49757, 7070
WHITELABELUS
Turkey
23->87
73
C:\Users\user\AppData\Roaming\scvost.exe, PE32
23->73
dropped
75
C:\Users\user\AppData\Local\Temp\ilklqn.vbs, ASCII
23->75
dropped
125
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
23->125
127
Contains functionality
to check if a debugger
is running (CheckRemoteDebuggerPresent)
23->127
32
wscript.exe
1
23->32
started
35
CasPol.exe
23->35
started
37
csc.exe
23->37
started
129
Detected large data
written to user environment
variables, potentially
indicating payload staging
for fileless execution
30->129
file10
signatures11
process12
file13
93
Wscript starts Powershell
(via cmd or directly)
32->93
95
Obfuscated command line
found
32->95
97
Windows Scripting host
queries suspicious COM
object (likely to drop
second stage)
32->97
101
3 other signatures
32->101
40
powershell.exe
32->40
started
43
powershell.exe
15
32->43
started
99
Antivirus detection
for dropped file
35->99
71
C:\Users\user\AppData\Local\Temp\CasPol.exe, PE32
37->71
dropped
45
conhost.exe
37->45
started
47
cvtres.exe
37->47
started
signatures14
process15
signatures16
119
Writes to foreign memory
regions
40->119
121
Modifies the context
of a thread in another
process (thread injection)
40->121
123
Injects a PE file into
a foreign processes
40->123
49
CasPol.exe
40->49
started
53
conhost.exe
40->53
started
55
conhost.exe
43->55
started
57
CasPol.exe
43->57
started
process17
dnsIp18
79
ip-api.com
208.95.112.1, 49756, 80
TUT-AS-TotalUptimeTechnologiesLLCUS
United States
49->79
103
Tries to harvest and
steal Putty / WinSCP
information (sessions,
passwords, etc)
49->103
105
Tries to steal Mail
credentials (via file
/ registry access)
49->105
107
Tries to harvest and
steal browser information
(history, passwords,
etc)
49->107
109
4 other signatures
49->109
59
cmd.exe
49->59
started
signatures19
process20
file21
77
C:\Users\user\AppData\...\wifi_profiles.tmp, ASCII
59->77
dropped
131
Uses netsh to modify
the Windows network
and firewall settings
59->131
133
Tries to harvest and
steal WLAN passwords
59->133
63
conhost.exe
59->63
started
65
chcp.com
59->65
started
67
netsh.exe
59->67
started
signatures22
process23
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.