Threat name:
GCleaner, REMUS Stealer, Vidar
Alert
Classification:
troj.spyw.evad.mine
Allocates memory in foreign processes
Antivirus detection for dropped file
C2 URLs / IPs found in malware configuration
Contains functionality to registers a callback to get notified when the system is suspended or resumed (often done by Miners)
Creates a thread in another existing process (thread injection)
Creates HTML files with .exe extension (expired dropper behavior)
Detected unpacking (creates a PE file in dynamic memory)
DNS related to crypt mining pools
Early bird code injection technique detected
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Hides threads from debuggers
Hooks files or directories query functions (used to hide files and directories)
Hooks processes query functions (used to hide processes)
Hooks registry keys query functions (used to hide registry keys)
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Modifies the context of a thread in another process (thread injection)
Modifies the prolog of user mode functions (user mode inline hooks)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Potentially malicious time measurement code found
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Queues an APC in another process (thread injection)
Sigma detected: Rare Remote Thread Creation By Uncommon Source Image
Sigma detected: Silenttrinity Stager Msbuild Activity
Suricata IDS alerts for network traffic
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Crypto Currency Wallets
Tries to steal from password manager
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Uses known network protocols on non-standard ports
Uses the Windows Restart Manager Abuse for Browser Credential File unlocking
Uses whoami command line tool to query computer and username
Writes to foreign memory regions
Yara detected MSIL Injector
Yara detected REMUS Stealer
Yara detected Vidar stealer
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
1957968
Sample:
Setup.exe
Startdate:
14/08/2026
Architecture:
WINDOWS
Score:
100
122
xmr-eu1.nanopool.org
2->122
124
45.91.200.135
PODAONLV
Netherlands
2->124
126
25 other IPs or domains
2->126
162
Suricata IDS alerts
for network traffic
2->162
164
Found malware configuration
2->164
166
Antivirus detection
for dropped file
2->166
170
16 other signatures
2->170
12
Setup.exe
7
2->12
started
15
svchost.exe
20
2->15
started
18
svchost.exe
2->18
started
signatures3
168
DNS related to crypt
mining pools
122->168
process4
file5
114
C:\Users\user\Desktop\xqAAE.exe, PE32+
12->114
dropped
116
C:\Users\user\Desktop\ae_mixtwo_2.exe, PE32
12->116
dropped
20
ae_mixtwo_2.exe
6
12->20
started
24
xqAAE.exe
1
12->24
started
224
Unusual module load
detection (module proxying)
15->224
27
WerFault.exe
2
15->27
started
29
WerFault.exe
15->29
started
31
WerFault.exe
15->31
started
signatures6
process7
dnsIp8
108
C:\Users\user\AppData\Local\Temp\...\11.exe, PE32+
20->108
dropped
182
Multi AV Scanner detection
for dropped file
20->182
184
Writes to foreign memory
regions
20->184
186
Allocates memory in
foreign processes
20->186
188
Injects a PE file into
a foreign processes
20->188
33
MSBuild.exe
37
20->33
started
38
11.exe
3
20->38
started
40
WerFault.exe
21
16
20->40
started
128
mrlketo.shop
72.62.195.74, 49736, 49737, 8932
AS-HOSTINGERCY
Malaysia
24->128
130
tarkioweb.com
176.53.159.66
ORACLE-BMC-31898-OracleCorporationUS
Turkey
24->130
190
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
24->190
192
Creates HTML files with
.exe extension (expired
dropper behavior)
24->192
194
Tries to steal Mail
credentials (via file
/ registry access)
24->194
196
4 other signatures
24->196
file9
signatures10
process11
dnsIp12
118
91.92.242.236, 49734, 80
OMEGATECH-ASSC
Netherlands
33->118
120
drive.usercontent.google.com
142.251.2.132, 443, 49730
GOOGLE-GoogleLLCUS
United States
33->120
100
C:\Users\user\AppData\...\PUuQSUV2CfB.exe, PE32+
33->100
dropped
102
C:\Users\user\AppData\...\pIMrSM9nzBavB.exe, PE32+
33->102
dropped
104
C:\Users\user\AppData\...\tQKLp5pGkrteO.exe, PE32+
33->104
dropped
106
9 other malicious files
33->106
dropped
172
Unusual module load
detection (module proxying)
33->172
42
tQKLp5pGkrteO.exe
33->42
started
47
5ociOJVEDzv.exe
33->47
started
49
vuq9NLcMNc.exe
33->49
started
55
5 other processes
33->55
174
Writes to foreign memory
regions
38->174
176
Allocates memory in
foreign processes
38->176
178
Modifies the context
of a thread in another
process (thread injection)
38->178
180
Injects a PE file into
a foreign processes
38->180
51
MSBuild.exe
38->51
started
53
WerFault.exe
38->53
started
file13
signatures14
process15
dnsIp16
136
serdaregitim.com
185.93.68.46
TWO-E-TELEKOMTR
Turkey
42->136
138
ity.beri303.org
104.21.48.6, 443, 49740
CLOUDFLARENET-CloudflareIncUS
Canada
42->138
140
telegram.me
149.154.167.99, 443, 49739
TELEGRAMVG
United Kingdom
42->140
110
C:\ProgramData\f08e312bbf\ccda4a21.exe, PE32+
42->110
dropped
112
C:\ProgramData\f08e312bbf\cbfec305.exe, PE32
42->112
dropped
198
Multi AV Scanner detection
for dropped file
42->198
200
Early bird code injection
technique detected
42->200
202
Tries to harvest and
steal Putty / WinSCP
information (sessions,
passwords, etc)
42->202
218
11 other signatures
42->218
57
firefox.exe
42->57
started
60
chrome.exe
42->60
started
62
msedge.exe
42->62
started
204
Writes to foreign memory
regions
47->204
220
2 other signatures
47->220
64
MSBuild.exe
47->64
started
67
WerFault.exe
47->67
started
142
shkpiva.shop
85.31.60.169, 49738, 5627
AS-HOSTINGERCY
Brazil
49->142
206
Detected unpacking (creates
a PE file in dynamic
memory)
49->206
208
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
49->208
210
Tries to steal Mail
credentials (via file
/ registry access)
49->210
212
Tries to steal from
password manager
49->212
222
2 other signatures
51->222
144
me-ycpi-cf-www.g06.yahoodns.net
209.73.190.11, 443, 49742
YAHOO-YSM-SC8-YahooHoldingsIncUS
United States
55->144
146
95.164.53.193, 49741, 5001
QWINS-LTDQWINSAS-SETAS213702AS-CUSTOMERSGB
Germany
55->146
148
3 other IPs or domains
55->148
214
Antivirus detection
for dropped file
55->214
216
Uses whoami command
line tool to query computer
and username
55->216
69
systeminfo.exe
55->69
started
71
cmd.exe
55->71
started
73
cmd.exe
55->73
started
75
7 other processes
55->75
file17
signatures18
process19
dnsIp20
132
127.0.0.1
unknown
unknown
57->132
134
87.120.104.144
SINOWORLDWIDEHK
Norway
64->134
152
Tries to harvest and
steal Putty / WinSCP
information (sessions,
passwords, etc)
64->152
154
Tries to steal Mail
credentials (via file
/ registry access)
64->154
156
Tries to harvest and
steal browser information
(history, passwords,
etc)
64->156
160
4 other signatures
64->160
77
chrome.exe
64->77
started
158
Queries sensitive network
adapter information
(via WMI, Win32_NetworkAdapter,
often done to detect
virtual machines)
69->158
79
conhost.exe
69->79
started
81
WMIC.exe
71->81
started
83
conhost.exe
71->83
started
85
conhost.exe
73->85
started
87
Defrag.exe
73->87
started
89
conhost.exe
75->89
started
91
Defrag.exe
75->91
started
93
3 other processes
75->93
signatures21
process22
process23
95
chrome.exe
77->95
started
98
Conhost.exe
81->98
started
dnsIp24
150
www.google.com
142.251.150.119
GOOGLE-GoogleLLCUS
United States
95->150
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.