Classification:
troj.adwa.expl.evad
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
.NET source code contains very large array initializations
Allocates memory in foreign processes
Antivirus detection for dropped file
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Creates processes via WMI
Detected large data written to user environment variables, potentially indicating payload staging for fileless execution
Detected unpacking (overwrites its own PE header)
Drops executables to the windows directory (C:\Windows) and starts them
Drops PE files to the startup folder
Early bird code injection technique detected
Found malware configuration
Found suspicious ZIP file
Hijacks the control flow in another process
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Overwrites code with unconditional jumps - possibly settings hooks in foreign process
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queues an APC in another process (thread injection)
Sample uses string decryption to hide its real strings
Sigma detected: Bad Opsec Defaults Sacrificial Processes With Improper Arguments
Sigma detected: Execution of Powershell Script in Public Folder
Sigma detected: HackTool - CACTUSTORCH Remote Thread Creation
Sigma detected: Potential PowerShell Command Line Obfuscation
Sigma detected: Rare Remote Thread Creation By Uncommon Source Image
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious PowerShell Parameter Substring
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: Windows Shell/Scripting Application File Write to Suspicious Folder
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious execution chain found
Unusual module load detection (module proxying)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
WScript reads language and country specific registry keys (likely country aware script)
Wscript starts Powershell (via cmd or directly)
Yara detected Costura Assembly Loader
Yara detected MSIL Injector
Yara detected Powershell decode and execute
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
1948396
Sample:
ZJT39dc0jQ.exe
Startdate:
27/07/2026
Architecture:
WINDOWS
Score:
100
115
vpnl.net
2->115
117
update.iobit.com.akamaized.net
2->117
119
4 other IPs or domains
2->119
151
Suricata IDS alerts
for network traffic
2->151
153
Found malware configuration
2->153
155
Malicious sample detected
(through community Yara
rule)
2->155
157
25 other signatures
2->157
12
msiexec.exe
87
40
2->12
started
16
wscript.exe
2->16
started
18
ZJT39dc0jQ.exe
47
2->18
started
20
wins32.exe
2->20
started
signatures3
process4
file5
99
C:\Windows\Installer\MSI5C2B.tmp, PE32+
12->99
dropped
101
C:\Windows\Installer\MSI34AB.tmp, PE32
12->101
dropped
103
C:\Windows\Installer\MSI344D.tmp, PE32
12->103
dropped
111
6 other malicious files
12->111
dropped
179
Drops executables to
the windows directory
(C:\Windows) and
starts them
12->179
22
MSI5C2B.tmp
1
12->22
started
24
iobituninstaller.exe
2
12->24
started
27
msiexec.exe
12->27
started
29
msiexec.exe
12->29
started
181
Windows Scripting host
queries suspicious COM
object (likely to drop
second stage)
16->181
183
Detected large data
written to user environment
variables, potentially
indicating payload staging
for fileless execution
16->183
31
powershell.exe
16->31
started
105
C:\Users\user\...\iobituninstaller.exe, PE32
18->105
dropped
107
C:\Users\user\AppData\Local\...\shi2574.tmp, PE32+
18->107
dropped
109
C:\Users\user\AppData\Local\...\pre2BB1.tmp, PE32
18->109
dropped
113
3 other malicious files
18->113
dropped
34
msiexec.exe
4
18->34
started
signatures6
process7
file8
36
cmd.exe
1
22->36
started
39
conhost.exe
22->39
started
87
C:\Users\user\...\iobituninstaller.tmp, PE32
24->87
dropped
41
iobituninstaller.tmp
18
24->41
started
185
Hijacks the control
flow in another process
31->185
187
Writes to foreign memory
regions
31->187
189
Modifies the context
of a thread in another
process (thread injection)
31->189
191
Injects a PE file into
a foreign processes
31->191
44
RegAsm.exe
31->44
started
47
conhost.exe
31->47
started
signatures9
process10
dnsIp11
167
Wscript starts Powershell
(via cmd or directly)
36->167
49
wscript.exe
36->49
started
52
powershell.exe
8
11
36->52
started
54
powershell.exe
36->54
started
62
2 other processes
36->62
89
C:\Users\user\AppData\...\libssl-1_1.dll, PE32
41->89
dropped
91
C:\Users\user\AppData\...\libcrypto-1_1.dll, PE32
41->91
dropped
93
C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+
41->93
dropped
95
4 other malicious files
41->95
dropped
57
Setup.exe
13
41->57
started
129
158.94.209.112, 49823, 80
OMEGATECH-ASSC
Netherlands
44->129
169
Early bird code injection
technique detected
44->169
171
Writes to foreign memory
regions
44->171
173
Allocates memory in
foreign processes
44->173
175
3 other signatures
44->175
60
chrome.exe
44->60
started
file12
signatures13
process14
dnsIp15
131
Wscript starts Powershell
(via cmd or directly)
49->131
133
Windows Scripting host
queries suspicious COM
object (likely to drop
second stage)
49->133
135
Suspicious execution
chain found
49->135
149
2 other signatures
49->149
64
powershell.exe
49->64
started
137
Bypasses PowerShell
execution policy
52->137
139
Drops PE files to the
startup folder
52->139
141
Powershell drops PE
file
52->141
81
C:\Users\Public\T.vbs, ASCII
54->81
dropped
83
C:\Users\Public\0x.ps1, Unicode
54->83
dropped
143
Loading BitLocker PowerShell
Module
54->143
121
stats-iobit-com.us-east-1.elasticbeanstalk.com
44.217.215.15, 443, 49775, 49776
AMAZON-AES-AmazoncomIncUS
United States
57->121
123
a1837.dscd.akamai.net
2.18.67.197, 443, 49769, 49770
AKAMAI-ASN1NL
United States
57->123
145
Detected unpacking (overwrites
its own PE header)
57->145
147
Overwrites code with
unconditional jumps
- possibly settings
hooks in foreign process
57->147
85
C:\Users\Public\three.zip, Zip
62->85
dropped
file16
signatures17
process18
file19
79
C:\Users\user\AppData\Roaming\...\wins32.exe, PE32
64->79
dropped
67
wins32.exe
64->67
started
70
powershell.exe
64->70
started
72
conhost.exe
64->72
started
process20
signatures21
159
Writes to foreign memory
regions
67->159
161
Allocates memory in
foreign processes
67->161
163
Injects a PE file into
a foreign processes
67->163
74
InstallUtil.exe
67->74
started
165
Loading BitLocker PowerShell
Module
70->165
process22
dnsIp23
125
158.94.210.247, 49793, 49807, 49815
OMEGATECH-ASSC
Netherlands
74->125
127
vpnl.net
157.20.182.20, 49792, 49794, 49795
HOSTER-AS-INHosterdaddyPrivateLimitedIN
Netherlands
74->127
97
C:\Users\user\AppData\Local\Temp\dtpnz.vbs, Unicode
74->97
dropped
177
Queries sensitive disk
information (via WMI,
Win32_DiskDrive, often
done to detect virtual
machines)
74->177
file24
signatures25
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.