Threat name:
ScreenConnect Tool, PureCrypter, Amadey,
Alert
Classification:
phis.troj.spyw.expl.evad
.NET source code contains method to dynamically call methods (often used by packers)
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Binary is likely a compiled AutoIt script file
C2 URLs / IPs found in malware configuration
Contains functionality to bypass UAC (CMSTPLUA)
Contains functionality to hide user accounts
Contains functionality to start a terminal service
Creates multiple autostart registry keys
Detected PureCrypter Trojan
Detected unpacking (changes PE section rights)
Disable Windows Defender notifications (registry)
Disable Windows Defender real time protection (registry)
Disables Windows Defender Tamper protection
Drops PE files with benign system names
Enables network access during safeboot for specific services
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Found suspicious powershell code related to unpacking or dynamic code loading
Hides threads from debuggers
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Modifies windows update settings
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Possible COM Object hijacking
Potentially malicious time measurement code found
Queries memory information (via WMI often done to detect virtual machines)
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive physical memory information (via WMI, Win32_PhysicalMemory, often done to detect virtual machines)
Queries sensitive Plug and Play Device Information (via WMI, Win32_PnPEntity, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Reads the Security eventlog
Reads the System eventlog
Sample is not signed and drops a device driver
Sample uses string decryption to hide its real strings
Sigma detected: Files With System Process Name In Unsuspected Locations
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: Powershell download and execute file
Sigma detected: PowerShell DownloadFile
Sigma detected: Remote Access Tool - ScreenConnect Suspicious Execution
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious MSHTA Child Process
Sigma detected: Suspicious Script Execution From Temp Folder
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to detect virtualization through RDTSC time measurements
Tries to download and execute files (via powershell)
Tries to evade debugger and weak emulator (self modifying code)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected Amadeys Clipper DLL
Yara detected Amadeys stealer DLL
Yara detected LummaC Stealer
Yara detected obfuscated html page
Yara detected Powershell decode and execute
Yara detected Powershell download and execute
Yara detected PureLog Stealer
Yara detected UAC Bypass using CMSTP
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
1610876
Sample:
BQuCS3qKSj.exe
Startdate:
10/02/2025
Architecture:
WINDOWS
Score:
100
127
relay.ssahelponline.ru
2->127
129
paleboreei.biz
2->129
131
5 other IPs or domains
2->131
147
Suricata IDS alerts
for network traffic
2->147
149
Found malware configuration
2->149
151
Malicious sample detected
(through community Yara
rule)
2->151
153
32 other signatures
2->153
10
skotes.exe
2
55
2->10
started
15
BQuCS3qKSj.exe
5
2->15
started
17
msiexec.exe
2->17
started
19
7 other processes
2->19
signatures3
process4
dnsIp5
137
185.215.113.16
WHOLESALECONNECTIONSNL
Portugal
10->137
139
185.215.113.43, 49955, 49970, 49976
WHOLESALECONNECTIONSNL
Portugal
10->139
141
185.215.113.97, 49975, 49977, 49980
WHOLESALECONNECTIONSNL
Portugal
10->141
103
26 other malicious files
10->103
dropped
215
Creates multiple autostart
registry keys
10->215
217
Hides threads from debuggers
10->217
219
Tries to detect sandboxes
/ dynamic malware analysis
system (registry check)
10->219
221
Tries to detect process
monitoring tools (Task
Manager, Process Explorer
etc.)
10->221
21
4a7d871283.exe
10->21
started
25
powershell.exe
1
49
10->25
started
27
kUHbhqh.exe
3
2
10->27
started
36
4 other processes
10->36
89
C:\Users\user\AppData\Local\...\skotes.exe, PE32
15->89
dropped
91
C:\Users\user\...\skotes.exe:Zone.Identifier, ASCII
15->91
dropped
223
Detected unpacking (changes
PE section rights)
15->223
225
Tries to evade debugger
and weak emulator (self
modifying code)
15->225
227
Tries to detect virtualization
through RDTSC time measurements
15->227
30
skotes.exe
15->30
started
93
C:\Windows\Installer\MSI8D51.tmp, PE32
17->93
dropped
95
C:\Windows\Installer\MSI84E3.tmp, PE32
17->95
dropped
105
8 other files (2 malicious)
17->105
dropped
229
Enables network access
during safeboot for
specific services
17->229
32
msiexec.exe
17->32
started
38
2 other processes
17->38
143
relay.ssahelponline.ru
38.240.47.42
COGENT-174US
United States
19->143
97
C:\Users\user\AppData\Roaming\VERSION.dll, PE32+
19->97
dropped
99
C:\Users\user\...\CiscoSparkLauncher.dll, PE32+
19->99
dropped
101
C:\Users\user\AppData\...\CiscoCollabHost.exe, PE32+
19->101
dropped
231
Reads the Security eventlog
19->231
233
Reads the System eventlog
19->233
34
ScreenConnect.WindowsClient.exe
19->34
started
40
2 other processes
19->40
file6
signatures7
process8
dnsIp9
79
C:\Users\user\AppData\Local\...\CXOzlCU5X.hta, HTML
21->79
dropped
155
Binary is likely a compiled
AutoIt script file
21->155
157
Creates HTA files
21->157
42
mshta.exe
21->42
started
45
cmd.exe
21->45
started
81
C:\Users\user\AppData\Local\...\VERSION.dll, PE32+
25->81
dropped
83
C:\Users\user\...\CiscoSparkLauncher.dll, PE32+
25->83
dropped
85
C:\Users\user\AppData\...\CiscoCollabHost.exe, PE32+
25->85
dropped
159
Creates multiple autostart
registry keys
25->159
175
3 other signatures
25->175
47
CiscoCollabHost.exe
25->47
started
50
conhost.exe
25->50
started
145
93.88.203.169
DRAVANET-ASHU
Hungary
27->145
87
C:\Users\user\AppData\...\Stamp_Setup.exe, PE32
27->87
dropped
161
Multi AV Scanner detection
for dropped file
27->161
163
Queries sensitive physical
memory information (via
WMI, Win32_PhysicalMemory,
often done to detect
virtual machines)
27->163
165
Found many strings related
to Crypto-Wallets (likely
being stolen)
27->165
177
5 other signatures
27->177
167
Detected unpacking (changes
PE section rights)
30->167
179
5 other signatures
30->179
52
rundll32.exe
32->52
started
169
Contains functionality
to hide user accounts
34->169
171
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
36->171
173
Injects a PE file into
a foreign processes
36->173
54
o29sbXN.exe
36->54
started
57
cABT5qY.exe
36->57
started
59
cmd.exe
36->59
started
61
4 other processes
36->61
file10
signatures11
process12
dnsIp13
181
Suspicious powershell
command line found
42->181
183
Tries to download and
execute files (via powershell)
42->183
63
powershell.exe
42->63
started
185
Uses schtasks.exe or
at.exe to add and modify
task schedules
45->185
66
conhost.exe
45->66
started
68
schtasks.exe
45->68
started
107
C:\Users\user\AppData\Local\...\svchost.exe, PE32
47->107
dropped
109
C:\Users\user\...\qqboUZMKP4hSO8Guzu.sys, PE32+
47->109
dropped
111
C:\Users\user\AppData\Local\Temp\jqnCLI.sys, PE32+
47->111
dropped
187
Contains functionality
to bypass UAC (CMSTPLUA)
47->187
189
Contains functionality
to start a terminal
service
47->189
191
Sample is not signed
and drops a device driver
47->191
205
2 other signatures
47->205
113
C:\Users\user\...\ScreenConnect.Windows.dll, PE32
52->113
dropped
115
C:\...\ScreenConnect.InstallerActions.dll, PE32
52->115
dropped
117
C:\Users\user\...\ScreenConnect.Core.dll, PE32
52->117
dropped
119
Microsoft.Deployme...indowsInstaller.dll, PE32
52->119
dropped
133
importenptoc.com
188.114.97.3
CLOUDFLARENETUS
European Union
54->133
193
Query firmware table
information (likely
to detect VMs)
54->193
195
Tries to harvest and
steal ftp login credentials
54->195
197
Tries to harvest and
steal browser information
(history, passwords,
etc)
54->197
135
paleboreei.biz
188.114.96.3
CLOUDFLARENETUS
European Union
57->135
199
Found many strings related
to Crypto-Wallets (likely
being stolen)
57->199
201
Tries to steal Crypto
Currency Wallets
57->201
121
C:\Temp\3HlzIWtqh.hta, HTML
59->121
dropped
203
Creates HTA files
59->203
70
conhost.exe
59->70
started
72
timeout.exe
59->72
started
123
C:\Users\user\AppData\Local\...\MSI7717.tmp, PE32
61->123
dropped
file14
signatures15
process16
file17
125
TempGLJFK6DXRX25B8R3R7FNGTUWFSTTIA7L.EXE, PE32
63->125
dropped
74
TempGLJFK6DXRX25B8R3R7FNGTUWFSTTIA7L.EXE
63->74
started
77
conhost.exe
63->77
started
process18
signatures19
207
Detected unpacking (changes
PE section rights)
74->207
209
Tries to detect sandboxes
and other dynamic analysis
tools (window names)
74->209
211
Modifies windows update
settings
74->211
213
7 other signatures
74->213
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.