MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 58125004d2a317f64dc8a5ec7da308c7df7d9029f417d1e5dc124a8392e3fd8b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Nitol


Vendor detections: 14


Intelligence 14 IOCs YARA 25 File information Comments

SHA256 hash: 58125004d2a317f64dc8a5ec7da308c7df7d9029f417d1e5dc124a8392e3fd8b
SHA3-384 hash: b16bda36b2a71e8694f139db7b1a42b9b8b7f2f58138cca01a49f30ea4a046e8b359ace9c305373136b202bfb579ce33
SHA1 hash: 4822180be4d79c8d11152a6ab352927902effbc0
MD5 hash: 56fc4cecf07a05512eef3973c8c0b792
humanhash: missouri-texas-social-ack
File name:WPS_2.0.exe
Download: download sample
Signature Nitol
File size:11'646'321 bytes
First seen:2025-05-10 03:59:49 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 357b59ff56f808887438b8bd8ad0eaa6 (12 x Nitol)
ssdeep 196608:GxMe4cxhAlXPB/+8MBF0W4P/qAOoRc7RhrtnZ3s:GecUGtF0/4UiRPnZ3s
Threatray 37 similar samples on MalwareBazaar
TLSH T171C6CF4566B844E6D0BE8135C9528A0BC3F238851FB5C7CB42915ABD1F3FBA20F6DE25
TrID 44.4% (.EXE) Win64 Executable (generic) (10522/11/4)
21.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
8.7% (.ICL) Windows Icons Library (generic) (2059/9)
8.5% (.EXE) OS/2 Executable (generic) (2029/13)
8.4% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon fadadac2a2b8c4e4 (21 x ValleyRAT, 11 x Nitol, 5 x Gh0stRAT)
Reporter GDHJDSYDH1
Tags:agent backdoor Evader exe FakeApp Gh0stRAT Nitol

Intelligence


File Origin
# of uploads :
1
# of downloads :
753
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
WPS_2.0.exe
Verdict:
Malicious activity
Analysis date:
2025-05-10 08:22:38 UTC
Tags:
wps lua auto-reg

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
97.4%
Tags:
vmdetect cobalt
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a file in the %temp% subdirectories
Сreating synchronization primitives
Searching for synchronization primitives
Creating a process from a recently created file
Creating a window
Launching a process
Creating a process with a hidden window
Using the Windows Management Instrumentation requests
Creating a file
Creating a file in the Program Files subdirectories
DNS request
Connection attempt
Sending a custom TCP request
Running batch commands
Creating a file in the %AppData% subdirectories
Enabling the 'hidden' option for recently created files
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Unauthorized injection to a system process
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm expired-cert explorer fingerprint fingerprint installer invalid-signature lolbin microsoft_visual_cc msiexec obfuscated overlay overlay packed regsvr32 runonce signed xor-pe zero
Result
Threat name:
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Contains functionality to capture and log keystrokes
Contains functionality to infect the boot sector
Contains functionality to inject code into remote processes
Contains functionality to modify Windows User Account Control (UAC) settings
Detected unpacking (creates a PE file in dynamic memory)
Disable UAC(promptonsecuredesktop)
Disables UAC (registry)
Encrypted powershell cmdline option found
Found evasive API chain (may stop execution after checking mutex)
Found stalling execution ending in API Sleep call
Found suspicious powershell code related to unpacking or dynamic code loading
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Sigma detected: Base64 Encoded PowerShell Command Detected
Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet
Sigma detected: Suspect Svchost Activity
Suspicious powershell command line found
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Yara detected Nitol
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1686566 Sample: WPS_2.0.exe Startdate: 10/05/2025 Architecture: WINDOWS Score: 100 79 wh-nginx-gateway-service.default.us.entry.4wps.net 2->79 81 params.wps.com 2->81 83 6 other IPs or domains 2->83 93 Malicious sample detected (through community Yara rule) 2->93 95 Multi AV Scanner detection for dropped file 2->95 97 Multi AV Scanner detection for submitted file 2->97 99 8 other signatures 2->99 10 WPS_2.0.exe 4 2->10         started        13 iusb3mon.exe 2->13         started        16 svchost.exe 2->16         started        19 3 other processes 2->19 signatures3 process4 dnsIp5 73 C:\Users\user\AppData\Local\...\lua5.1.dll, PE32+ 10->73 dropped 75 C:\Users\user\AppData\Local\...\irsetup.exe, PE32+ 10->75 dropped 21 irsetup.exe 13 10->21         started        109 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 13->109 77 127.0.0.1 unknown unknown 16->77 file6 signatures7 process8 file9 65 C:\Users\user\AppData\...\vcruntime140.dll, PE32 21->65 dropped 67 C:\Users\user\AppData\Local\...\msvcp140.dll, PE32 21->67 dropped 69 C:\Users\user\AppData\Local\...\iusb3mon.exe, PE32 21->69 dropped 71 2 other malicious files 21->71 dropped 24 iusb3mon.exe 21->24         started        28 powershell.exe 11 21->28         started        30 powershell.exe 11 21->30         started        32 6 other processes 21->32 process10 dnsIp11 85 116.193.171.34, 25448, 49700, 49702 POWERLINE-AS-APPOWERLINEDATACENTERHK Hong Kong 24->85 101 Detected unpacking (creates a PE file in dynamic memory) 24->101 103 Found evasive API chain (may stop execution after checking mutex) 24->103 105 Suspicious powershell command line found 24->105 107 11 other signatures 24->107 34 cmd.exe 24->34         started        37 powershell.exe 24->37         started        39 powershell.exe 24->39         started        41 svchost.exe 24->41         started        43 conhost.exe 28->43         started        45 conhost.exe 30->45         started        87 istio-gateway.us.entry.4wps.net 52.13.76.125, 443, 49693, 49694 AMAZON-02US United States 32->87 47 conhost.exe 32->47         started        49 conhost.exe 32->49         started        51 3 other processes 32->51 signatures12 process13 signatures14 89 Uses schtasks.exe or at.exe to add and modify task schedules 34->89 53 conhost.exe 34->53         started        55 schtasks.exe 34->55         started        91 Found suspicious powershell code related to unpacking or dynamic code loading 37->91 57 conhost.exe 37->57         started        59 SecEdit.exe 37->59         started        61 conhost.exe 39->61         started        63 SecEdit.exe 39->63         started        process15
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2025-05-10 04:00:16 UTC
File Type:
PE+ (Exe)
Extracted files:
37
AV detection:
12 of 37 (32.43%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
bootkit defense_evasion discovery execution persistence trojan
Behaviour
Checks processor information in registry
Modifies system certificate store
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
System policy modification
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Suspicious use of SetThreadContext
Adds Run key to start application
Checks whether UAC is enabled
Command and Scripting Interpreter: PowerShell
Indicator Removal: File Deletion
Writes to the Master Boot Record (MBR)
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
UAC bypass
Unpacked files
SH256 hash:
58125004d2a317f64dc8a5ec7da308c7df7d9029f417d1e5dc124a8392e3fd8b
MD5 hash:
56fc4cecf07a05512eef3973c8c0b792
SHA1 hash:
4822180be4d79c8d11152a6ab352927902effbc0
SH256 hash:
de9724af64157d9aa73741155747f58d62ebbb251a607f7d0c1788e6988fa5a3
MD5 hash:
c62e81ecbaf21433287b2f8571c284b9
SHA1 hash:
cbddaabe6d5af7a3e11ceb8c0363701eb6400cb8
SH256 hash:
bb5f77b44272c2a440409b860a607ce9bc3649ccfb7ba576e0aaf86c750c151d
MD5 hash:
5a880f3e3385c81737409eb1c7a05d35
SHA1 hash:
d947162f96805da453116309b007800aa580613d
SH256 hash:
1202a4ae6949ccb5f0637d0d9bd0940628a7277718d498077660ebfe1e1e5e24
MD5 hash:
0dfbee6c019a8e0d6890b142903a15a0
SHA1 hash:
af099da8c05c0d425fc3a4acfcb3061968916740
SH256 hash:
f57f06425bf34f9ee20a28dc0ff7db4b1e6d3c6a027e680902d95d65cf5b77ee
MD5 hash:
0a3278787bd1c0055cdcf78d3e567dfe
SHA1 hash:
9951af0237fcab890b05e8cfc7d6a8d68ba9d174
Detections:
INDICATOR_SUSPICIOUS_References_SecTools INDICATOR_SUSPICIOUS_EXE_ClearMyTracksByProcess
SH256 hash:
7a3e3ba48976d9a0bf2a342167fbd42f39313d22261fdc9e5beb621070564f39
MD5 hash:
48fa8575e2b121fe63ec3456dc1e387a
SHA1 hash:
5a01e0ee659a8f145bcf99484740f1e1feeeef0a
SH256 hash:
c6a73c19fc2d9065380e617b135813a9aa9253e2583d3c5ece8017badf6e29b3
MD5 hash:
5cff40977318984e0f7c8bd102990dc4
SHA1 hash:
a1b820e16b601ef0285fb01ae1375f68bb51894f
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:Check_OutputDebugStringA_iat
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:grakate_stealer_nov_2021
Rule name:INDICATOR_KB_CERT_0a1f3a057a1dce4bf7d76d0c7adf837e
Author:ditekSHen
Description:Detects executables signed with stolen, revoked or invalid certificates
Rule name:INDICATOR_SUSPICIOUS_EXE_ClearMyTracksByProcess
Author:ditekSHen
Description:Detects executables calling ClearMyTracksByProcess
Rule name:INDICATOR_SUSPICIOUS_References_SecTools
Author:ditekSHen
Description:Detects executables referencing many IR and analysis tools
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:meth_peb_parsing
Author:Willi Ballenthin
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SUSP_XORed_MSDOS_Stub_Message
Author:Florian Roth
Description:Detects suspicious XORed MSDOS stub message
Reference:https://yara.readthedocs.io/en/latest/writingrules.html#xor-strings
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Nitol

Executable exe 58125004d2a317f64dc8a5ec7da308c7df7d9029f417d1e5dc124a8392e3fd8b

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_TRUST_INFORequires Elevated Execution (level:requireAdministrator)high
Reviews
IDCapabilitiesEvidence
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::GetTokenInformation
SHELL_APIManipulates System ShellSHELL32.dll::ShellExecuteExA
WIN32_PROCESS_APICan Create Process and ThreadsADVAPI32.dll::OpenProcessToken
KERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::LoadLibraryW
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetDiskFreeSpaceA
KERNEL32.dll::GetCommandLineA
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateDirectoryA
KERNEL32.dll::DeleteFileA
KERNEL32.dll::MoveFileExA
KERNEL32.dll::GetFileAttributesA
KERNEL32.dll::RemoveDirectoryA
KERNEL32.dll::GetTempPathA
WIN_USER_APIPerforms GUI ActionsUSER32.dll::PeekMessageA

Comments