Threat name:
Quasar, XRat, XWorm
Alert
Classification:
troj.adwa.evad
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
.NET source code contains very large strings
Adds a directory exclusion to Windows Defender
Antivirus detection for dropped file
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Command shell drops VBS files
Creates a thread in another existing process (thread injection)
Found malware configuration
Found suspicious powershell code related to unpacking or dynamic code loading
Hides that the sample has been downloaded from the Internet (zone.identifier)
Hooks files or directories query functions (used to hide files and directories)
Hooks processes query functions (used to hide processes)
Hooks registry keys query functions (used to hide registry keys)
Injects code into the Windows Explorer (explorer.exe)
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Modifies the context of a thread in another process (thread injection)
Modifies the prolog of user mode functions (user mode inline hooks)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Mutes Antivirus updates and installments via hosts file black listing
Protects its processes via BreakOnTermination flag
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sets debug register (to hijack the execution of another thread)
Sigma detected: Base64 Encoded PowerShell Command Detected
Sigma detected: Malicious Base64 Encoded PowerShell Keywords in Command Lines
Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious PowerShell Parameter Substring
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Unusual module load detection (module proxying)
Uses ipconfig to lookup or modify the Windows network settings
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Yara detected Obfuscated Powershell
Yara detected Powershell decode and execute
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
1835848
Sample:
WalletAiFinder_Crypter.bat
Startdate:
18/12/2025
Architecture:
WINDOWS
Score:
100
117
www.msftncsi.com.edgesuite.net
2->117
119
www.msftncsi.com
2->119
121
4 other IPs or domains
2->121
153
Suricata IDS alerts
for network traffic
2->153
155
Found malware configuration
2->155
157
Malicious sample detected
(through community Yara
rule)
2->157
159
25 other signatures
2->159
14
cmd.exe
2
2->14
started
18
Sirdur.exe
2->18
started
20
SeroXen.exe
2->20
started
22
SeroXen.exe
2->22
started
signatures3
process4
file5
107
C:\Users\user\AppData\...\run_hidden.vbs, ASCII
14->107
dropped
189
Suspicious powershell
command line found
14->189
191
Command shell drops
VBS files
14->191
193
Bypasses PowerShell
execution policy
14->193
24
cscript.exe
2
14->24
started
26
conhost.exe
14->26
started
195
Antivirus detection
for dropped file
18->195
197
Multi AV Scanner detection
for dropped file
18->197
signatures6
process7
process8
28
cmd.exe
3
24->28
started
signatures9
185
Suspicious powershell
command line found
28->185
187
Command shell drops
VBS files
28->187
31
WalletAiFinder.exe
5
28->31
started
35
powershell.exe
8
28->35
started
37
conhost.exe
28->37
started
39
16 other processes
28->39
process10
file11
109
C:\Users\user\AppData\...\WalletFinder.exe, PE32
31->109
dropped
111
C:\Users\user\AppData\Roaming\Update.exe, PE32
31->111
dropped
113
C:\Users\user\AppData\Roaming\SeroXen.exe, PE32
31->113
dropped
135
Antivirus detection
for dropped file
31->135
137
Multi AV Scanner detection
for dropped file
31->137
41
SeroXen.exe
14
7
31->41
started
46
WalletFinder.exe
4
31->46
started
48
Update.exe
31->48
started
115
C:\Users\user\AppData\...\WalletAiFinder.exe, PE32
35->115
dropped
139
Found suspicious powershell
code related to unpacking
or dynamic code loading
35->139
141
Powershell drops PE
file
35->141
signatures12
process13
dnsIp14
125
ip-api.com
208.95.112.1, 49693, 49698, 80
TUT-ASUS
United States
41->125
97
C:\Users\user\AppData\Roaming\...\Client.exe, PE32
41->97
dropped
99
C:\Windows\System32\drivers\etc\hosts, ASCII
41->99
dropped
171
Antivirus detection
for dropped file
41->171
173
Multi AV Scanner detection
for dropped file
41->173
175
Suspicious powershell
command line found
41->175
183
5 other signatures
41->183
50
Client.exe
41->50
started
53
powershell.exe
41->53
started
55
schtasks.exe
41->55
started
64
2 other processes
41->64
101
C:\Users\user\AppData\...\SeedBrutoforce.exe, PE32
46->101
dropped
103
C:\Users\user\AppData\Roaming\dont del.bat, ASCII
46->103
dropped
57
cmd.exe
46->57
started
59
SeedBrutoforce.exe
46->59
started
127
23.160.168.167, 1111, 2212, 4782
HOSTCRAMHostCramLLCUS
Reserved
48->127
105
C:\Users\user\AppData\Local\Sirdur.exe, PE32
48->105
dropped
177
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
48->177
179
Protects its processes
via BreakOnTermination
flag
48->179
181
Uses schtasks.exe or
at.exe to add and modify
task schedules
48->181
62
schtasks.exe
48->62
started
file15
signatures16
process17
dnsIp18
143
Antivirus detection
for dropped file
50->143
145
Multi AV Scanner detection
for dropped file
50->145
147
Hides that the sample
has been downloaded
from the Internet (zone.identifier)
50->147
66
schtasks.exe
50->66
started
149
Loading BitLocker PowerShell
Module
53->149
68
conhost.exe
53->68
started
70
conhost.exe
55->70
started
151
Suspicious powershell
command line found
57->151
72
powershell.exe
57->72
started
76
conhost.exe
57->76
started
129
23.49.5.132, 49738, 49742, 49743
AKAMAI-ASUS
United States
59->129
131
23.49.5.148, 49694, 49740, 49741
AKAMAI-ASUS
United States
59->131
133
3 other IPs or domains
59->133
78
conhost.exe
62->78
started
80
conhost.exe
64->80
started
82
conhost.exe
64->82
started
signatures19
process20
dnsIp21
84
conhost.exe
66->84
started
123
ipwho.is
15.204.213.5, 443, 49736
HP-INTERNET-ASUS
United States
72->123
163
Injects code into the
Windows Explorer (explorer.exe)
72->163
165
Sets debug register
(to hijack the execution
of another thread)
72->165
167
Writes to foreign memory
regions
72->167
169
3 other signatures
72->169
86
explorer.exe
72->86
injected
89
svchost.exe
72->89
injected
91
svchost.exe
72->91
injected
93
2 other processes
72->93
signatures22
process23
signatures24
161
Unusual module load
detection (module proxying)
86->161
95
Sirdur.exe
86->95
started
process25
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.