| File name: | 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader |
| Full analysis: | https://app.any.run/tasks/997f56bf-339f-4cf9-9118-dc45e4598a35 |
| Verdict: | Malicious activity |
| Analysis date: | April 18, 2025, 04:26:44 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections |
| MD5: | 8C8BADF634F5C15D5AEBEA34D2233F50 |
| SHA1: | 8CF8EE9269D04BD5DBCDFA8A49024F25A46714AF |
| SHA256: | 5387A93FC5BD4D316D29DA5E3E05607EEC6C0D97BFA36E76BA1D4880F4DFA998 |
| SSDEEP: | 49152:dTdgMIISYUnUu4O3f/HAzruQfZt8lW3mUbzDJH38:RCMlSYUnUu4O3fSfZeW3VXd8 |
| .exe | | | InstallShield setup (49.2) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (16.2) |
| .scr | | | Windows screen saver (14.9) |
| .dll | | | Win32 Dynamic Link Library (generic) (7.5) |
| .exe | | | Win32 Executable (generic) (5.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 29696 |
| InitializedDataSize: | 29184 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x80e4 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1164 | "C:\Users\admin\Desktop\2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe" | C:\Users\admin\Desktop\2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 5728 | "C:\Program Files\Java\jre1.8.0_271\bin\jp2launcher.exe" -secure -javaws -jre "C:\Program Files\Java\jre1.8.0_271" -vma LWNsYXNzcGF0aABDOlxQcm9ncmFtIEZpbGVzXEphdmFcanJlMS44LjBfMjcxXGxpYlxkZXBsb3kuamFyAC1EamF2YS5zZWN1cml0eS5wb2xpY3k9ZmlsZTpDOlxQcm9ncmFtIEZpbGVzXEphdmFcanJlMS44LjBfMjcxXGxpYlxzZWN1cml0eVxqYXZhd3MucG9saWN5AC1EdHJ1c3RQcm94eT10cnVlAC1YdmVyaWZ5OnJlbW90ZQAtRGpubHB4LmhvbWU9QzpcUHJvZ3JhbSBGaWxlc1xKYXZhXGpyZTEuOC4wXzI3MVxiaW4ALURqYXZhLnNlY3VyaXR5Lm1hbmFnZXIALURzdW4uYXd0Lndhcm11cD10cnVlAC1YYm9vdGNsYXNzcGF0aC9hOkM6XFByb2dyYW0gRmlsZXNcSmF2YVxqcmUxLjguMF8yNzFcbGliXGphdmF3cy5qYXI7QzpcUHJvZ3JhbSBGaWxlc1xKYXZhXGpyZTEuOC4wXzI3MVxsaWJcZGVwbG95LmphcjtDOlxQcm9ncmFtIEZpbGVzXEphdmFcanJlMS44LjBfMjcxXGxpYlxwbHVnaW4uamFyAC1EamRrLmRpc2FibGVMYXN0VXNhZ2VUcmFja2luZz10cnVlAC1Eam5scHguanZtPUM6XFByb2dyYW0gRmlsZXNcSmF2YVxqcmUxLjguMF8yNzFcYmluXGphdmF3LmV4ZQAtRGpubHB4LnZtYXJncz1MVVJxWkdzdVpHbHpZV0pzWlV4aGMzUlZjMkZuWlZSeVlXTnJhVzVuUFhSeWRXVUE= -ma LVNTVkJhc2VsaW5lVXBkYXRlAC1ub3RXZWJKYXZh | C:\Program Files\Java\jre1.8.0_271\bin\jp2launcher.exe | javaws.exe | ||||||||||||
User: admin Company: Oracle Corporation Integrity Level: MEDIUM Description: Java(TM) Web Launcher Exit code: 0 Version: 11.271.2.09 Modules
| |||||||||||||||
| 5892 | "C:\Users\admin\AppData\Local\Temp\3582-490\2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe" | C:\Users\admin\AppData\Local\Temp\3582-490\2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | ||||||||||||
User: admin Company: Oracle Corporation Integrity Level: MEDIUM Description: Java Update Checker Version: 2.8.401.10 Modules
| |||||||||||||||
| 6712 | "C:\Program Files\Java\jre1.8.0_271\bin\javaws.exe" -J-Djdk.disableLastUsageTracking=true -SSVBaselineUpdate | C:\Program Files\Java\jre1.8.0_271\bin\javaws.exe | — | 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | |||||||||||
User: admin Company: Oracle Corporation Integrity Level: MEDIUM Description: Java(TM) Web Start Launcher Exit code: 0 Version: 11.271.2.09 Modules
| |||||||||||||||
| 7392 | C:\Users\admin\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\FileCoAuth.exe -Embedding | C:\Users\admin\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\FileCoAuth.exe | — | svchost.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 7448 | "C:\Users\admin\AppData\Local\Temp\3582-490\FileCoAuth.exe" -Embedding | C:\Users\admin\AppData\Local\Temp\3582-490\FileCoAuth.exe | — | FileCoAuth.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft OneDriveFile Co-Authoring Executable Exit code: 0 Version: 19.043.0304.0013 Modules
| |||||||||||||||
| 7540 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (5892) 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\JavaSoft\Java Update\Policy\jucheck |
| Operation: | write | Name: | Method |
Value: jau-m | |||
| (PID) Process: | (5892) 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\JavaSoft\Java Update\Policy\jucheck |
| Operation: | write | Name: | LastUpdateBeginTime |
Value: Fri, 18 Apr 2025 04:26:54 GMT | |||
| (PID) Process: | (5892) 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\JavaSoft\Java Update\Policy\jucheck |
| Operation: | delete value | Name: | LocalFileName |
Value: | |||
| (PID) Process: | (5892) 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\JavaSoft\Java Update\Policy\jucheck |
| Operation: | delete value | Name: | InstallOptions |
Value: | |||
| (PID) Process: | (5892) 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\JavaSoft\Java Update\Policy\jucheck |
| Operation: | delete value | Name: | UpdateDescription |
Value: | |||
| (PID) Process: | (5892) 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\JavaSoft\Java Update\Policy\jucheck |
| Operation: | delete value | Name: | UpdateTitle1 |
Value: | |||
| (PID) Process: | (5892) 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\JavaSoft\Java Update\Policy\jucheck |
| Operation: | delete value | Name: | UpdateTitle2 |
Value: | |||
| (PID) Process: | (5892) 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\JavaSoft\Java Update\Policy\jucheck |
| Operation: | delete value | Name: | UpdateMoreInfoUrl |
Value: | |||
| (PID) Process: | (5892) 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\JavaSoft\Java Update\Policy\jucheck |
| Operation: | delete value | Name: | BalloonTitle |
Value: | |||
| (PID) Process: | (5892) 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\JavaSoft\Java Update\Policy\jucheck |
| Operation: | delete value | Name: | BalloonTip |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1164 | 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | C:\Users\admin\AppData\Local\Temp\3582-490\2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | executable | |
MD5:00D43AFFB8E12569A341EC4E86FE07D7 | SHA256:2228007A6284EA84BBFFFCF3C31CA081771F14F4BB94B865D6C2F5DD0D1EF1C2 | |||
| 1164 | 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | C:\ProgramData\Adobe\ARM\S\388\AdobeARMHelper.exe | executable | |
MD5:C2A0798C0FADF00C7A1F374A31012152 | SHA256:9D0BBD67B2CF12AD6B0C5A781377F8A858C71C6861D2C04E4D8DA5E48D0CCBE3 | |||
| 5892 | 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | C:\Users\admin\AppData\Local\Temp\au-descriptor-1.8.0_451-b10.xml | xml | |
MD5:A171AD503E5FF3810E3D50D8E99F5C4C | SHA256:2432429D010EB4BDC79540F489B61A2AE6C042DC1ECE1BA6E034E0A8B1EAAC29 | |||
| 1164 | 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | C:\Users\admin\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\OneDriveUpdaterService.exe | executable | |
MD5:32C1CFACE596E114A37E9A39CC678BDA | SHA256:724D6AF89AE852CF8E19E10E54B533F1304F42DF61B73E3BAE752AB1687AC0C9 | |||
| 1164 | 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe | executable | |
MD5:EA16990673CB3198617430BD8ED90960 | SHA256:17512B1DC73DDE13508659E68EF8463FACE5870FBC5FCF19790F7B452711BCCE | |||
| 1164 | 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | C:\Users\admin\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\FileSyncHelper.exe | executable | |
MD5:DB186E9339BBD1D5793A0A058E6A1B4F | SHA256:22AF3E0CC6DF92A3267290A9462CF9B952E4F0D752B73722B26D63797B65998D | |||
| 5728 | jp2launcher.exe | C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1693682860-607145093-2874071422-1001\83aa4cc77f591dfc2374580bbd95f6ba_bb926e54-e3ca-40fd-ae90-2764341e7792 | binary | |
MD5:C8366AE350E7019AEFC9D1E6E6A498C6 | SHA256:11E6ACA8E682C046C83B721EEB5C72C5EF03CB5936C60DF6F4993511DDC61238 | |||
| 1164 | 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | C:\Users\admin\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\FileSyncConfig.exe | executable | |
MD5:0F27A0A9CD3BD9796B73BBB50E2590FF | SHA256:E0BD73EFACD6095FCC1D7DE8F97A71505879ADBEE626278D32510520B98C7D34 | |||
| 7448 | FileCoAuth.exe | C:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-04-18.0427.7448.1.odl | binary | |
MD5:7527CB19AB1EA1DCABD3FF268A253806 | SHA256:5FD73EDF1E51424FC2959FA5B143CF1AF7DEA2AC8A4E2448A0CAC99526079D95 | |||
| 1164 | 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | C:\Users\admin\AppData\Local\Temp\tmp5023.tmp | text | |
MD5:C7675DDA6121F931F9F9D208E122257A | SHA256:B6AB79C23B7FA907A178234309C2277E5B25340DBA277DC661FF68E5948782BC | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.197.134.132:443 | https://javadl-esd-secure.oracle.com/update/1.8.0/map-m-1.8.0.xml | unknown | — | — | — |
— | — | GET | 200 | 23.197.134.132:443 | https://javadl-esd-secure.oracle.com/update/1.8.0/8a1589aa0fe24566b4337beee47c2d29/au-descriptor-1.8.0_451-b10.xml | unknown | xml | 6.67 Kb | whitelisted |
— | — | POST | 500 | 40.91.76.224:443 | https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail | unknown | xml | 512 b | whitelisted |
— | — | POST | 500 | 40.91.76.224:443 | https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail | unknown | xml | 512 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5892 | 2025-04-18_8c8badf634f5c15d5aebea34d2233f50_amadey_black-basta_elex_hijackloader_luca-stealer_neshta_remcos_smoke-loader.exe | 23.197.134.132:443 | javadl-esd-secure.oracle.com | Akamai International B.V. | US | whitelisted |
5728 | jp2launcher.exe | 23.197.134.132:443 | javadl-esd-secure.oracle.com | Akamai International B.V. | US | whitelisted |
2104 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4776 | slui.exe | 40.91.76.224:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
7540 | slui.exe | 40.91.76.224:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
javadl-esd-secure.oracle.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |