| File name: | 2025-05-19_d1d59828ca74b548d636615b6c828cc5_black-basta_cobalt-strike_satacom |
| Full analysis: | https://app.any.run/tasks/ae57f06e-ca58-456b-a1e1-3b911c5a607e |
| Verdict: | Malicious activity |
| Analysis date: | May 19, 2025, 04:28:08 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows, 7 sections |
| MD5: | D1D59828CA74B548D636615B6C828CC5 |
| SHA1: | E39E1440971C62E48BD344125826489D840C4825 |
| SHA256: | 84A2E709B53EB187E8F16B951BFEACB5D60E0D41B3FDA6DC1AC92ABFD5FB7B46 |
| SSDEEP: | 196608:HHXvfktYFHBtiN881mwU/kivNAnI9Wkkoo:HHXvfkt8tiN6wU/jFAYpJo |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2025:05:17 17:41:39+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.43 |
| CodeSize: | 173568 |
| InitializedDataSize: | 155648 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xce30 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 7520 | "C:\Users\admin\Desktop\2025-05-19_d1d59828ca74b548d636615b6c828cc5_black-basta_cobalt-strike_satacom.exe" | C:\Users\admin\Desktop\2025-05-19_d1d59828ca74b548d636615b6c828cc5_black-basta_cobalt-strike_satacom.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 7604 | "C:\Users\admin\Desktop\2025-05-19_d1d59828ca74b548d636615b6c828cc5_black-basta_cobalt-strike_satacom.exe" | C:\Users\admin\Desktop\2025-05-19_d1d59828ca74b548d636615b6c828cc5_black-basta_cobalt-strike_satacom.exe | 2025-05-19_d1d59828ca74b548d636615b6c828cc5_black-basta_cobalt-strike_satacom.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 7972 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7520 | 2025-05-19_d1d59828ca74b548d636615b6c828cc5_black-basta_cobalt-strike_satacom.exe | C:\Users\admin\AppData\Local\Temp\_MEI75202\Crypto\Cipher\_raw_cbc.pyd | executable | |
MD5:EB16374178BC01AA8D747320F4F87B29 | SHA256:566FBD9C43DA57ABAAF3112C04D25DD42C46A0476FFA0E8F5845B2A63E3EFF99 | |||
| 7520 | 2025-05-19_d1d59828ca74b548d636615b6c828cc5_black-basta_cobalt-strike_satacom.exe | C:\Users\admin\AppData\Local\Temp\_MEI75202\Crypto\Cipher\_raw_aesni.pyd | executable | |
MD5:22008913F02D3EB99106167F47310C84 | SHA256:1299671282571743D7E88B445750916433DC2DF80C4696AB7B2B0438B0855B83 | |||
| 7520 | 2025-05-19_d1d59828ca74b548d636615b6c828cc5_black-basta_cobalt-strike_satacom.exe | C:\Users\admin\AppData\Local\Temp\_MEI75202\Crypto\Cipher\_raw_des3.pyd | executable | |
MD5:A03344A790C603C5D15820FB434E3ED9 | SHA256:3554BF2DC1556F81F19D51B54A2B634BFAEA8B610B131E9FFC36D07D10315CFA | |||
| 7520 | 2025-05-19_d1d59828ca74b548d636615b6c828cc5_black-basta_cobalt-strike_satacom.exe | C:\Users\admin\AppData\Local\Temp\_MEI75202\Crypto\Cipher\_raw_arc2.pyd | executable | |
MD5:FE0E87F93714087FC66CBEB095A3E2BB | SHA256:CCDA26DE5920C34339038AC93FBB7A6CCB5139AF7A5F8087E08B6E0BC1E47733 | |||
| 7520 | 2025-05-19_d1d59828ca74b548d636615b6c828cc5_black-basta_cobalt-strike_satacom.exe | C:\Users\admin\AppData\Local\Temp\_MEI75202\Crypto\Cipher\_raw_aes.pyd | executable | |
MD5:A927B92173974652EE1570F53A5B419D | SHA256:3A01018171AEEFAE474A6791F0318DAA3373731B7D0F3C165118DF5C12DA3B41 | |||
| 7520 | 2025-05-19_d1d59828ca74b548d636615b6c828cc5_black-basta_cobalt-strike_satacom.exe | C:\Users\admin\AppData\Local\Temp\_MEI75202\Crypto\Cipher\_pkcs1_decode.pyd | executable | |
MD5:8F5AF0BA701B493041777FC34185B7B7 | SHA256:4BE10912BFC5F2372CC030CC9EA94E83048683481FBD7F26BA7F95641AC9E9B4 | |||
| 7520 | 2025-05-19_d1d59828ca74b548d636615b6c828cc5_black-basta_cobalt-strike_satacom.exe | C:\Users\admin\AppData\Local\Temp\_MEI75202\Crypto\Cipher\_raw_ctr.pyd | executable | |
MD5:0A69F60B07A3D347BBCA4E02A796A397 | SHA256:D175DF6236B884968C059A61A4058273EEFB05C6B470EB79E8011AD2AE1ECE0C | |||
| 7520 | 2025-05-19_d1d59828ca74b548d636615b6c828cc5_black-basta_cobalt-strike_satacom.exe | C:\Users\admin\AppData\Local\Temp\_MEI75202\Crypto\Cipher\_raw_cfb.pyd | executable | |
MD5:26ED0DD5AC8C656A62246A9C9F3E935C | SHA256:96F26FFAA3131134785F8C6F97A70F00AE1058A928514863838D88E8D6F406F9 | |||
| 7520 | 2025-05-19_d1d59828ca74b548d636615b6c828cc5_black-basta_cobalt-strike_satacom.exe | C:\Users\admin\AppData\Local\Temp\_MEI75202\Crypto\Hash\_BLAKE2s.pyd | executable | |
MD5:171445643563E613E458665396281943 | SHA256:3B2B3E8311B6B8D5F4E9639FF671DE0E5DAC5405A6D6F54CB3ABAF08F7C916AC | |||
| 7520 | 2025-05-19_d1d59828ca74b548d636615b6c828cc5_black-basta_cobalt-strike_satacom.exe | C:\Users\admin\AppData\Local\Temp\_MEI75202\Crypto\Cipher\_raw_des.pyd | executable | |
MD5:36836C859F54C2D6D6E7210E691B90D3 | SHA256:042DD37D6E721953EA7F4C9A2174DE9C57F6E9581636227724AC64B9318BA108 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2104 | svchost.exe | GET | 200 | 2.16.164.120:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1196 | RUXIMICS.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1196 | RUXIMICS.exe | GET | 200 | 2.16.164.120:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
2104 | svchost.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1196 | RUXIMICS.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2104 | svchost.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2104 | svchost.exe | 2.16.164.120:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
1196 | RUXIMICS.exe | 2.16.164.120:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
2104 | svchost.exe | 23.219.150.101:80 | www.microsoft.com | AKAMAI-AS | CL | whitelisted |
1196 | RUXIMICS.exe | 23.219.150.101:80 | www.microsoft.com | AKAMAI-AS | CL | whitelisted |
7604 | 2025-05-19_d1d59828ca74b548d636615b6c828cc5_black-basta_cobalt-strike_satacom.exe | 172.67.75.40:443 | rentry.co | CLOUDFLARENET | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
rentry.co |
| unknown |
settings-win.data.microsoft.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2196 | svchost.exe | Misc activity | ET INFO Pastebin Service Domain in DNS Lookup (rentry .co) |
7604 | 2025-05-19_d1d59828ca74b548d636615b6c828cc5_black-basta_cobalt-strike_satacom.exe | Misc activity | ET INFO Observed Pastebin Service Domain (rentry .co in TLS SNI) |