File name:

2025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee

Full analysis: https://app.any.run/tasks/3888b911-7df2-45e6-a4c2-9cfe7e31a805
Verdict: Malicious activity
Analysis date: May 15, 2025, 18:52:30
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
urelas
bootkit
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

CA1D5D19884E6A527F103424E963CC8C

SHA1:

D71F3D0D4B35FA26F304E89F9844E17E62E12491

SHA256:

B41FF8587FE23648A561E7EAE8048A5BB546C684C6049F200B35CFD988A7DB4F

SSDEEP:

6144:8bF8kKJ89Mxbf74lu1gxcsHaYEUvDq8Y+hR0UVPPob8/eSiMG/Pt2Z0OL3kC8HyF:W8gwg6YEa3oaeLbYZXgChU2YLfgV1+CJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • URELAS has been detected

      • 2025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee.exe (PID: 5864)
      • opdev.exe (PID: 5588)
      • gujoco.exe (PID: 5552)
      • tidaq.exe (PID: 5344)
    • URELAS mutex has been found

      • gujoco.exe (PID: 5552)
    • URELAS has been detected (YARA)

      • gujoco.exe (PID: 5552)
      • tidaq.exe (PID: 5344)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 2025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee.exe (PID: 5864)
      • opdev.exe (PID: 5588)
      • gujoco.exe (PID: 5552)
      • tidaq.exe (PID: 5344)
    • Reads security settings of Internet Explorer

      • 2025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee.exe (PID: 5864)
      • opdev.exe (PID: 5588)
      • gujoco.exe (PID: 5552)
    • Starts itself from another location

      • 2025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee.exe (PID: 5864)
      • opdev.exe (PID: 5588)
    • Starts CMD.EXE for commands execution

      • 2025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee.exe (PID: 5864)
      • gujoco.exe (PID: 5552)
    • Executing commands from a ".bat" file

      • 2025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee.exe (PID: 5864)
      • gujoco.exe (PID: 5552)
    • Connects to unusual port

      • gujoco.exe (PID: 5552)
    • There is functionality for taking screenshot (YARA)

      • tidaq.exe (PID: 5344)
  • INFO

    • Create files in a temporary directory

      • 2025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee.exe (PID: 5864)
      • opdev.exe (PID: 5588)
      • gujoco.exe (PID: 5552)
      • tidaq.exe (PID: 5344)
    • Reads the computer name

      • 2025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee.exe (PID: 5864)
      • opdev.exe (PID: 5588)
      • gujoco.exe (PID: 5552)
    • Checks supported languages

      • 2025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee.exe (PID: 5864)
      • opdev.exe (PID: 5588)
      • gujoco.exe (PID: 5552)
      • tidaq.exe (PID: 5344)
    • Process checks computer location settings

      • 2025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee.exe (PID: 5864)
      • opdev.exe (PID: 5588)
      • gujoco.exe (PID: 5552)
    • Checks proxy server information

      • slui.exe (PID: 5416)
    • Reads the software policy settings

      • slui.exe (PID: 5416)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2013:08:07 06:38:42+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 108544
InitializedDataSize: 259584
UninitializedDataSize: -
EntryPoint: 0xc85b
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
9
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #URELAS 2025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee.exe #URELAS opdev.exe cmd.exe no specs conhost.exe no specs #URELAS gujoco.exe slui.exe #URELAS tidaq.exe cmd.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1164\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1180C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\_vslite.bat" "C:\Windows\SysWOW64\cmd.exe2025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1188\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2088C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\_vslite.bat" "C:\Windows\SysWOW64\cmd.exegujoco.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
5344"C:\Users\admin\AppData\Local\Temp\tidaq.exe" C:\Users\admin\AppData\Local\Temp\tidaq.exe
gujoco.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\tidaq.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5416C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5552"C:\Users\admin\AppData\Local\Temp\gujoco.exe" OKC:\Users\admin\AppData\Local\Temp\gujoco.exe
opdev.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\gujoco.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5588"C:\Users\admin\AppData\Local\Temp\opdev.exe" hiC:\Users\admin\AppData\Local\Temp\opdev.exe
2025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\opdev.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5864"C:\Users\admin\Desktop\2025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee.exe" C:\Users\admin\Desktop\2025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\2025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
4 553
Read events
4 553
Write events
0
Delete events
0

Modification events

No data
Executable files
4
Suspicious files
0
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
5588opdev.exeC:\Users\admin\AppData\Local\Temp\gujoco.exeexecutable
MD5:EF1D52E1FDFD3CD56C53087A3BCDC7D9
SHA256:A1DAD46D01C6491B033299C15E3561A00644F4F57BB0D0B04CA34B153913F088
5552gujoco.exeC:\Users\admin\AppData\Local\Temp\tidaq.exeexecutable
MD5:501D79BE7C284EC8267FBD348003F2EE
SHA256:CAC871FF45637E817CC701CD9AA0F2F8F607B292FAF21AD04E3B34302A6788C7
5344tidaq.exeC:\Users\admin\AppData\Local\Temp\opdev.exeexecutable
MD5:536BFF3948E62CCD5354CB227983164D
SHA256:D17251F17D5DEFF851FAB7BFC20141EC534C90EF7E4A584E41F15886400C53D1
5552gujoco.exeC:\Users\admin\AppData\Local\Temp\_vslite.battext
MD5:7F010BDEB31D8F588ECA181F3E22A921
SHA256:59E29871AC10B9A5C6D5828B653377A008D0F9EC88B8665EA2A79E6CF99C72C7
58642025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee.exeC:\Users\admin\AppData\Local\Temp\opdev.exeexecutable
MD5:933805CF1EFE362E7341BDC94ED35235
SHA256:6B3D9B8AF8E90A04336E6935F072D7A3DDC5FC22FBC0ED88756826E67D25492C
58642025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee.exeC:\Users\admin\AppData\Local\Temp\_vslite.battext
MD5:7C7F7E160E11CA09EF61E29859F6B2A3
SHA256:2DCEC0F23ACD8E1FFC2EFBA2D9A934BEE7DC86B1424330857111449C56980658
58642025-05-15_ca1d5d19884e6a527f103424e963cc8c_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stealc_tofsee.exeC:\Users\admin\AppData\Local\Temp\golfinfo.initext
MD5:1D0C7814439F3808ADDDA52D1B3D6441
SHA256:F95FA7492EE38C643C4C9F629974AD597B92D902A43DB3253ACA80C902D6466A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
42
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6036
SIHClient.exe
GET
200
23.53.40.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6036
SIHClient.exe
GET
200
23.53.40.176:80
http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl
unknown
whitelisted
6036
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.1.crl
unknown
whitelisted
6036
SIHClient.exe
GET
200
23.53.40.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
6036
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.1.crl
unknown
whitelisted
6036
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6036
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.2.crl
unknown
whitelisted
6036
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.2.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
5552
gujoco.exe
218.54.31.226:11110
SK Broadband Co Ltd
KR
malicious
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
4
System
192.168.100.255:137
whitelisted
6036
SIHClient.exe
172.202.163.200:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
GB
whitelisted
6036
SIHClient.exe
23.53.40.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6036
SIHClient.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
6036
SIHClient.exe
40.69.42.241:443
fe3cr.delivery.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.46
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
crl.microsoft.com
  • 23.53.40.176
  • 23.53.40.178
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
  • 20.83.72.98
whitelisted
nexusrules.officeapps.live.com
  • 52.111.243.30
whitelisted
login.live.com
  • 20.190.160.66
  • 20.190.160.132
  • 40.126.32.140
  • 20.190.160.2
  • 20.190.160.20
  • 40.126.32.138
  • 40.126.32.74
  • 40.126.32.134
whitelisted

Threats

No threats detected
No debug info