0xblack .dev
Malware research · ARGUS
← all findings
000f85d150af662ada1c4e9208c783ccaaf7283134bce5ff99723d07b3deb90c.exe
Published 2026-08-03 06:29 UTC · ARGUS
Summary Verdict
SUSPICIOUS confidence 95% (high)
SHA-256
000f85d150af662ada1c4e9208c783ccaaf7283134bce5ff99723d07b3deb90c
Packing
unknown/custom (entropy 7.87)
Signals
executable-drop, child-processes, packed
Methodology The sample was executed in an isolated, instrumented Windows VM (host-only networking with emulated C2 responses) while process, file-system, registry and network activity were recorded. The verdict is derived by correlating observed runtime behaviour with static indicators. No sample binary was uploaded or redistributed.
Child processes (1) C:\argus-vr-agent\quarantine\000f85d150af662ada1c4e9208c783ccaaf7283134bce5ff99723d07b3deb90c_extracted\000f85d150af662ada1c4e9208c783ccaaf7283134bce5ff99723d07b3deb90c.exe Dropped files (1) C:\Users\researcher\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\VersionUpdate.exe MITRE ATT&CK T1105 Ingress Tool Transfer / staged payloadT1059 Command and Scripting InterpreterT1027.002 Obfuscated Files or Information: Software Packing
Indicators of Compromise (defanged) 4b605ca699cd96b81df1edb72d03bc26bf353500 85353855d5d34ff6fd68f43a5f5ea3e2 C:\Users\researcher\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\VersionUpdate.exe IOCs (JSON)Copy {
"sha256": "000f85d150af662ada1c4e9208c783ccaaf7283134bce5ff99723d07b3deb90c",
"verdict": "suspicious",
"confidence": 95,
"signals": [
"executable-drop",
"child-processes",
"packed"
],
"attack": [
"T1105",
"T1059",
"T1027.002"
],
"dropped": [
"C:\\Users\\researcher\\AppData\\Roaming\\Microsoft\\Windows\\PowerShell\\PSReadLine\\VersionUpdate.exe"
],
"children": [
"C:\\argus-vr-agent\\quarantine\\000f85d150af662ada1c4e9208c783ccaaf7283134bce5ff99723d07b3deb90c_extracted\\000f85d150af662ada1c4e9208c783ccaaf7283134bce5ff99723d07b3deb90c.exe"
]
}