0xblack .dev
Malware research · ARGUS
← all findings
0cc87edf5dd17fe02cb5fa8925087374dde0f3a2de206f726f2c98d2f193f6c3.exe
Published 2026-08-03 06:28 UTC · ARGUS
Summary Verdict
SUSPICIOUS confidence 95% (high)
SHA-256
0cc87edf5dd17fe02cb5fa8925087374dde0f3a2de206f726f2c98d2f193f6c3
Packing
unknown/custom (entropy 7.77)
Signals
executable-drop, child-processes, packed
Methodology The sample was executed in an isolated, instrumented Windows VM (host-only networking with emulated C2 responses) while process, file-system, registry and network activity were recorded. The verdict is derived by correlating observed runtime behaviour with static indicators. No sample binary was uploaded or redistributed.
Child processes (1) C:\argus-vr-agent\quarantine\0cc87edf5dd17fe02cb5fa8925087374dde0f3a2de206f726f2c98d2f193f6c3_extracted\0cc87edf5dd17fe02cb5fa8925087374dde0f3a2de206f726f2c98d2f193f6c3.exe Dropped files (2) C:\Users\RESEAR~1\AppData\Local\Temp\nsq8BE3.tmp\System.dll C:\Users\researcher\AppData\Local\Temp\nsq8BE3.tmp\System.dll MITRE ATT&CK T1105 Ingress Tool Transfer / staged payloadT1059 Command and Scripting InterpreterT1027.002 Obfuscated Files or Information: Software Packing
Indicators of Compromise (defanged) 7537d649c3ec62d6de4f4397639abe9d 9cbe5798ca562db8bd9bb63edd11ddb1d1e637f6 C:\Users\RESEAR~1\AppData\Local\Temp\nsq8BE3.tmp\System.dll C:\Users\researcher\AppData\Local\Temp\nsq8BE3.tmp\System.dll IOCs (JSON)Copy {
"sha256": "0cc87edf5dd17fe02cb5fa8925087374dde0f3a2de206f726f2c98d2f193f6c3",
"verdict": "suspicious",
"confidence": 95,
"signals": [
"executable-drop",
"child-processes",
"packed"
],
"attack": [
"T1105",
"T1059",
"T1027.002"
],
"dropped": [
"C:\\Users\\RESEAR~1\\AppData\\Local\\Temp\\nsq8BE3.tmp\\System.dll",
"C:\\Users\\researcher\\AppData\\Local\\Temp\\nsq8BE3.tmp\\System.dll"
],
"children": [
"C:\\argus-vr-agent\\quarantine\\0cc87edf5dd17fe02cb5fa8925087374dde0f3a2de206f726f2c98d2f193f6c3_extracted\\0cc87edf5dd17fe02cb5fa8925087374dde0f3a2de206f726f2c98d2f193f6c3.exe"
]
}