0xblack.dev Malware research · ARGUS
← all findings

c93919b24e82d7c32d8e9f2fa7fc5e3138d21a6360752cc79c7f3f0543ced50d.exe

Published 2026-08-03 06:28 UTC · ARGUS
Share on X VirusTotal MalwareBazaar

Summary

Verdict
SUSPICIOUS   confidence 95% (high)
SHA-256
c93919b24e82d7c32d8e9f2fa7fc5e3138d21a6360752cc79c7f3f0543ced50d
Packing
unknown/custom (entropy 7.85)
Signals
executable-drop, child-processes, packed

Methodology

The sample was executed in an isolated, instrumented Windows VM (host-only networking with emulated C2 responses) while process, file-system, registry and network activity were recorded. The verdict is derived by correlating observed runtime behaviour with static indicators. No sample binary was uploaded or redistributed.

Child processes (3)

Dropped files (1)

MITRE ATT&CK

T1105 Ingress Tool Transfer / staged payloadT1059 Command and Scripting InterpreterT1027.002 Obfuscated Files or Information: Software Packing

Indicators of Compromise (defanged)

IOCs (JSON)

{
  "sha256": "c93919b24e82d7c32d8e9f2fa7fc5e3138d21a6360752cc79c7f3f0543ced50d",
  "verdict": "suspicious",
  "confidence": 95,
  "signals": [
    "executable-drop",
    "child-processes",
    "packed"
  ],
  "attack": [
    "T1105",
    "T1059",
    "T1027.002"
  ],
  "dropped": [
    "C:\\Users\\lab\\AppData\\Local\\Temp\\idarykumoj5.ps1"
  ],
  "children": [
    "C:\\WINDOWS\\System32\\Conhost.exe",
    "C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell.exe",
    "C:\\argus-vr-agent\\quarantine\\c93919b24e82d7c32d8e9f2fa7fc5e3138d21a6360752cc79c7f3f0543ced50d_extracted\\c93919b24e82d7c32d8e9f2fa7fc5e3138d21a6360752cc79c7f3f0543ced50d.exe"
  ]
}
ARGUS · 0xblack.dev