0xblack.dev Malware research · ARGUS
← all findings

f690fc36d2e6c795b0310cb9af23c0283a8c1ab39322ea8bb6e4f69290c2f14a.exe

Published 2026-08-03 06:28 UTC · ARGUS
Share on X VirusTotal MalwareBazaar

Summary

Verdict
SUSPICIOUS   confidence 95% (high)
Family
RedLineStealer
SHA-256
f690fc36d2e6c795b0310cb9af23c0283a8c1ab39322ea8bb6e4f69290c2f14a
Packing
unknown/custom (entropy 7.93)
Signals
yara-match, executable-drop, child-processes, packed

Methodology

The sample was executed in an isolated, instrumented Windows VM (host-only networking with emulated C2 responses) while process, file-system, registry and network activity were recorded. The verdict is derived by correlating observed runtime behaviour with static indicators. No sample binary was uploaded or redistributed.

Child processes (3)

Dropped files (16)

MITRE ATT&CK

T1105 Ingress Tool Transfer / staged payloadT1059 Command and Scripting InterpreterT1027.002 Obfuscated Files or Information: Software Packing

YARA matches

Injection_API_ComboDownloader_APIsPersistence_RunKeyEmbedded_ExecutableAntiDebug_Checks

Indicators of Compromise (defanged)

IOCs (JSON)

{
  "sha256": "f690fc36d2e6c795b0310cb9af23c0283a8c1ab39322ea8bb6e4f69290c2f14a",
  "family": "RedLineStealer",
  "verdict": "suspicious",
  "confidence": 95,
  "signals": [
    "yara-match",
    "executable-drop",
    "child-processes",
    "packed"
  ],
  "attack": [
    "T1105",
    "T1059",
    "T1027.002"
  ],
  "dropped": [
    "C:\\Users\\RESEAR~1\\AppData\\Local\\Temp\\_MEI29322\\libcrypto-3.dll",
    "C:\\Users\\RESEAR~1\\AppData\\Local\\Temp\\_MEI29322\\libffi-8.dll",
    "C:\\Users\\RESEAR~1\\AppData\\Local\\Temp\\_MEI29322\\libssl-3.dll",
    "C:\\Users\\RESEAR~1\\AppData\\Local\\Temp\\_MEI29322\\python313.dll",
    "C:\\Users\\RESEAR~1\\AppData\\Local\\Temp\\_MEI29322\\tcl86t.dll",
    "C:\\Users\\RESEAR~1\\AppData\\Local\\Temp\\_MEI29322\\tk86t.dll",
    "C:\\Users\\RESEAR~1\\AppData\\Local\\Temp\\_MEI29322\\VCRUNTIME140.dll",
    "C:\\Users\\RESEAR~1\\AppData\\Local\\Temp\\_MEI29322\\VCRUNTIME140_1.dll",
    "C:\\Users\\RESEAR~1\\AppData\\Local\\Temp\\_MEI29322\\zlib1.dll",
    "C:\\Users\\researcher\\AppData\\Roaming\\aobpxyf.exe",
    "C:\\Users\\researcher\\AppData\\Roaming\\apbisx.exe",
    "C:\\Users\\researcher\\AppData\\Roaming\\bipxye.exe"
  ],
  "children": [
    "C:\\Users\\researcher\\AppData\\Roaming\\aobpxyf.exe",
    "C:\\argus-vr-agent\\Veg Checker.exe",
    "C:\\argus-vr-agent\\quarantine\\f690fc36d2e6c795b0310cb9af23c0283a8c1ab39322ea8bb6e4f69290c2f14a_extracted\\f690fc36d2e6c795b0310cb9af23c0283a8c1ab39322ea8bb6e4f69290c2f14a.exe"
  ]
}
ARGUS · 0xblack.dev