Malicious
Classifications
Stealer Spyware
Threat Names
KematianStealer
Dynamic Analysis Report
Created on 2024-07-04T08:21:56+00:00
vppgnb.bat
Windows Batch File
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "15 minutes" to "20 seconds" to reveal dormant functionality.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\RDhJ0CNFevzX\Desktop\kematian.ps1 | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (3)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KematianStealer | KematianStealer | Stealer |
5/5
|
...
|
KematianStealer | Kematian Stealer | Spyware |
5/5
|
...
|
PowerShell_Execution_Commands | PowerShell command execution detected | - |
4/5
|
...
|
b4b21a3f2bbd8eec8bc7d5f86bd1b6d5dcacebcac4dc4d05ef134e732ed5c994 | Downloaded File | Text |
Malicious
|
...
|
»
YARA Matches (3)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PowerShell_Execution_Commands | PowerShell command execution detected | - |
4/5
|
...
|
KematianStealer | KematianStealer | Stealer |
5/5
|
...
|
KematianStealer | Kematian Stealer | Spyware |
5/5
|
...
|
C:\Users\RDhJ0CNFevzX\AppData\Roaming\Kematian\DE-(XC64ZB)-(2024-07-04)-(UTC)\Important Files\R aKsPw6.csv | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\vtn2su4g.0.cs | Dropped File | Text |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\vtn2su4g.out | Dropped File | Text |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\vtn2su4g.cmdline | Dropped File | Text |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\kdotfQjio.bat | Dropped File | Text |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\vtn2su4g.dll | Dropped File | Empty |
Clean
|
...
|
»
b94954783a3a0c42d37cd001fce737c66790f69d3566ab7aa3fcbca8e1bb5536 | Downloaded File | Text |
Clean
|
...
|
»
a1fbe9f6be58f3eb6cc73ad2e73090966e990d330b67cd3c52213625164318e9 | Downloaded File | Unknown |
Clean
|
...
|
»
8e2e6571d18f294798f5b5b25e8beaf20b1d004753bc31b64c99df1327a88160 | Downloaded File | Text |
Clean
|
...
|
»
d701d948474b8d68368b194cbb7acf22d579c7458459e4590617591361f9ad1b | Downloaded File | Text |
Clean
|
...
|
»
2ed27c1421e6928dbe13dbfdb5c59e1045b30341fe7ebe05700006bc5ac572c0 | Downloaded File | Text |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_da21122d-ae44-4f93-ba1d-c9a978ca5b20 | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_67a2505d-bf00-4e2f-b010-406d32caddc3 | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_cc38888a-7080-4220-9b7d-de7a9b2167ba | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_6de40067-cd2a-4666-8cd9-870e0a588215 | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_6fe77092-4798-42ae-bda5-e7f822b580e9 | Modified File | Stream |
Clean
|
...
|
»