Try VMRay Platform
Malicious
Classifications

Stealer Spyware

Threat Names

KematianStealer

Remarks (1/1)

(0x0200000E): The overall sleep time of all monitored processes was truncated from "15 minutes" to "20 seconds" to reveal dormant functionality.

Filters:
File Name Category Type Verdict Actions
C:\Users\RDhJ0CNFevzX\Desktop\vppgnb.bat Sample File Batch
Malicious
»
MIME Type application/x-bat
File Size 3.61 MB
MD5 cbcb58dabe241328f335d5710a7d5564 Copy to Clipboard
SHA1 ca88012046bb818c24980b8d9c6fef0310dcd662 Copy to Clipboard
SHA256 c87215ddba4bbda4ff1c9cf6a8d95012e42d3cecfeb1c22e65f7880e4102388b Copy to Clipboard
SSDeep 6144:eU0L7ReDkuXpOraQftcvIaJfFM9Cl5BpE0m6a9HKT6oJlwApWYcp/Z:I74Dkk+t8tpy9G09HHon8ZZ Copy to Clipboard
ImpHash -
C:\Users\RDhJ0CNFevzX\Desktop\kematian.ps1 Dropped File Text
Malicious
»
MIME Type text/plain
File Size 74.13 KB
MD5 a8631654acf90d83adc4681d485bf3e5 Copy to Clipboard
SHA1 90e48eb01e19ea218362c1f882f776b363d05d6a Copy to Clipboard
SHA256 5687e23ca7e442ea12d71626f29f7822d3d4f1b105f839b173fa015e533b6736 Copy to Clipboard
SSDeep 1536:oSDVn5ahg5yYp6zdv/5l05Qo8l01zhwZPhZcLcJS7srHX6Cd:oSDVn5Uwiv/5IQo8l01zhw5hUc9KCd Copy to Clipboard
ImpHash -
YARA Matches (3)
»
Rule Name Rule Description Classification Score Actions
KematianStealer KematianStealer Stealer
5/5
KematianStealer Kematian Stealer Spyware
5/5
PowerShell_Execution_Commands PowerShell command execution detected -
4/5
b4b21a3f2bbd8eec8bc7d5f86bd1b6d5dcacebcac4dc4d05ef134e732ed5c994 Downloaded File Text
Malicious
»
MIME Type text/plain
File Size 74.13 KB
MD5 57e74958422ad77210f7888b3c963790 Copy to Clipboard
SHA1 0d2d058343778c466e8c780f4d7b331e9f8a83c6 Copy to Clipboard
SHA256 b4b21a3f2bbd8eec8bc7d5f86bd1b6d5dcacebcac4dc4d05ef134e732ed5c994 Copy to Clipboard
SSDeep 1536:oSDVn5ahg5yYp6zdv/5l05Qo8l01zhwZPhZcLcJS7srHX6Cg:oSDVn5Uwiv/5IQo8l01zhw5hUc9KCg Copy to Clipboard
ImpHash -
YARA Matches (3)
»
Rule Name Rule Description Classification Score Actions
PowerShell_Execution_Commands PowerShell command execution detected -
4/5
KematianStealer KematianStealer Stealer
5/5
KematianStealer Kematian Stealer Spyware
5/5
C:\Users\RDhJ0CNFevzX\AppData\Roaming\Kematian\DE-(XC64ZB)-(2024-07-04)-(UTC)\Important Files\R aKsPw6.csv Dropped File Stream
Clean
»
MIME Type application/octet-stream
File Size 38.82 KB
MD5 8726fc6ea24646f678c4420a149350bb Copy to Clipboard
SHA1 7bb9840f24be1b23b7c8878ce0ff048801e14edb Copy to Clipboard
SHA256 89f81f6a29dfec45e0956ea05e1e95fe4d6afc814c60de81b666e73bb7394b0d Copy to Clipboard
SSDeep 768:X0fbOn05RXWj3iu4NFMCRiS+K/Wp83Pzvn3ehLFTTM:kbOn05NWj34NLixt83zn3gLFTTM Copy to Clipboard
ImpHash -
C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\vtn2su4g.0.cs Dropped File Text
Clean
»
MIME Type text/plain
File Size 4.92 KB
MD5 2a829317f65fea84eb85cb2376fa9e21 Copy to Clipboard
SHA1 2f223ea8738f9989385e93b9c8cf0e8fc5e30700 Copy to Clipboard
SHA256 f99c46f447010a438586651fcdf9068394926247bf7656980fee066b2069fe8f Copy to Clipboard
SSDeep 96:JL4W84Ji4AnzvN0OpVDUNKMiNjHJ4OY492VXyNbEqbE:OqHeVRV4oMiNjHJu/VCNIr Copy to Clipboard
ImpHash -
C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\vtn2su4g.out Dropped File Text
Clean
»
MIME Type text/plain
File Size 803 Bytes
MD5 43974785d442bed765ad73b29903534b Copy to Clipboard
SHA1 e4c3dd092b05de15b81fc7905fe1284e64ad5f54 Copy to Clipboard
SHA256 eaeacfbec92c9b9c2dea6b11a2103a9c4e705e4116406978015d7056264a71c6 Copy to Clipboard
SSDeep 12:Kmn/IR37Lvkmb6KOkrk+ik9k2Lkqe1x1+gNxO0WZEd+gNxP:KWId3ka6KOk9k+kqev+VELf Copy to Clipboard
ImpHash -
C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\vtn2su4g.cmdline Dropped File Text
Clean
»
MIME Type text/plain
File Size 708 Bytes
MD5 9d8f51aeb7c467dbf33bf30fbbb2a7e7 Copy to Clipboard
SHA1 61ac3d5fb7596556b2ab00ebd8445900de62eede Copy to Clipboard
SHA256 d152a21ee34cfa3e01a0f7ac497f1fc842fc3aa271f4d4195346918e6a024a5b Copy to Clipboard
SSDeep 12:p37Lvkmb6KOkrk+ik9k2Lkqe1x1+gNxO0WZEd+gNxC:V3ka6KOk9k+kqev+VELS Copy to Clipboard
ImpHash -
C:\Users\RDhJ0CNFevzX\Desktop\kdotfQjio.bat Dropped File Text
Clean
»
Also Known As C:\Users\RDhJ0CNFevzX\Desktop\kdotmZyXn.bat (Accessed File)
C:\Users\RDhJ0CNFevzX\Desktop\kdotnqUTZ.bat (Accessed File)
C:\Users\RDhJ0CNFevzX\Desktop\kdotqzBNDv.bat (Accessed File)
C:\Windows\System32\kdotAqIoB.bat (Accessed File)
C:\Windows\System32\kdotPUzdp.bat (Accessed File)
C:\Windows\System32\kdotkccaDE.bat (Accessed File)
C:\Windows\System32\kdotljBUkx.bat (Accessed File)
C:\Windows\System32\kdottNmtN.bat (Accessed File)
C:\Windows\system32\kdotAqIoB.bat (Accessed File)
C:\Windows\system32\kdotPUzdp.bat (Accessed File)
C:\Windows\system32\kdotkccaDE.bat (Accessed File)
C:\Windows\system32\kdotljBUkx.bat (Accessed File)
C:\Windows\system32\kdottNmtN.bat (Accessed File)
\??\C:\Users\RDhJ0CNFevzX\Desktop\kdotfQjio.bat (Accessed File)
\??\C:\Users\RDhJ0CNFevzX\Desktop\kdotmZyXn.bat (Accessed File)
\??\C:\Users\RDhJ0CNFevzX\Desktop\kdotnqUTZ.bat (Accessed File)
\??\C:\Users\RDhJ0CNFevzX\Desktop\kdotqzBNDv.bat (Accessed File)
\??\C:\Windows\System32\kdotAqIoB.bat (Accessed File)
\??\C:\Windows\System32\kdotPUzdp.bat (Accessed File)
\??\C:\Windows\System32\kdotkccaDE.bat (Accessed File)
\??\C:\Windows\System32\kdotljBUkx.bat (Accessed File)
\??\C:\Windows\System32\kdottNmtN.bat (Accessed File)
kdotAqIoB.bat (Accessed File)
kdotPUzdp.bat (Accessed File)
kdotfQjio.bat (Accessed File)
kdotkccaDE.bat (Accessed File)
kdotljBUkx.bat (Accessed File)
kdotmZyXn.bat (Accessed File)
kdotnqUTZ.bat (Accessed File)
kdotqzBNDv.bat (Accessed File)
kdottNmtN.bat (Accessed File)
MIME Type text/x-msdos-batch
File Size 169 Bytes
MD5 4301a2b0e54b520977d99df5d4d94901 Copy to Clipboard
SHA1 3428339150c80201a46795b1345805daab12e58c Copy to Clipboard
SHA256 c8a20c06d52d6b1af916fd7af0d07e5648f537dee8850bf87dd54cd3c4ace3c5 Copy to Clipboard
SSDeep 3:mKDDgvJxwuMWOc9/tT/zFSvQX4AThQoV1REJOMWW8I/i3IFPbAxg98VEyn:hO/wu9Oc9/trzgvt2hQI1iAMLg34jAxT Copy to Clipboard
ImpHash -
c:\windows\system32\temp.vbs Dropped File Text
Clean
»
Also Known As temp.vbs (Dropped File, Accessed File)
MIME Type text/plain
File Size 90 Bytes
MD5 4c7a00d88939a256a27e9572e19a9dae Copy to Clipboard
SHA1 119890c37752d0e8be17f412afd4725add2d9b01 Copy to Clipboard
SHA256 f816dca0832ec1caf51f1ad02b6e7ceb9a4f34183608f25b995e0af1e6d28935 Copy to Clipboard
SSDeep 3:FER/1GXfeFH5OOc9/tT//FvJFxAAov:FERtbFHIOc9/tr/QAy Copy to Clipboard
ImpHash -
C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\vtn2su4g.dll Dropped File Empty
Clean
»
Also Known As C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\vtn2su4g.err (Dropped File, Accessed File)
C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\vtn2su4g.tmp (Dropped File, Accessed File)
C:\Users\RDhJ0CNFevzX\AppData\Roaming\Kematian\DE-(XC64ZB)-(2024-07-04)-(UTC)\productkey.txt (Accessed File)
MIME Type application/x-empty
File Size 0 Bytes (not extracted)
MD5 d41d8cd98f00b204e9800998ecf8427e Copy to Clipboard
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 Copy to Clipboard
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 Copy to Clipboard
SSDeep 3:: Copy to Clipboard
ImpHash -
b94954783a3a0c42d37cd001fce737c66790f69d3566ab7aa3fcbca8e1bb5536 Downloaded File Text
Clean
»
MIME Type text/plain
File Size 6.30 KB
MD5 75846ce1e77e07545629a87ac9bc4a2b Copy to Clipboard
SHA1 d27af6c792327bf5832148c6797cd88dac333baa Copy to Clipboard
SHA256 b94954783a3a0c42d37cd001fce737c66790f69d3566ab7aa3fcbca8e1bb5536 Copy to Clipboard
SSDeep 96:iPL4W84Ji4AnzvN0OpVDUNKMiNjHJ4OY492VXyNbEqbIQH9idwO3Kglh:isqHeVRV4oMiNjHJu/VCNIgH9MwO3Kyh Copy to Clipboard
ImpHash -
a1fbe9f6be58f3eb6cc73ad2e73090966e990d330b67cd3c52213625164318e9 Downloaded File Unknown
Clean
»
MIME Type application/json
File Size 294 Bytes
MD5 a9490a52b3bca917b5b81dcba4126ef2 Copy to Clipboard
SHA1 4148a4f708ec1a040f096c344792e149fd07bfa3 Copy to Clipboard
SHA256 a1fbe9f6be58f3eb6cc73ad2e73090966e990d330b67cd3c52213625164318e9 Copy to Clipboard
SSDeep 6:YWybuOAX/uMpIIeNX4HO9UQVXEqeLSD7FkTLt8HH/al:YWybuvvX24HXAXMODRG8Hf8 Copy to Clipboard
ImpHash -
8e2e6571d18f294798f5b5b25e8beaf20b1d004753bc31b64c99df1327a88160 Downloaded File Text
Clean
»
MIME Type text/plain
File Size 276 Bytes
MD5 9a1617440fcffbe17121b00d7657e136 Copy to Clipboard
SHA1 81e37f06c03e3cbec4d64da80d9f973ad31fac16 Copy to Clipboard
SHA256 8e2e6571d18f294798f5b5b25e8beaf20b1d004753bc31b64c99df1327a88160 Copy to Clipboard
SSDeep 6:yQycnLNSS17L+LRB2U4DOeNPcvn+LhhaYD41cK2fvFiwj:zymAS13aRB2U4DOeFin+thaeocJvtj Copy to Clipboard
ImpHash -
d701d948474b8d68368b194cbb7acf22d579c7458459e4590617591361f9ad1b Downloaded File Text
Clean
»
MIME Type text/plain
File Size 276 Bytes
MD5 683cfacb866832ab2d6b658bbd018c0f Copy to Clipboard
SHA1 77df05d0550319baa10fe26ca3e48c1f0e785535 Copy to Clipboard
SHA256 d701d948474b8d68368b194cbb7acf22d579c7458459e4590617591361f9ad1b Copy to Clipboard
SSDeep 6:yQycnLNSSzz7L+LRB2U4DOeNPcvn+LhhaYD41cK2fvFiwj:zymASP3aRB2U4DOeFin+thaeocJvtj Copy to Clipboard
ImpHash -
2ed27c1421e6928dbe13dbfdb5c59e1045b30341fe7ebe05700006bc5ac572c0 Downloaded File Text
Clean
»
MIME Type text/plain
File Size 6 Bytes
MD5 d42f2da1df5ecdf29be4ac27edda0c12 Copy to Clipboard
SHA1 b73d74fcede92cdd78ec92c2c5899671d1b32044 Copy to Clipboard
SHA256 2ed27c1421e6928dbe13dbfdb5c59e1045b30341fe7ebe05700006bc5ac572c0 Copy to Clipboard
SSDeep 3:ovn:ovn Copy to Clipboard
ImpHash -
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex Modified File Stream
Clean
»
MIME Type application/octet-stream
File Size 19.46 KB
MD5 9234e11e9f115a0eb7f4d9fa92b2f325 Copy to Clipboard
SHA1 cb3608fe282dd675908ca0066dfa19b58c78f08f Copy to Clipboard
SHA256 5ef0d6eacf198ca68744f5e97cbad33b8cb844efb7e3dc0726f8516bef64c986 Copy to Clipboard
SSDeep 384:yEMLaFIsFa7LaS0ZxTkv/7Jj9TGpspRiuD/1Q6ToDxUesZgsKnRatmLvodCwshzQ:wd+BGYq Copy to Clipboard
ImpHash -
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex Modified File Stream
Clean
»
MIME Type application/octet-stream
File Size 19.46 KB
MD5 f0b1e945b3e420baf29fe353614498bd Copy to Clipboard
SHA1 c389ef8cd3e07b413d874efd46290b957111b270 Copy to Clipboard
SHA256 1dfeddbea90b79e88e4c7f54d2fd61ab8af693f5b73b67fa49a95c91e6c0064d Copy to Clipboard
SSDeep 384:yEjLaFIsFa7LaS0ZxTkv/7Jj9TGpspRiuD/1Q6ToDxUesZgsKnRatmLvodCwshzQ:/d+BGYq Copy to Clipboard
ImpHash -
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex Modified File Stream
Clean
»
MIME Type application/octet-stream
File Size 19.46 KB
MD5 6773a0cef32e5a2ce21ad542246464e0 Copy to Clipboard
SHA1 d6dbdcd8ac860ee4b9018aef28157c9efac218f8 Copy to Clipboard
SHA256 9d0adaeb2b5f152dbdcdb80ab75e4936a43881a186ce6cd17da99085f7cb2f42 Copy to Clipboard
SSDeep 384:yEMLxFIsFa7LaS0ZxTkv/7Jj9TGpspRiuD/1Q6ToDxUesZgsKnRatmLvodCwshzQ:Ld+BGYq Copy to Clipboard
ImpHash -
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex Modified File Stream
Clean
»
MIME Type application/octet-stream
File Size 19.46 KB
MD5 06b6641fd3f0958fbc150223c738f9b9 Copy to Clipboard
SHA1 6515d7eda657885e0ba2ac78d5ce0fa5c073d945 Copy to Clipboard
SHA256 a970572f91f6340b4939cd80537209319ba855436e864b89c4cdb33b2231ab6a Copy to Clipboard
SSDeep 384:yEMLxFZsia7LaS0ZxTkv/7Jj9TGpspRiuD/1Q6ToDxUesZgsKnRatmLvodCwshzQ:zd+BGYq Copy to Clipboard
ImpHash -
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex Modified File Stream
Clean
»
MIME Type application/octet-stream
File Size 19.46 KB
MD5 0eeb128f3e3dcff57c831bd1c9748203 Copy to Clipboard
SHA1 8cf4eb7336b7046e049aa3ac995a1e7d114e16b6 Copy to Clipboard
SHA256 aad8b9ec8ace5b0a2b75c50ee68e9804f77d43b2dc7e54ab61bc60e1ccae4741 Copy to Clipboard
SSDeep 384:yEMLxFZsiaiLzSiZxTkv/7Jj9TGpspRiuD/1Q6ToDxUesZgsKnRatmLvodCwshzQ:1d+BGYq Copy to Clipboard
ImpHash -
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex Modified File Stream
Clean
»
MIME Type application/octet-stream
File Size 19.46 KB
MD5 549da27994966a697909d72e8423dc6a Copy to Clipboard
SHA1 4d152663b957fe62b720109bb94050b23428aedf Copy to Clipboard
SHA256 e599d4887a63c57f5ad20f5b635814203da961f3c52c5f646a0233f23466d0a1 Copy to Clipboard
SSDeep 384:yEMLxFZsFa7LaS0ZxTkv/7Jj9TGpspRiuD/1Q6ToDxUesZgsKnRatmLvodCwshzQ:6d+BGYq Copy to Clipboard
ImpHash -
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_da21122d-ae44-4f93-ba1d-c9a978ca5b20 Modified File Stream
Clean
»
MIME Type application/octet-stream
File Size 10.75 KB
MD5 8845f276e426accd51223008b6aed4bf Copy to Clipboard
SHA1 c9fa81aa57e7c32c4bcefd33788967cc3170fe91 Copy to Clipboard
SHA256 72831bc6962c8017ea71abc038a8f60e79976ebaf05d363c80f32c975a55d0d9 Copy to Clipboard
SSDeep 192:8wUOJGqwAf5CBbXuQuxs0B8HX64MnENxUyrTEAsr9jQ0uwm/CgGZYySo0nbSRNNo:8wUOJGqwARCBbXxss0B8364MnENxUyr3 Copy to Clipboard
ImpHash -
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_67a2505d-bf00-4e2f-b010-406d32caddc3 Modified File Stream
Clean
»
MIME Type application/octet-stream
File Size 8.73 KB
MD5 de26212a79e7c70ea65871ce7c0142bb Copy to Clipboard
SHA1 0ff4743454228ffabbad8cdacda16726baad110c Copy to Clipboard
SHA256 bff972df82ef871cff56b4093f6953a526992555c2913ecd6fede0d642b7cc0a Copy to Clipboard
SSDeep 192:ScPcWHBxheQYm2/ivkcBRc/hy2fZxy7GkiZ2HGjh1E4LQjNKZWLq5kbMyD41vLSe:ScPcWHBxheQYm2/ivkcBRc/hy2fZxy7U Copy to Clipboard
ImpHash -
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_cc38888a-7080-4220-9b7d-de7a9b2167ba Modified File Stream
Clean
»
MIME Type application/octet-stream
File Size 1.77 KB
MD5 c9fa9488f8854802c6f5eff3234d8a8a Copy to Clipboard
SHA1 8b9029e83008d74b8c5414a2ef064629a340c9ae Copy to Clipboard
SHA256 12bd362291f72f2c2e7756742b7377549d13d5bf231455d23ef250c5bdf18121 Copy to Clipboard
SSDeep 24:WM83yV+ty+ZcnPZcMGcZcFc7Vc4vcEvcXc6c4ncSZncJ5S+Z+Wz+q:BSy8PiPiMLim64EEEM34cYcJ5lgDq Copy to Clipboard
ImpHash -
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_6de40067-cd2a-4666-8cd9-870e0a588215 Modified File Stream
Clean
»
MIME Type application/octet-stream
File Size 1.59 KB
MD5 5c8ce5ee94c705d5cf9c9f9ff4ba54a6 Copy to Clipboard
SHA1 6266e20e86de3b206706e66c108982166828c7f4 Copy to Clipboard
SHA256 b0ada1a5b9cd3c6c3c9fa895bf63665129ea3ac1be1391a2064296fdf950fe3a Copy to Clipboard
SSDeep 24:WM83yV+ty+hXpDXTX8XAX8X+XpZX4qXpoPXSJMeS+Z+Wz+q:BSy8Pppbr848Oph4ip2SJplgDq Copy to Clipboard
ImpHash -
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_6fe77092-4798-42ae-bda5-e7f822b580e9 Modified File Stream
Clean
»
MIME Type application/octet-stream
File Size 1.15 KB
MD5 9832b59b183bb6318e62f1385d345c6d Copy to Clipboard
SHA1 54b856a180fb3723403f9aad24ca548de63dc376 Copy to Clipboard
SHA256 bfd60204585f1603ee9faac7c44adb9fcd6fa56b7748f03ecb1a9beaa7c56ea1 Copy to Clipboard
SSDeep 24:WM83yV+ty+qXlIZXxf/DXdQXPZX3X6S+Z+Wz+q:BSy8PilIhNTWPhn6lgDq Copy to Clipboard
ImpHash -
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image