SilentRunLoader Stealer Executes via SilentRunAndUpload.exe for Covert Run-and-Exfil Workflow

  • June 8, 2026
Share with your community:

Zero‑Dwell Threat Intelligence Report

A narrative, executive‑ready view into the malware’s behavior, exposure, and reliable defenses.
Generated: 2026-06-08 08:11:10 UTC

Executive Overview — What We’re Dealing With

This specimen has persisted long enough to matter. Human experts classified it as Malware, and the telemetry confirms a capable, evasive Trojan with real impact potential.

File
5wq0w.exe
Type
Win64 Executable (generic)
SHA‑1
a8409848b0fcec6514b43971358adb33b5a09299
MD5
da3161679965c898574449b7d789451c
First Seen
2026-06-05 12:51:11.314158
Last Analysis
2026-06-05 17:44:17.616244
Dwell Time
4 hours 53 minutes

Extended Dwell Time Impact

For 4+ hours, this malware remained undetected — a limited but sufficient window for the adversary to complete initial execution and establish basic system access.

Comparative Context

Industry studies report a median dwell time closer to 21–24 days. This case represents rapid detection and containment within hours rather than days.

Timeline

Time (UTC) Event Elapsed
2026-04-10 04:54:22 UTC First VirusTotal submission
2026-06-05 19:02:14 UTC Latest analysis snapshot 56 days, 14 hours, 7 minutes
2026-06-08 08:11:10 UTC Report generation time 59 days, 3 hours, 16 minutes

Why It Matters

Every additional day of dwell time is not just an abstract number — it is attacker opportunity. Each day equates to more time for lateral movement, stealth persistence, and intelligence gathering.

Global Detection Posture — Who Caught It, Who Missed It

VirusTotal engines: 71. Detected as malicious: 38. Missed: 33. Coverage: 53.5%.

Detected Vendors

  • Xcitium
  • +37 additional vendors (names not provided)

List includes Xcitium plus an additional 18 vendors per the provided summary.

Missed Vendors

  • Acronis
  • Antiy-AVL
  • Avira
  • Bkav
  • ClamAV
  • CMC
  • Cylance
  • Cynet
  • DrWeb
  • ESET-NOD32
  • F-Secure
  • google_safebrowsing
  • Gridinsoft
  • huorong
  • Jiangmin
  • K7AntiVirus
  • K7GW
  • Malwarebytes
  • NANO-Antivirus
  • Panda
  • Sangfor
  • SUPERAntiSpyware
  • TACHYON
  • tehtris
  • Trapmine
  • VBA32
  • VirIT
  • Webroot
  • Xcitium
  • Yandex
  • Zillya
  • ZoneAlarm
  • Zoner

Why it matters: if any endpoint relies solely on a missed engine, this malware can operate with zero alerts. Prevention‑first controls close that gap regardless of signature lag.

Behavioral Storyline — How the Malware Operates

Dominant system-level operations (82.30% of behavior) suggest this malware performs deep system reconnaissance, privilege escalation, or core OS manipulation. It’s actively probing system defenses and attempting to gain administrative control.

Behavior Categories (weighted)

Weight values represent the frequency and intensity of malware interactions with specific system components. Higher weights indicate more aggressive targeting of that category. Each operation (registry access, file modification, network connection, etc.) contributes to the category’s total weight, providing a quantitative measure of the malware’s behavioral focus.

Category Weight Percentage
System 7195 82.30%
File System 1323 15.13%
Registry 102 1.17%
Process 84 0.96%
Misc 16 0.18%
Windows 7 0.08%
Threading 4 0.05%
Synchronization 4 0.05%
Device 4 0.05%
Hooking 2 0.02%
Crypto 1 0.01%

MITRE ATT&CK Mapping

  • T1059 – accept command line arguments
  • T1083 – enumerate files on Windows
  • T1057 – enumerate process modules
  • T1129 – link function at runtime on Windows
  • T1083 – enumerate files recursively
  • T1129 – parse PE header
  • T1129 – link many functions at runtime
  • T1027 – encode data using XOR
  • T1083 – get file size
  • T1497.001 – reference anti-VM strings targeting Xen
  • T1082 – get disk information
  • T1083 – get common file path
  • T1082 – query environment variable
  • T1071 – Attempts to connect to a dead IP:Port
  • T1071 – Reads data out of its own binary image
  • T1071 – HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • T1071 – The PE file contains an overlay
  • T1027 – The binary contains an unknown PE section name indicative of packing
  • T1027.002 – The binary contains an unknown PE section name indicative of packing
  • T1485 – Anomalous file deletion behavior detected (10+)

Following the Trail — Network & DNS Activity

Outbound activity leans on reputable infrastructure (e.g., CDNs, cloud endpoints) to blend in. TLS sessions and
HTTP calls show routine beaconing and IP‑lookup behavior that can masquerade as normal browsing.

Contacted Domains

Domain IP Country ASN/Org
www.aieov.com 13.248.169.48 United States Amazon Technologies Inc.

Observed IPs

IP Country ASN/Org
224.0.0.252
8.8.4.4 United States Google LLC
8.8.8.8 United States Google LLC

DNS Queries

Request Type
5isohu.com A
www.aieov.com A

Contacted IPs

IP Country ASN/Org
224.0.0.252
8.8.4.4 United States Google LLC
8.8.8.8 United States Google LLC

Port Distribution

Port Count Protocols
137 1 udp
5355 4 udp
53 48 udp

UDP Packets

Source IP Dest IP Sport Dport Time Proto
192.168.56.14 192.168.56.255 137 137 7.07404088973999 udp
192.168.56.14 224.0.0.252 51209 5355 7.036679983139038 udp
192.168.56.14 224.0.0.252 53401 5355 8.477315902709961 udp
192.168.56.14 224.0.0.252 55094 5355 9.601387023925781 udp
192.168.56.14 224.0.0.252 55848 5355 7.03731894493103 udp
192.168.56.14 8.8.4.4 49916 53 102.32238292694092 udp
192.168.56.14 8.8.4.4 50180 53 149.29161596298218 udp
192.168.56.14 8.8.4.4 50710 53 69.71380805969238 udp
192.168.56.14 8.8.4.4 50870 53 318.96356105804443 udp
192.168.56.14 8.8.4.4 50914 53 243.27571392059326 udp
192.168.56.14 8.8.4.4 51262 53 304.604455947876 udp
192.168.56.14 8.8.4.4 52815 53 11.068310022354126 udp
192.168.56.14 8.8.4.4 53449 53 347.5727970600128 udp
192.168.56.14 8.8.4.4 54579 53 55.35433602333069 udp
192.168.56.14 8.8.4.4 54683 53 196.30766987800598 udp
192.168.56.14 8.8.4.4 55827 53 257.63521099090576 udp
192.168.56.14 8.8.4.4 55914 53 131.04173588752747 udp
192.168.56.14 8.8.4.4 56399 53 178.05751299858093 udp
192.168.56.14 8.8.4.4 57742 53 361.9319648742676 udp
192.168.56.14 8.8.4.4 59068 53 333.21341705322266 udp
192.168.56.14 8.8.4.4 60117 53 84.07317900657654 udp
192.168.56.14 8.8.4.4 60713 53 271.99493408203125 udp
192.168.56.14 8.8.4.4 62022 53 163.65061807632446 udp
192.168.56.14 8.8.4.4 62112 53 40.776062965393066 udp
192.168.56.14 8.8.4.4 62548 53 225.02635788917542 udp
192.168.56.14 8.8.4.4 62800 53 290.24448108673096 udp
192.168.56.14 8.8.4.4 63205 53 210.66736793518066 udp
192.168.56.14 8.8.4.4 64753 53 116.68264102935791 udp
192.168.56.14 8.8.4.4 65148 53 26.416929006576538 udp
192.168.56.14 8.8.8.8 49916 53 101.32357692718506 udp
192.168.56.14 8.8.8.8 50180 53 148.29221987724304 udp
192.168.56.14 8.8.8.8 50710 53 68.71488094329834 udp
192.168.56.14 8.8.8.8 50870 53 317.969486951828 udp
192.168.56.14 8.8.8.8 50914 53 242.27630305290222 udp
192.168.56.14 8.8.8.8 51262 53 303.6074290275574 udp
192.168.56.14 8.8.8.8 52815 53 12.057453870773315 udp
192.168.56.14 8.8.8.8 53449 53 346.5740978717804 udp
192.168.56.14 8.8.8.8 54579 53 54.35547995567322 udp
192.168.56.14 8.8.8.8 54683 53 195.31257605552673 udp
192.168.56.14 8.8.8.8 55827 53 256.6366729736328 udp
192.168.56.14 8.8.8.8 55914 53 130.0417160987854 udp
192.168.56.14 8.8.8.8 56399 53 177.06563687324524 udp
192.168.56.14 8.8.8.8 57742 53 360.9336199760437 udp
192.168.56.14 8.8.8.8 59068 53 332.2170510292053 udp
192.168.56.14 8.8.8.8 60117 53 83.0745759010315 udp
192.168.56.14 8.8.8.8 60713 53 270.9964098930359 udp
192.168.56.14 8.8.8.8 62022 53 162.65229105949402 udp
192.168.56.14 8.8.8.8 62112 53 39.777302980422974 udp
192.168.56.14 8.8.8.8 62548 53 224.02618598937988 udp
192.168.56.14 8.8.8.8 62800 53 289.2450919151306 udp
192.168.56.14 8.8.8.8 63205 53 209.6686189174652 udp
192.168.56.14 8.8.8.8 64753 53 115.6843159198761 udp
192.168.56.14 8.8.8.8 65148 53 25.41801691055298 udp

Hunting tip: alert on unknown binaries initiating TLS to IP‑lookup services or unusual CDN endpoints — especially early in execution.

Persistence & Policy — Registry and Services

Registry and service telemetry points to policy awareness and environment reconnaissance rather than noisy persistence. Below is a compact view of the most relevant keys and handles; expand to see the full lists where available.

Registry Opened

22

Registry Set

0

Services Started

0

Services Opened

0

Registry Opened (Top 25)

Key
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize\AppsUseLightTheme
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableUmpdBufferSizeCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppModel\Lookaside\machine
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Display
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppModel\Lookaside\user
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Segment Heap
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SilentRunAndUpload.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\MUI\Settings
Show all (22 total)

Registry Set (Top 25)

Services Started (Top 15)

Services Opened (Top 15)

Like what you see? Share with a friend.