SilentRunLoader Variant Executes as Application form.exe With XOR-Encoded Staging Logic

  • June 8, 2026
Share with your community:

Zero‑Dwell Threat Intelligence Report

A narrative, executive‑ready view into the malware’s behavior, exposure, and reliable defenses.
Generated: 2026-06-08 08:11:10 UTC

Executive Overview — What We’re Dealing With

This specimen has persisted long enough to matter. Human experts classified it as Malware, and the telemetry confirms a capable, evasive Trojan with real impact potential.

File
gi61qu1.exe
Type
Win64 Executable (generic)
SHA‑1
c2a375a60bedf75a3fb014c41b8486ebdc1249d0
MD5
2e738dae88d058110c55b63233cee2de
First Seen
2026-06-05 16:47:47.054208
Last Analysis
2026-06-05 17:27:52.939010
Dwell Time
40 minutes

Extended Dwell Time Impact

For 40+ minutes, this malware was rapidly detected — demonstrating excellent security controls that intercepted the threat during initial execution phases, severely limiting adversary capabilities.

Comparative Context

Industry studies report a median dwell time closer to 21–24 days. This case represents extremely rapid detection within minutes.

Timeline

Time (UTC) Event Elapsed
2026-03-30 11:30:32 UTC First VirusTotal submission
2026-06-05 18:58:34 UTC Latest analysis snapshot 67 days, 7 hours, 28 minutes
2026-06-08 08:11:10 UTC Report generation time 69 days, 20 hours, 40 minutes

Why It Matters

Every additional day of dwell time is not just an abstract number — it is attacker opportunity. Each day equates to more time for lateral movement, stealth persistence, and intelligence gathering.

Global Detection Posture — Who Caught It, Who Missed It

VirusTotal engines: 71. Detected as malicious: 38. Missed: 33. Coverage: 53.5%.

Detected Vendors

  • Xcitium
  • +37 additional vendors (names not provided)

List includes Xcitium plus an additional 18 vendors per the provided summary.

Missed Vendors

  • Acronis
  • Antiy-AVL
  • Avira
  • Bkav
  • ClamAV
  • CMC
  • CrowdStrike
  • Cynet
  • DrWeb
  • F-Secure
  • Gridinsoft
  • huorong
  • Jiangmin
  • K7AntiVirus
  • K7GW
  • Kingsoft
  • Malwarebytes
  • MaxSecure
  • NANO-Antivirus
  • Panda
  • Sangfor
  • SUPERAntiSpyware
  • TACHYON
  • tehtris
  • Trapmine
  • VBA32
  • VirIT
  • Webroot
  • Xcitium
  • Yandex
  • Zillya
  • ZoneAlarm
  • Zoner

Why it matters: if any endpoint relies solely on a missed engine, this malware can operate with zero alerts. Prevention‑first controls close that gap regardless of signature lag.

MITRE ATT&CK Mapping

  • T1059 – accept command line arguments
  • T1027 – encode data using XOR
  • T1129 – parse PE header
  • T1129 – link many functions at runtime
  • T1083 – get file size
  • T1129 – link function at runtime on Windows
  • T1083 – get common file path
  • T1082 – get disk information
  • T1057 – enumerate process modules
  • T1082 – query environment variable
  • T1083 – enumerate files on Windows
  • T1497.001 – reference anti-VM strings targeting Xen
  • T1083 – enumerate files recursively
  • T1129 – Drops a binary and executes it
  • T1564 – A process created a hidden window
  • T1027 – The binary contains an unknown PE section name indicative of packing
  • T1564.003 – A process created a hidden window
  • T1027.002 – The binary contains an unknown PE section name indicative of packing
  • T1071 – Attempts to connect to a dead IP:Port
  • T1071 – Resolves a suspicious Top Level Domain (TLD)
  • T1071 – The PE file contains an overlay
  • T1071 – Reads data out of its own binary image

Persistence & Policy — Registry and Services

Registry and service telemetry points to policy awareness and environment reconnaissance rather than noisy persistence. Below is a compact view of the most relevant keys and handles; expand to see the full lists where available.

Registry Opened

39

Registry Set

0

Services Started

0

Services Opened

0

Registry Opened (Top 25)

Key
HKEY_CURRENT_USER\Control Panel\Desktop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CertDllOpenStoreProv
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv
HKEY_CURRENT_USER\Software\Policies\Microsoft\Control Panel\Desktop
HKEY_USERS\S-1-5-21-4005801669-2598574594-602355426-1001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\crypt32\DiagMatchAnyMask
HKEY_CURRENT_USER\Control Panel\Desktop\PreferredUILanguages
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\MUI\Settings
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize\AppsUseLightTheme
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0
HKEY_CURRENT_USER\Control Panel\Desktop\MuiCached\MachineLanguageConfiguration
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\crypt32\DiagLevel
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap
HKEY_CURRENT_USER\Control Panel\Desktop\LanguageConfiguration
HKEY_CURRENT_USER\Control Panel\Desktop\MuiCached
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages
HKEY_CURRENT_USER\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppModel\Lookaside\user
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppModel\Lookaside\machine
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Display
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SilentRunAndUpload.exe
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Segment Heap
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration
Show all (39 total)

Registry Set (Top 25)

Services Started (Top 15)

Services Opened (Top 15)

Like what you see? Share with a friend.