Zero‑Dwell Threat Intelligence Report
Executive Overview — What We’re Dealing With
This specimen has persisted long enough to matter. Human experts classified it as Malware, and the telemetry confirms a capable, evasive Trojan with real impact potential.
Extended Dwell Time Impact
For 40+ minutes, this malware was rapidly detected — demonstrating excellent security controls that intercepted the threat during initial execution phases, severely limiting adversary capabilities.
Comparative Context
Industry studies report a median dwell time closer to 21–24 days. This case represents extremely rapid detection within minutes.
Timeline
| Time (UTC) | Event | Elapsed |
|---|---|---|
| 2026-03-30 11:30:32 UTC | First VirusTotal submission | — |
| 2026-06-05 18:58:34 UTC | Latest analysis snapshot | 67 days, 7 hours, 28 minutes |
| 2026-06-08 08:11:10 UTC | Report generation time | 69 days, 20 hours, 40 minutes |
Why It Matters
Every additional day of dwell time is not just an abstract number — it is attacker opportunity. Each day equates to more time for lateral movement, stealth persistence, and intelligence gathering.
Global Detection Posture — Who Caught It, Who Missed It
VirusTotal engines: 71. Detected as malicious: 38. Missed: 33. Coverage: 53.5%.
Detected Vendors
- Xcitium
- +37 additional vendors (names not provided)
List includes Xcitium plus an additional 18 vendors per the provided summary.
Missed Vendors
- Acronis
- Antiy-AVL
- Avira
- Bkav
- ClamAV
- CMC
- CrowdStrike
- Cynet
- DrWeb
- F-Secure
- Gridinsoft
- huorong
- Jiangmin
- K7AntiVirus
- K7GW
- Kingsoft
- Malwarebytes
- MaxSecure
- NANO-Antivirus
- Panda
- Sangfor
- SUPERAntiSpyware
- TACHYON
- tehtris
- Trapmine
- VBA32
- VirIT
- Webroot
- Xcitium
- Yandex
- Zillya
- ZoneAlarm
- Zoner
Why it matters: if any endpoint relies solely on a missed engine, this malware can operate with zero alerts. Prevention‑first controls close that gap regardless of signature lag.
MITRE ATT&CK Mapping
- T1059 – accept command line arguments
- T1027 – encode data using XOR
- T1129 – parse PE header
- T1129 – link many functions at runtime
- T1083 – get file size
- T1129 – link function at runtime on Windows
- T1083 – get common file path
- T1082 – get disk information
- T1057 – enumerate process modules
- T1082 – query environment variable
- T1083 – enumerate files on Windows
- T1497.001 – reference anti-VM strings targeting Xen
- T1083 – enumerate files recursively
- T1129 – Drops a binary and executes it
- T1564 – A process created a hidden window
- T1027 – The binary contains an unknown PE section name indicative of packing
- T1564.003 – A process created a hidden window
- T1027.002 – The binary contains an unknown PE section name indicative of packing
- T1071 – Attempts to connect to a dead IP:Port
- T1071 – Resolves a suspicious Top Level Domain (TLD)
- T1071 – The PE file contains an overlay
- T1071 – Reads data out of its own binary image
Persistence & Policy — Registry and Services
Registry and service telemetry points to policy awareness and environment reconnaissance rather than noisy persistence. Below is a compact view of the most relevant keys and handles; expand to see the full lists where available.
39
0
0
0
Registry Opened (Top 25)
| Key |
|---|
| HKEY_CURRENT_USER\Control Panel\Desktop |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CertDllOpenStoreProv |
| HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv |
| HKEY_CURRENT_USER\Software\Policies\Microsoft\Control Panel\Desktop |
| HKEY_USERS\S-1-5-21-4005801669-2598574594-602355426-1001 |
| HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\crypt32\DiagMatchAnyMask |
| HKEY_CURRENT_USER\Control Panel\Desktop\PreferredUILanguages |
| HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\MUI\Settings |
| HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize\AppsUseLightTheme |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
| HKEY_CURRENT_USER\Control Panel\Desktop\MuiCached\MachineLanguageConfiguration |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
| HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\crypt32\DiagLevel |
| HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize |
| HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap |
| HKEY_CURRENT_USER\Control Panel\Desktop\LanguageConfiguration |
| HKEY_CURRENT_USER\Control Panel\Desktop\MuiCached |
| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| HKEY_CURRENT_USER\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages |
| HKEY_CURRENT_USER\ |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16 |
| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable |
| HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots |
| HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc |
| HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize |
| HKEY_LOCAL_MACHINE\System\Setup |
| HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager |
| HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppModel\Lookaside\user |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppModel\Lookaside\machine |
| HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc |
| HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Display |
| HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SilentRunAndUpload.exe |
| HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
| HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Segment Heap |
| HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration |