MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 051c5d064ba3816e2eb061b2f1b96c8bf3609b038831464596c3a8436d3415eb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DiamondFox


Vendor detections: 7


Intelligence 7 IOCs 1 YARA 10 File information Comments

SHA256 hash: 051c5d064ba3816e2eb061b2f1b96c8bf3609b038831464596c3a8436d3415eb
SHA3-384 hash: d26a224ecfd826e106f182e999f77ca00a6ac88f1a80406448aece225f02b88dbbe343f48cf5aadb2fa9c7868404791b
SHA1 hash: 1b16696a621004b0cc5dd293598d1d585608874d
MD5 hash: 74f57657c904faaf18f9423ce1764469
humanhash: finch-twelve-pluto-bluebird
File name:74F57657C904FAAF18F9423CE1764469.exe
Download: download sample
Signature DiamondFox
File size:4'925'552 bytes
First seen:2021-09-01 16:26:01 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 32569d67dc210c5cb9a759b08da2bdb3 (122 x RedLineStealer, 42 x DiamondFox, 37 x RaccoonStealer)
ssdeep 98304:xwCvLUBsgBgXYnBqxLdOKR0na+ieB11ajgqs2Avn:xNLUCgBgXhLoKinfnB1OKvn
Threatray 459 similar samples on MalwareBazaar
TLSH T1B7363358BE9188FEDD8211390C54A7B3A2FED3494E3828EB5F4758395F189E3935EC09
dhash icon 848c5454baf47474 (2'088 x Adware.Neoreklami, 101 x RedLineStealer, 33 x DiamondFox)
Reporter abuse_ch
Tags:DiamondFox exe


Avatar
abuse_ch
DiamondFox C2:
http://45.142.215.144/

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://45.142.215.144/ https://threatfox.abuse.ch/ioc/204183/

Intelligence


File Origin
# of uploads :
1
# of downloads :
204
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Searching for the window
Running batch commands
Connection attempt
Sending a custom TCP request
DNS request
Sending an HTTP GET request
Deleting a recently created file
Launching a process
Sending a UDP request
Result
Threat name:
RedLine Vidar
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Adds a directory exclusion to Windows Defender
Antivirus detection for dropped file
Antivirus detection for URL or domain
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Creates processes via WMI
Disable Windows Defender real time protection (registry)
Found many strings related to Crypto-Wallets (likely being stolen)
Machine Learning detection for dropped file
Maps a DLL or memory area into another process
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
PE file has a writeable .text section
PE file has nameless sections
Sigma detected: Powershell Defender Exclusion
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: Suspicious Svchost Process
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Yara detected RedLine Stealer
Yara detected Vidar stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 475942 Sample: BO4kkcAoaF.exe Startdate: 01/09/2021 Architecture: WINDOWS Score: 100 62 104.21.17.130 CLOUDFLARENETUS United States 2->62 64 104.21.20.198 CLOUDFLARENETUS United States 2->64 66 3 other IPs or domains 2->66 86 Antivirus detection for URL or domain 2->86 88 Antivirus detection for dropped file 2->88 90 Multi AV Scanner detection for dropped file 2->90 92 12 other signatures 2->92 9 BO4kkcAoaF.exe 17 2->9         started        signatures3 process4 file5 42 C:\Users\user\AppData\...\setup_install.exe, PE32 9->42 dropped 44 C:\Users\user\AppData\...\Sun04dac6d7a0.exe, PE32 9->44 dropped 46 C:\Users\user\...\Sun047089ae5093c14.exe, PE32 9->46 dropped 48 12 other files (5 malicious) 9->48 dropped 12 setup_install.exe 1 9->12         started        process6 dnsIp7 82 104.21.87.76 CLOUDFLARENETUS United States 12->82 84 127.0.0.1 unknown unknown 12->84 112 Adds a directory exclusion to Windows Defender 12->112 16 cmd.exe 1 12->16         started        18 cmd.exe 1 12->18         started        20 cmd.exe 1 12->20         started        22 6 other processes 12->22 signatures8 process9 signatures10 25 Sun043e60205beb4f.exe 64 16->25         started        30 Sun047089ae5093c14.exe 18->30         started        32 Sun045118d0261f811cc.exe 3 20->32         started        94 Adds a directory exclusion to Windows Defender 22->94 34 Sun041024b30f4a0.exe 1 22->34         started        36 Sun043bec3ec581a9.exe 12 22->36         started        38 Sun04637c853e.exe 2 22->38         started        40 powershell.exe 26 22->40         started        process11 dnsIp12 68 37.0.10.214 WKD-ASIE Netherlands 25->68 70 37.0.10.237 WKD-ASIE Netherlands 25->70 78 10 other IPs or domains 25->78 50 C:\Users\...50amldsBbSU4ZWwObHHleCO_4.exe, PE32 25->50 dropped 52 C:\Users\user\AppData\...\rus01_1[1].bmp, PE32 25->52 dropped 54 C:\Users\user\AppData\...\passat01_1[1].bmp, PE32 25->54 dropped 60 41 other files (20 malicious) 25->60 dropped 96 Machine Learning detection for dropped file 25->96 98 Tries to harvest and steal browser information (history, passwords, etc) 25->98 100 Disable Windows Defender real time protection (registry) 25->100 102 Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation)) 30->102 104 Maps a DLL or memory area into another process 30->104 106 Checks if the current machine is a virtual machine (disk enumeration) 30->106 80 2 other IPs or domains 32->80 56 C:\Users\user\AppData\Local\Temp\sqlite.dll, PE32 32->56 dropped 108 Creates processes via WMI 32->108 72 208.95.112.1 TUT-ASUS United States 34->72 74 45.136.151.102 ENZUINC-US Latvia 34->74 76 74.114.154.18 AUTOMATTICUS Canada 36->76 58 C:\Users\user\AppData\...\Sun04637c853e.tmp, PE32 38->58 dropped 110 Antivirus detection for dropped file 38->110 file13 signatures14
Threat name:
Win32.Trojan.ArkeiStealer
Status:
Malicious
First seen:
2021-08-29 16:22:16 UTC
AV detection:
22 of 28 (78.57%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:glupteba family:metasploit family:redline family:smokeloader family:vidar botnet:706 aspackv2 backdoor dropper infostealer loader persistence stealer suricata trojan
Behaviour
Creates scheduled task(s)
Kills process with taskkill
Script User-Agent
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Adds Run key to start application
Legitimate hosting services abused for malware hosting/C2
Looks up external IP address via web service
Loads dropped DLL
ASPack v2.12-2.42
Downloads MZ/PE file
Executes dropped EXE
Vidar Stealer
Glupteba
Glupteba Payload
MetaSploit
Process spawned unexpected child process
RedLine
RedLine Payload
SmokeLoader
Vidar
suricata: ET MALWARE JS/Nemucod requesting EXE payload 2016-02-01
suricata: ET MALWARE JS/Nemucod.M.gen downloading EXE payload
suricata: ET MALWARE Suspicious Zipped Filename in Outbound POST Request (Passwords.txt)
suricata: ET MALWARE Vidar/Arkei Stealer Client Data Upload
suricata: ET MALWARE Vidar/Arkei/Megumin/Oski Stealer Data Exfil
Malware Config
C2 Extraction:
https://eduarroma.tumblr.com/
http://varmisende.com/upload/
http://fernandomayol.com/upload/
http://nextlytm.com/upload/
http://people4jan.com/upload/
http://asfaltwerk.com/upload/
Unpacked files
SH256 hash:
aafc69d03ed7357afe5ace72217e769a49791b0d275fe5e432180903cce805be
MD5 hash:
5491cf213d898b6e6b0addbd4dc4f073
SHA1 hash:
138528e384217d5cecf44cb12fc29a8d77bbfbd6
SH256 hash:
a18e5d223da775448e2e111101fe1f4ab919be801fd435d3a278718aa5e6ccba
MD5 hash:
0c6cae115465a83f05d3ff391fd009ac
SHA1 hash:
066ea93bb540ae4be0d2e522d4bb59eec74053ad
SH256 hash:
835c9b5e60ebf50a888e851d1c7218d436490613ec04a04055b73fbddf73edf3
MD5 hash:
6961557695f34a53cf8224be7c265fbe
SHA1 hash:
f52d34d0b1dbd181f2acb21f42d875d514afb6f7
SH256 hash:
64ffc8a9ef49470c23de2952972cf796f9a081f902e0b35f7bdc270a9784f06a
MD5 hash:
5f61cabf346884d12876eaefad9da7ba
SHA1 hash:
f18ea2dfe4e3e5e3a803c5d08945a1200ed84130
SH256 hash:
de776a861c0437152110af6c8587371652700b593aba04570845b1f43354d48e
MD5 hash:
5760f92ffa3e901f79ba5a228da4ffb4
SHA1 hash:
c835255267fbeffd5acfe441a970b1b9ad57f9ae
SH256 hash:
fbffb84931a267fab6c24cf08723fa029cb85c2315f01d5b1f41922350adb831
MD5 hash:
052270e8e9cfb3512932e0df484caef4
SHA1 hash:
85305fee690beea8458bab5d55d0368c47340501
SH256 hash:
b5864940981481cef770a0a09268cb5aaf63a86d32fa7ff980dc22a72f855697
MD5 hash:
f2a75bdb477dbc61a40c582493f91599
SHA1 hash:
822664f9040b7a38cf64a943973196e7b418e936
SH256 hash:
24da4be8c1d9ca77f30cfea2e4fa4113d2be3497a1efba8c2465605dccf20166
MD5 hash:
698f103458a664e57eae14b914673934
SHA1 hash:
71f6f414b92fc5daf178e5b0d49a24fd4890439b
SH256 hash:
eb97bd9ab0539b21f0be447002d004efeec3133811022f73516cb7627f3b5fc1
MD5 hash:
ab73cc413405209fcf52577c34c2c8a3
SHA1 hash:
6bb120fa23e1198528f251efe74bdd27f67c47d2
SH256 hash:
603c61184bc21390d64d8fe234f3b5928bb38384bd382aa0466980909b7ed60b
MD5 hash:
427aa284f4b287435f555b948ea061ce
SHA1 hash:
3d087b25e1fedf107abb78c337b965a9bdea8c1d
SH256 hash:
9791a7cf7065aefbb1b011c11e9f4de289cbea1133bb21c6f5b8016a883a4ee9
MD5 hash:
be4e6f7c03e32f970bc232e50ef94a12
SHA1 hash:
023f5aa8d4ac88edee4133dc192515fee662b0e2
SH256 hash:
e427f8ef21691e3d8c2313d11129ad08ddef69a158eca2f77c170603478ff0c4
MD5 hash:
0dedd909aae9aa0a89b4422106310e9e
SHA1 hash:
271d36afa5b729ee590cf8066166ca5e9c9d0340
SH256 hash:
a6ee51d3b2994c3b07f410cec3384108a4f58698ec15bbc773286b884c221af0
MD5 hash:
49677de9cbebdd846500333088ed8dd9
SHA1 hash:
f05e2a9d22b62db7e185b5f8a80e38acecdeba11
SH256 hash:
136cb85b7e7225856384d639bc9d85e43a96ad385d73e08c2c8cab04f77f27d5
MD5 hash:
36595166fa367c57f7b3a7b5ec639229
SHA1 hash:
f6c8538a9f762f772bf27a891175583b979b40c4
SH256 hash:
517cb559cede9713cf9e87601ade2d53fe6c3a4433ea5c4ac97ac95c74768e11
MD5 hash:
0b030edc2307521094d42927ea01a28e
SHA1 hash:
fd0b84991ca84b2f394ba715d2b5cf36338680e4
SH256 hash:
d11960ae4df065ca1a728c05abfe2a242a0d75c69ca0e37802117f1006f75042
MD5 hash:
5bbc2e2c0d47aff5543535b4fdcd5a30
SHA1 hash:
fe00f5255bf0060d356eeb2ac238cdaad1776ef3
SH256 hash:
051c5d064ba3816e2eb061b2f1b96c8bf3609b038831464596c3a8436d3415eb
MD5 hash:
74f57657c904faaf18f9423ce1764469
SHA1 hash:
1b16696a621004b0cc5dd293598d1d585608874d
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_SUSPICIOUS_EXE_Referenfces_Messaging_Clients
Author:ditekSHen
Description:Detects executables referencing many email and collaboration clients. Observed in information stealers
Rule name:INDICATOR_SUSPICIOUS_EXE_SQLQuery_ConfidentialDataStore
Author:ditekSHen
Description:Detects executables containing SQL queries to confidential data stores. Observed in infostealers
Rule name:INDICATOR_SUSPICIOUS_EXE_WindDefender_AntiEmaulation
Author:ditekSHen
Description:Detects executables containing potential Windows Defender anti-emulation checks
Rule name:MALWARE_Win_RedLine
Author:ditekSHen
Description:Detects RedLine infostealer
Rule name:MALWARE_Win_Vidar
Author:ditekSHen
Description:Detects Vidar / ArkeiStealer
Rule name:RedOctoberPluginCollectInfo
Rule name:SUSP_XORed_Mozilla
Author:Florian Roth
Description:Detects suspicious XORed keyword - Mozilla/5.0
Reference:Internal Research
Rule name:SUSP_XORed_MSDOS_Stub_Message
Author:Florian Roth
Description:Detects suspicious XORed MSDOS stub message
Reference:https://yara.readthedocs.io/en/latest/writingrules.html#xor-strings
Rule name:Vidar
Author:kevoreilly
Description:Vidar Payload
Rule name:win_raccoon_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.raccoon.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments