MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 14490c9c139e9bc984781f8143a571e1f1f140c69a7cd12c34fc0bf20abb0889. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



BlackNET


Vendor detections: 17


Intelligence 17 IOCs YARA 6 File information Comments

SHA256 hash: 14490c9c139e9bc984781f8143a571e1f1f140c69a7cd12c34fc0bf20abb0889
SHA3-384 hash: a156c5492104a915b0bdde94154fc551b1a040d11c500fc2b79a383643853c61b18651ee5e7406404fceeac19a5f2d1f
SHA1 hash: a179259548f9e81b65126130342f5b076c8b8a77
MD5 hash: baa73a9b35bf02d8c56a1286bcd2d714
humanhash: batman-berlin-nitrogen-alabama
File name:BAA73A9B35BF02D8C56A1286BCD2D714.exe
Download: download sample
Signature BlackNET
File size:1'201'952 bytes
First seen:2024-01-28 19:05:10 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'125 x AgentTesla, 20'148 x Formbook, 12'362 x SnakeKeylogger)
ssdeep 12288:DCwHtUz0qTqcXrwV+XinIBLAx9gKupscZ0PpHTzY8QGWlCL8K7XLlq95ZPFdmUG/:DCwHybsV/IOv6scZ0BzUfCz3+zsw8YS
Threatray 24 similar samples on MalwareBazaar
TLSH T19645BFA517DA2A10D1FF5B72D8F12A0697F5F823D7AAE31B188411FD0C5AB925C43B23
TrID 67.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
9.7% (.EXE) Win64 Executable (generic) (10523/12/4)
6.0% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.1% (.EXE) Win32 Executable (generic) (4505/5/1)
File icon (PE):PE icon
dhash icon e8b249cd4dc982e0 (7 x CoinMiner, 4 x AsyncRAT, 4 x VenomRAT)
Reporter abuse_ch
Tags:BlackNet exe


Avatar
abuse_ch
BlackNET C2:
http://190.123.44.240/receive.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
336
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
blacknet
ID:
1
File name:
14490c9c139e9bc984781f8143a571e1f1f140c69a7cd12c34fc0bf20abb0889.exe
Verdict:
Malicious activity
Analysis date:
2024-01-29 01:45:42 UTC
Tags:
blacknet trojan

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Sending a custom TCP request
Creating a file in the %AppData% directory
Restart of the analyzed sample
Creating a file
Creating a window
Сreating synchronization primitives
Using the Windows Management Instrumentation requests
Sending an HTTP GET request
Creating a file in the %AppData% subdirectories
Enabling the 'hidden' option for recently created files
Enabling the 'hidden' option for analyzed file
Creating a process from a recently created file
Unauthorized injection to a recently created process
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Enabling autorun by creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
obfuscated overlay packed packed phishing smartassembly smart_assembly
Malware family:
BlackNet RAT
Verdict:
Malicious
Result
Threat name:
BlackNET, PureLog Stealer
Detection:
malicious
Classification:
troj.spyw.expl.evad.mine
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Contains functionality to log keystrokes (.Net Source)
Creates autostart registry keys with suspicious names
Drops VBS files to the startup folder
Found strings related to Crypto-Mining
Injects a PE file into a foreign processes
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: Drops script at startup location
Snort IDS alert for network traffic
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Yara detected BlackNET
Yara detected Costura Assembly Loader
Yara detected Generic Downloader
Yara detected PureLog Stealer
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1382353 Sample: 9l72TMHrLC.exe Startdate: 28/01/2024 Architecture: WINDOWS Score: 100 47 Snort IDS alert for network traffic 2->47 49 Multi AV Scanner detection for domain / URL 2->49 51 Malicious sample detected (through community Yara rule) 2->51 53 8 other signatures 2->53 8 9l72TMHrLC.exe 6 2->8         started        12 wscript.exe 1 2->12         started        14 9l72TMHrLC.exe 2->14         started        16 9l72TMHrLC.exe 2->16         started        process3 file4 41 C:\Users\user\AppData\Roaming\Sksewdjj.exe, PE32 8->41 dropped 43 C:\Users\user\AppData\...\Sksewdjj.vbs, ASCII 8->43 dropped 61 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 8->61 63 Found strings related to Crypto-Mining 8->63 65 Drops VBS files to the startup folder 8->65 67 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 8->67 18 9l72TMHrLC.exe 16 6 8->18         started        69 Windows Scripting host queries suspicious COM object (likely to drop second stage) 12->69 22 Sksewdjj.exe 5 12->22         started        71 Injects a PE file into a foreign processes 14->71 25 9l72TMHrLC.exe 14->25         started        27 9l72TMHrLC.exe 16->27         started        signatures5 process6 dnsIp7 45 190.123.44.240, 49738, 49740, 49741 ALTANREDESSAPIdeCVMX Panama 18->45 39 C:\Users\user\AppData\...\WindowsUpdate.exe, PE32 18->39 dropped 29 WindowsUpdate.exe 5 18->29         started        57 Multi AV Scanner detection for dropped file 22->57 59 Injects a PE file into a foreign processes 22->59 32 Sksewdjj.exe 22->32         started        file8 signatures9 process10 signatures11 73 Multi AV Scanner detection for dropped file 29->73 75 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 29->75 77 Injects a PE file into a foreign processes 29->77 34 WindowsUpdate.exe 29->34         started        37 WindowsUpdate.exe 29->37         started        process12 signatures13 55 Creates autostart registry keys with suspicious names 34->55
Threat name:
Win32.Trojan.Smokeloader
Status:
Malicious
First seen:
2024-01-26 09:58:28 UTC
File Type:
PE (.Net Exe)
Extracted files:
14
AV detection:
20 of 24 (83.33%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:blacknet family:zgrat botnet:hacked persistence rat trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Adds Run key to start application
Checks computer location settings
Drops startup file
Executes dropped EXE
Loads dropped DLL
BlackNET
BlackNET payload
Contains code to disable Windows Defender
Detect ZGRat V1
ZGRat
Malware Config
C2 Extraction:
http://190.123.44.240
Unpacked files
SH256 hash:
84b5b3229baa923cd5b7390e9eb054e792fabbfafb7b351d2194f6589817a21d
MD5 hash:
3c9ae215cbad59684d48849ceeacef30
SHA1 hash:
31debb20e41c47759221e745287806a9238d66fd
SH256 hash:
e1aa988efc3ee2cad1fa25d61d9339ea081a34ae6f23b43c4d986e6f529690e2
MD5 hash:
ada1b6df693e033693b8f4f7dfff2131
SHA1 hash:
c3e6e1dbf5d3adb7d5a9a07288b4cdee558813de
SH256 hash:
9224f14845cc700eaca9a89dfeeea13da9ae0311f8b97c7d206f8ce9f88a46d1
MD5 hash:
2346dfbc4b04b94f4d494a35cdbb9073
SHA1 hash:
b27ca2a3b2cc43d19d91e33e70d377883bd042e3
Detections:
BlackNetRAT win_blacknet_rat_w0 HKTL_NET_GUID_BlackNET SUSP_Modified_SystemExeFileName_in_File INDICATOR_SUSPICIOUS_EXE_RegKeyComb_DisableWinDefender CN_disclosed_20180208_c INDICATOR_SUSPICIOUS_DisableWinDefender MALWARE_Win_BlackNET MAL_Winnti_Sample_May18_1
SH256 hash:
19458ce7d971eb3d25e2725c4430d76a633d9548c0d3ee2f277e98101fe479e6
MD5 hash:
c57d8379c81f0d515ea599c4ab15e6fe
SHA1 hash:
41c2fe587d146ab28acd87bf39d9ab49b30b7686
SH256 hash:
90559222538e34da94ead6ee8cdda99d7ffb6c184dd4096850bd17279637de5b
MD5 hash:
c120efaf98a377d7cc898de1602f573e
SHA1 hash:
14b459217f499b19abc672e3684dd7e2e7897b7f
Detections:
Typical_Malware_String_Transforms
SH256 hash:
14490c9c139e9bc984781f8143a571e1f1f140c69a7cd12c34fc0bf20abb0889
MD5 hash:
baa73a9b35bf02d8c56a1286bcd2d714
SHA1 hash:
a179259548f9e81b65126130342f5b076c8b8a77
Detections:
INDICATOR_EXE_Packed_SmartAssembly
Malware family:
BlackWorm
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_EXE_Packed_SmartAssembly
Author:ditekSHen
Description:Detects executables packed with SmartAssembly
Rule name:NET
Author:malware-lu
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_imphash
Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

BlackNET

Executable exe 14490c9c139e9bc984781f8143a571e1f1f140c69a7cd12c34fc0bf20abb0889

(this sample)

  
Delivery method
Distributed via web download

Comments