Threat name:
RedLine SmokeLoader Tofsee
Alert
Classification:
troj.spyw.evad
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains very large array initializations
.NET source code references suspicious native API functions
Allocates memory in foreign processes
Antivirus detection for dropped file
Benign windows process drops PE files
Changes security center settings (notifications, updates, antivirus, firewall)
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Creates a thread in another existing process (thread injection)
Deletes itself after installation
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Drops executables to the windows directory (C:\Windows) and starts them
Found many strings related to Crypto-Wallets (likely being stolen)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Hides threads from debuggers
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Maps a DLL or memory area into another process
Modifies the windows firewall
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Sigma detected: Copying Sensitive Files with Credential Data
Sigma detected: Suspect Svchost Activity
Sigma detected: Suspicious Svchost Process
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Uses known network protocols on non-standard ports
Uses netsh to modify the Windows network and firewall settings
Writes to foreign memory regions
Yara detected RedLine Stealer
Yara detected SmokeLoader
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
487744
Sample:
K6skRE2yZL.exe
Startdate:
22/09/2021
Architecture:
WINDOWS
Score:
100
90
telete.in
2->90
92
microsoft-com.mail.protection.outlook.com
2->92
94
2 other IPs or domains
2->94
142
Snort IDS alert for
network traffic (e.g.
based on Emerging Threat
rules)
2->142
144
Multi AV Scanner detection
for submitted file
2->144
146
Yara detected SmokeLoader
2->146
148
15 other signatures
2->148
11
K6skRE2yZL.exe
2->11
started
14
vtiuokvl.exe
2->14
started
16
issucsu
2->16
started
18
12 other processes
2->18
signatures3
process4
dnsIp5
160
Detected unpacking (changes
PE section rights)
11->160
21
K6skRE2yZL.exe
11->21
started
162
Detected unpacking (overwrites
its own PE header)
14->162
164
Writes to foreign memory
regions
14->164
166
Allocates memory in
foreign processes
14->166
168
Injects a PE file into
a foreign processes
14->168
24
svchost.exe
14->24
started
170
Machine Learning detection
for dropped file
16->170
27
issucsu
16->27
started
96
127.0.0.1
unknown
unknown
18->96
98
192.168.2.1
unknown
unknown
18->98
172
Changes security center
settings (notifications,
updates, antivirus,
firewall)
18->172
signatures6
process7
dnsIp8
150
Checks for kernel code
integrity (NtQuerySystemInformation(CodeIntegrityInformation))
21->150
152
Maps a DLL or memory
area into another process
21->152
154
Checks if the current
machine is a virtual
machine (disk enumeration)
21->154
29
explorer.exe
9
21->29
injected
102
microsoft-com.mail.protection.outlook.com
52.101.24.0, 25, 49851, 49875
MICROSOFT-CORP-MSN-AS-BLOCKUS
United States
24->102
104
defeatwax.ru
193.56.146.188, 443, 49856, 49879
LVLT-10753US
unknown
24->104
156
System process connects
to network (likely due
to code injection or
exploit)
24->156
158
Creates a thread in
another existing process
(thread injection)
27->158
signatures9
process10
dnsIp11
106
216.128.137.31, 80
AS-CHOOPAUS
United States
29->106
108
kevonahira2.top
194.87.234.157, 49740, 49741, 49742
MTW-ASRU
Russian Federation
29->108
110
3 other IPs or domains
29->110
82
C:\Users\user\AppData\Roaming\issucsu, PE32
29->82
dropped
84
C:\Users\user\AppData\Local\Temp5F6.exe, PE32
29->84
dropped
86
C:\Users\user\AppData\Local\Temp\D9DF.exe, PE32
29->86
dropped
88
2 other malicious files
29->88
dropped
178
System process connects
to network (likely due
to code injection or
exploit)
29->178
180
Benign windows process
drops PE files
29->180
182
Deletes itself after
installation
29->182
184
Hides that the sample
has been downloaded
from the Internet (zone.identifier)
29->184
34
E5F6.exe
2
29->34
started
37
BB9B.exe
29->37
started
40
22F1.exe
29->40
started
43
3 other processes
29->43
file12
signatures13
process14
dnsIp15
116
Antivirus detection
for dropped file
34->116
118
Multi AV Scanner detection
for dropped file
34->118
120
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
34->120
122
Queries sensitive disk
information (via WMI,
Win32_DiskDrive, often
done to detect virtual
machines)
34->122
45
E5F6.exe
15
24
34->45
started
49
conhost.exe
34->49
started
100
188.124.36.242, 25802, 49839
SELECTELRU
Russian Federation
37->100
124
Detected unpacking (changes
PE section rights)
37->124
126
Query firmware table
information (likely
to detect VMs)
37->126
128
Machine Learning detection
for dropped file
37->128
130
Tries to detect sandboxes
/ dynamic malware analysis
system (registry check)
37->130
51
conhost.exe
37->51
started
80
C:\Users\user\AppData\Local\...\vtiuokvl.exe, PE32
40->80
dropped
132
Detected unpacking (overwrites
its own PE header)
40->132
134
Uses netsh to modify
the Windows network
and firewall settings
40->134
136
Modifies the windows
firewall
40->136
53
cmd.exe
40->53
started
56
cmd.exe
40->56
started
58
sc.exe
40->58
started
64
3 other processes
40->64
138
Tries to detect sandboxes
and other dynamic analysis
tools (window names)
43->138
140
2 other signatures
43->140
60
D9DF.exe
43->60
started
62
conhost.exe
43->62
started
file16
signatures17
process18
dnsIp19
112
146.70.35.170, 30905, 49822
TENET-1ZA
United Kingdom
45->112
114
api.ip.sb
45->114
174
Tries to harvest and
steal browser information
(history, passwords,
etc)
45->174
176
Tries to steal Crypto
Currency Wallets
45->176
78
C:\Windows\SysWOW64\...\vtiuokvl.exe (copy), PE32
53->78
dropped
66
conhost.exe
53->66
started
68
conhost.exe
56->68
started
70
conhost.exe
58->70
started
72
conhost.exe
64->72
started
74
conhost.exe
64->74
started
76
conhost.exe
64->76
started
file20
signatures21
process22
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.