Threat name:
Blank Grabber, Cobian RAT, R77 RootKit,
Alert
Classification:
rans.troj.adwa.spyw.expl.evad
.NET source code contains potential unpacker
.NET source code contains process injector
.NET source code references suspicious native API functions
Allocates memory in foreign processes
Antivirus detection for dropped file
C2 URLs / IPs found in malware configuration
Changes the view of files in windows explorer (hidden files and folders)
Connects to many ports of the same IP (likely port scanning)
Contains functionality to log keystrokes (.Net Source)
Creates a thread in another existing process (thread injection)
Creates autostart registry keys with suspicious names
Creates files in the system32 config directory
Document contains an embedded VBA macro with suspicious strings
Document contains an embedded VBA with functions possibly related to ADO stream file operations
Document contains an embedded VBA with functions possibly related to HTTP operations
Document contains an embedded VBA with functions possibly related to WSH operations (process, registry, environment, or keystrokes)
Drops PE files to the document folder of the user
Drops PE files to the startup folder
Drops PE files with benign system names
Found direct / indirect Syscall (likely to bypass EDR)
Found malware configuration
Found stalling execution ending in API Sleep call
Hooks files or directories query functions (used to hide files and directories)
Hooks processes query functions (used to hide processes)
Hooks registry keys query functions (used to hide registry keys)
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Modifies existing user documents (likely ransomware behavior)
Modifies the context of a thread in another process (thread injection)
Modifies the prolog of user mode functions (user mode inline hooks)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Files With System Process Name In Unsuspected Locations
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: Potentially Suspicious Malware Callback Communication
Sigma detected: Schedule system process
Sigma detected: System File Execution Location Anomaly
Suricata IDS alerts for network traffic
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Uses dynamic DNS services
Uses schtasks.exe or at.exe to add and modify task schedules
Uses the Telegram API (likely for C&C communication)
Writes to foreign memory regions
Yara detected Blank Grabber
Yara detected R77 RootKit
Yara detected UAC Bypass using CMSTP
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
1723726
Sample:
Wrotocol.exe
Startdate:
26/06/2025
Architecture:
WINDOWS
Score:
100
153
freedns.afraid.org
2->153
155
api.telegram.org
2->155
157
11 other IPs or domains
2->157
193
Suricata IDS alerts
for network traffic
2->193
195
Found malware configuration
2->195
197
Malicious sample detected
(through community Yara
rule)
2->197
203
31 other signatures
2->203
15
Wrotocol.exe
13
2->15
started
18
._cache_Host Process for Windows.exe
2->18
started
22
EXCEL.EXE
186
51
2->22
started
signatures3
199
Uses dynamic DNS services
153->199
201
Uses the Telegram API
(likely for C&C
communication)
155->201
process4
dnsIp5
133
C:\Users\user\AppData\...\unicodedata.pyd, PE32+
15->133
dropped
135
C:\Users\user\AppData\Local\...\select.pyd, PE32+
15->135
dropped
137
C:\Users\user\AppData\Local\...\python311.dll, PE32+
15->137
dropped
141
7 other malicious files
15->141
dropped
24
Wrotocol.exe
4
15->24
started
27
conhost.exe
15->27
started
159
147.185.221.28, 49180, 49735
SALSGIVERUS
United States
18->159
139
{6Y7BDC40-879330-6E7IKJ-6E7IKJ40S1}.exe, PE32
18->139
dropped
205
Changes the view of
files in windows explorer
(hidden files and folders)
18->205
207
Creates autostart registry
keys with suspicious
names
18->207
209
Writes to foreign memory
regions
18->209
211
4 other signatures
18->211
29
schtasks.exe
18->29
started
31
schtasks.exe
18->31
started
161
s-part-0012.t-0009.t-msedge.net
13.107.246.40, 443, 49759, 49760
MICROSOFT-CORP-MSN-AS-BLOCKUS
United States
22->161
file6
signatures7
process8
file9
117
C:\Users\user\AppData\Local\Temp\...\tool.exe, PE32
24->117
dropped
33
tool.exe
1
5
24->33
started
36
conhost.exe
29->36
started
38
conhost.exe
31->38
started
process10
file11
107
C:\Users\user\AppData\...\._cache_tool.exe, PE32
33->107
dropped
109
C:\ProgramData\Synaptics\Synaptics.exe, PE32
33->109
dropped
111
C:\ProgramData\Synaptics\RCXDEDA.tmp, PE32
33->111
dropped
40
._cache_tool.exe
4
33->40
started
43
Synaptics.exe
32
33->43
started
process12
dnsIp13
119
C:\Users\user\AppData\Local\...\WmiPrvSE.exe, PE32+
40->119
dropped
121
C:\Users\...\Host Process for Windows.exe, PE32
40->121
dropped
47
WmiPrvSE.exe
40->47
started
50
Host Process for Windows.exe
40->50
started
167
drive.usercontent.google.com
142.250.176.193, 443, 49725, 49726
GOOGLEUS
United States
43->167
169
docs.google.com
142.250.81.238, 443, 49723, 49724
GOOGLEUS
United States
43->169
171
freedns.afraid.org
69.42.215.252, 49728, 80
AWKNET-LLCUS
United States
43->171
123
C:\Users\user\Documents\JDDHMPCDUJ\~$cache1, PE32
43->123
dropped
231
Antivirus detection
for dropped file
43->231
233
Drops PE files to the
document folder of the
user
43->233
52
WerFault.exe
43->52
started
file14
signatures15
process16
file17
143
C:\Users\user\AppData\...\unicodedata.pyd, PE32+
47->143
dropped
145
C:\Users\user\AppData\Local\...\select.pyd, PE32+
47->145
dropped
147
C:\Users\user\AppData\Local\...\python311.dll, PE32+
47->147
dropped
151
7 other malicious files
47->151
dropped
54
WmiPrvSE.exe
47->54
started
57
conhost.exe
47->57
started
149
C:\...\._cache_Host Process for Windows.exe, PE32
50->149
dropped
59
._cache_Host Process for Windows.exe
50->59
started
process18
file19
113
C:\Users\user\AppData\Local\Temp\...\tool.exe, PE32+
54->113
dropped
62
tool.exe
54->62
started
115
C:\Users\user\AppData\Roaming\Svchost.exe, PE32
59->115
dropped
213
Writes to foreign memory
regions
59->213
215
Allocates memory in
foreign processes
59->215
217
Modifies the context
of a thread in another
process (thread injection)
59->217
219
2 other signatures
59->219
65
dllhost.exe
59->65
started
68
Svchost.exe
59->68
started
70
schtasks.exe
59->70
started
72
schtasks.exe
59->72
started
signatures20
process21
file22
125
C:\Users\user\AppData\...\unicodedata.pyd, PE32+
62->125
dropped
127
C:\Users\user\AppData\Local\...\sqlite3.dll, PE32+
62->127
dropped
129
C:\Users\user\AppData\Local\...\select.pyd, PE32+
62->129
dropped
131
16 other malicious files
62->131
dropped
74
tool.exe
62->74
started
181
Found stalling execution
ending in API Sleep
call
65->181
183
Writes to foreign memory
regions
65->183
185
Creates a thread in
another existing process
(thread injection)
65->185
78
winlogon.exe
65->78
injected
80
lsass.exe
65->80
injected
82
svchost.exe
65->82
injected
187
Allocates memory in
foreign processes
68->187
189
Modifies the context
of a thread in another
process (thread injection)
68->189
191
Injects a PE file into
a foreign processes
68->191
84
schtasks.exe
68->84
started
86
schtasks.exe
68->86
started
88
conhost.exe
70->88
started
90
conhost.exe
72->90
started
signatures23
process24
dnsIp25
163
ip-api.com
208.95.112.1, 49755, 80
TUT-ASUS
United States
74->163
165
api.telegram.org
149.154.167.220, 443, 49756
TELEGRAMRU
United Kingdom
74->165
221
Tries to harvest and
steal browser information
(history, passwords,
etc)
74->221
223
Tries to steal Crypto
Currency Wallets
74->223
225
Modifies existing user
documents (likely ransomware
behavior)
74->225
92
Synaptics.exe
74->92
started
94
Conhost.exe
74->94
started
96
dllhost.exe
78->96
started
99
dllhost.exe
78->99
started
227
Creates files in the
system32 config directory
80->227
229
Writes to foreign memory
regions
80->229
101
conhost.exe
84->101
started
103
conhost.exe
86->103
started
signatures26
process27
signatures28
173
Injects code into the
Windows Explorer (explorer.exe)
96->173
175
Writes to foreign memory
regions
96->175
177
Creates a thread in
another existing process
(thread injection)
96->177
179
Injects a PE file into
a foreign processes
99->179
105
dwm.exe
99->105
injected
process29
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.