MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 256a30be8a3081bcb330fe591086a4aed7d48b44e73d2a9692f94bcccd935b33. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Adware.Neoreklami


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: 256a30be8a3081bcb330fe591086a4aed7d48b44e73d2a9692f94bcccd935b33
SHA3-384 hash: 0efc0ed4ab1786f563721faaa1ab7216457a2ca1cec3a27de5e14ec2a72532457c2ea434465fdb53031f0eb63eafb90f
SHA1 hash: ce22f9a0e1911f63b73c163ed51df25c931ce552
MD5 hash: 7019e12889a7356eeccc4b8d8b485f21
humanhash: fish-red-oxygen-ten
File name:file
Download: download sample
Signature Adware.Neoreklami
File size:7'642'086 bytes
First seen:2024-09-24 16:26:40 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 3786a4cf8bfee8b4821db03449141df4 (2'475 x Adware.Neoreklami, 2 x RedLineStealer, 2 x Adware.MultiPlug)
ssdeep 196608:91OzVTTBjGzzK3g1vbe9MGy1IdwkavpzJobjKbN9:3O9T5Iz5yMG8IdwkszJoXKN9
TLSH T1BC763353F2E18CB6E1524C35CA24AF8D1174E71C0F082073B796AE4E3EBE497653E999
TrID 37.8% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
20.0% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
12.7% (.EXE) Win64 Executable (generic) (10523/12/4)
7.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
Magika pebin
File icon (PE):PE icon
dhash icon 848c5454baf47474 (2'466 x Adware.Neoreklami, 102 x RedLineStealer, 65 x N-able)
Reporter Bitsight
Tags:Adware.Neoreklami exe


Avatar
Bitsight
url: http://194.58.114.223/d/385121

Intelligence


File Origin
# of uploads :
1
# of downloads :
429
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
file
Verdict:
Malicious activity
Analysis date:
2024-09-24 16:31:38 UTC
Tags:
xor-url generic adware neoreklami

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
92.5%
Tags:
Encryption Execution Generic Network Stealth Trojan Autorun Gumen
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Сreating synchronization primitives
Running batch commands
Creating a process with a hidden window
Launching a process
Launching cmd.exe command interpreter
Creating a file
Using the Windows Management Instrumentation requests
Replacing files
Launching a service
Sending a UDP request
Blocking the Windows Defender launch
Enabling autorun by creating a file
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
epmicrosoft_visual_cc installer lolbin microsoft_visual_cc overlay packed sfx shell32
Result
Threat name:
Neoreklami
Detection:
malicious
Classification:
adwa.evad
Score:
100 / 100
Signature
AI detected suspicious sample
Antivirus detection for dropped file
Creates files in the recycle bin to hide itself
Machine Learning detection for dropped file
Machine Learning detection for sample
Modifies Group Policy settings
Modifies Windows Defender protection settings
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: Potentially Suspicious PowerShell Child Processes
Sigma detected: Rare Remote Thread Creation By Uncommon Source Image
Sigma detected: Suspicious Scheduled Task Creation Involving Temp Folder
Suspicious powershell command line found
Uses cmd line tools excessively to alter registry or file data
Uses schtasks.exe or at.exe to add and modify task schedules
Very long command line found
Yara detected Neoreklami
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1517062 Sample: file.exe Startdate: 24/09/2024 Architecture: WINDOWS Score: 100 131 www.rapidfilestorage.com 2->131 133 skrptfiles.tracemonitors.com 2->133 135 3 other IPs or domains 2->135 155 Antivirus detection for dropped file 2->155 157 Multi AV Scanner detection for dropped file 2->157 159 Multi AV Scanner detection for submitted file 2->159 161 9 other signatures 2->161 14 file.exe 7 2->14         started        17 Install.exe 2->17         started        signatures3 process4 file5 123 C:\Users\user\AppData\Local\...\config.txt, COM 14->123 dropped 125 C:\Users\user\AppData\Local\...\Install.exe, PE32 14->125 dropped 20 Install.exe 4 14->20         started        127 C:\Windows\Temp\...127ZiYEVm.exe, PE32 17->127 dropped 129 C:\Windows\System32behaviorgraphroupPolicy\gpt.ini, ASCII 17->129 dropped 137 Creates files in the recycle bin to hide itself 17->137 139 Very long command line found 17->139 141 Modifies Windows Defender protection settings 17->141 143 Modifies Group Policy settings 17->143 24 cmd.exe 17->24         started        26 powershell.exe 17->26         started        28 Conhost.exe 17->28         started        signatures6 process7 file8 121 C:\Users\user\AppData\Local\...\Install.exe, PE32 20->121 dropped 163 Multi AV Scanner detection for dropped file 20->163 165 Machine Learning detection for dropped file 20->165 30 Install.exe 1 20->30         started        167 Modifies Windows Defender protection settings 24->167 33 forfiles.exe 24->33         started        35 forfiles.exe 24->35         started        37 forfiles.exe 24->37         started        45 3 other processes 24->45 169 Uses cmd line tools excessively to alter registry or file data 26->169 39 cmd.exe 26->39         started        41 conhost.exe 26->41         started        43 reg.exe 26->43         started        47 8 other processes 26->47 signatures9 process10 signatures11 181 Antivirus detection for dropped file 30->181 183 Multi AV Scanner detection for dropped file 30->183 185 Very long command line found 30->185 191 2 other signatures 30->191 49 cmd.exe 1 30->49         started        52 forfiles.exe 1 30->52         started        54 schtasks.exe 30->54         started        187 Modifies Windows Defender protection settings 33->187 56 cmd.exe 33->56         started        58 cmd.exe 35->58         started        60 cmd.exe 37->60         started        189 Uses cmd line tools excessively to alter registry or file data 39->189 62 reg.exe 39->62         started        64 cmd.exe 45->64         started        66 cmd.exe 45->66         started        process12 signatures13 145 Suspicious powershell command line found 49->145 147 Uses cmd line tools excessively to alter registry or file data 49->147 149 Modifies Windows Defender protection settings 49->149 68 forfiles.exe 1 49->68         started        82 5 other processes 49->82 85 2 other processes 52->85 70 conhost.exe 54->70         started        72 reg.exe 56->72         started        74 reg.exe 58->74         started        76 reg.exe 60->76         started        78 powershell.exe 64->78         started        80 reg.exe 66->80         started        process14 signatures15 87 cmd.exe 1 68->87         started        90 gpupdate.exe 78->90         started        151 Modifies Windows Defender protection settings 82->151 92 cmd.exe 1 82->92         started        94 cmd.exe 1 82->94         started        96 cmd.exe 1 82->96         started        98 cmd.exe 1 82->98         started        153 Suspicious powershell command line found 85->153 100 powershell.exe 7 85->100         started        process16 signatures17 177 Suspicious powershell command line found 87->177 102 powershell.exe 12 87->102         started        105 conhost.exe 90->105         started        179 Uses cmd line tools excessively to alter registry or file data 92->179 107 reg.exe 1 1 92->107         started        109 reg.exe 1 1 94->109         started        111 reg.exe 1 1 96->111         started        113 reg.exe 1 1 98->113         started        115 WMIC.exe 1 100->115         started        process18 signatures19 171 Uses cmd line tools excessively to alter registry or file data 102->171 173 Modifies Windows Defender protection settings 102->173 117 gpupdate.exe 1 102->117         started        175 Suspicious powershell command line found 107->175 process20 process21 119 conhost.exe 117->119         started       
Threat name:
Win32.Trojan.Neoreblamy
Status:
Malicious
First seen:
2024-09-24 15:57:17 UTC
File Type:
PE (Exe)
Extracted files:
13
AV detection:
14 of 38 (36.84%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion discovery evasion execution spyware stealer trojan
Behaviour
Enumerates system info in registry
Modifies data under HKEY_USERS
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Drops file in Windows directory
Drops file in System32 directory
Checks installed software on the system
Drops Chrome extension
Drops desktop.ini file(s)
Checks BIOS information in registry
Checks computer location settings
Executes dropped EXE
Indirect Command Execution
Loads dropped DLL
Reads user/profile data of web browsers
Blocklisted process makes network request
Command and Scripting Interpreter: PowerShell
Modifies Windows Defender Real-time Protection settings
Windows security bypass
Unpacked files
SH256 hash:
497c42c031715aacd7467ac1b20eb89ae0f6fba6b4fb396bba46be6d01dedff5
MD5 hash:
03f292568b92a465ce18acc826c2f599
SHA1 hash:
1780c4b4ff3f4149c4e5d5e3af90389e656d707c
SH256 hash:
256a30be8a3081bcb330fe591086a4aed7d48b44e73d2a9692f94bcccd935b33
MD5 hash:
7019e12889a7356eeccc4b8d8b485f21
SHA1 hash:
ce22f9a0e1911f63b73c163ed51df25c931ce552
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Adware.Neoreklami

Executable exe 256a30be8a3081bcb330fe591086a4aed7d48b44e73d2a9692f94bcccd935b33

(this sample)

  
Dropped by
Privateloader
  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
SHELL_APIManipulates System ShellSHELL32.dll::ShellExecuteExA
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CreateProcessA
KERNEL32.dll::CloseHandle
KERNEL32.dll::CreateThread
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::GetStartupInfoA
KERNEL32.dll::GetCommandLineA
KERNEL32.dll::GetCommandLineW
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateDirectoryA
KERNEL32.dll::CreateDirectoryW
KERNEL32.dll::CreateFileW
KERNEL32.dll::CreateFileA
KERNEL32.dll::DeleteFileA
KERNEL32.dll::DeleteFileW

Comments