Threat name:
RedLine SmokeLoader Tofsee Vidar
Alert
Classification:
troj.spyw.evad
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code references suspicious native API functions
Antivirus detection for dropped file
Antivirus detection for URL or domain
Benign windows process drops PE files
Changes security center settings (notifications, updates, antivirus, firewall)
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Contains functionality to detect sleep reduction / modifications
Contains functionality to inject code into remote processes
Creates a thread in another existing process (thread injection)
Deletes itself after installation
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Found evasive API chain (may stop execution after checking computer name)
Found evasive API chain (may stop execution after checking locale)
Found evasive API chain (may stop execution after checking mutex)
Found evasive API chain (may stop execution after reading information in the PEB, e.g. number of processors)
Found many strings related to Crypto-Wallets (likely being stolen)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Maps a DLL or memory area into another process
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: Copying Sensitive Files with Credential Data
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Yara detected RedLine Stealer
Yara detected SmokeLoader
Yara detected Vidar stealer
behaviorgraph
top1
signatures2
2
Behavior Graph
ID:
553704
Sample:
3R3xp7MAfh.exe
Startdate:
15/01/2022
Architecture:
WINDOWS
Score:
100
81
Snort IDS alert for
network traffic (e.g.
based on Emerging Threat
rules)
2->81
83
Multi AV Scanner detection
for domain / URL
2->83
85
Antivirus detection
for URL or domain
2->85
87
14 other signatures
2->87
10
3R3xp7MAfh.exe
2->10
started
13
rwjbwwg
2->13
started
15
rwjbwwg
2->15
started
17
11 other processes
2->17
process3
signatures4
115
Contains functionality
to inject code into
remote processes
10->115
117
Injects a PE file into
a foreign processes
10->117
19
3R3xp7MAfh.exe
10->19
started
119
Multi AV Scanner detection
for dropped file
13->119
121
Machine Learning detection
for dropped file
13->121
22
rwjbwwg
13->22
started
24
rwjbwwg
15->24
started
123
Changes security center
settings (notifications,
updates, antivirus,
firewall)
17->123
26
WerFault.exe
17->26
started
28
MpCmdRun.exe
17->28
started
process5
signatures6
89
Checks for kernel code
integrity (NtQuerySystemInformation(CodeIntegrityInformation))
19->89
91
Maps a DLL or memory
area into another process
19->91
93
Checks if the current
machine is a virtual
machine (disk enumeration)
19->93
30
explorer.exe
10
19->30
injected
95
Creates a thread in
another existing process
(thread injection)
22->95
process7
dnsIp8
67
185.233.81.115, 443, 49738
SUPERSERVERSDATACENTERRU
Russian Federation
30->67
69
188.166.28.199, 80
DIGITALOCEAN-ASNUS
Netherlands
30->69
71
9 other IPs or domains
30->71
57
C:\Users\user\AppData\Roaming\rwjbwwg, PE32
30->57
dropped
59
C:\Users\user\AppData\Local\Temp\F924.exe, PE32+
30->59
dropped
61
C:\Users\user\AppData\Local\Temp\B7A4.exe, PE32
30->61
dropped
63
8 other malicious files
30->63
dropped
73
System process connects
to network (likely due
to code injection or
exploit)
30->73
75
Benign windows process
drops PE files
30->75
77
Deletes itself after
installation
30->77
79
Hides that the sample
has been downloaded
from the Internet (zone.identifier)
30->79
35
B7A4.exe
3
30->35
started
38
2E3A.exe
30->38
started
40
AEAB.exe
2
30->40
started
43
1FC2.exe
30->43
started
file9
signatures10
process11
file12
97
Antivirus detection
for dropped file
35->97
99
Multi AV Scanner detection
for dropped file
35->99
101
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
35->101
111
2 other signatures
35->111
45
B7A4.exe
35->45
started
103
Detected unpacking (changes
PE section rights)
38->103
105
Detected unpacking (overwrites
its own PE header)
38->105
107
Found evasive API chain
(may stop execution
after checking mutex)
38->107
113
4 other signatures
38->113
55
C:\Users\user\AppData\Local\...\fmhydiub.exe, PE32
40->55
dropped
109
Machine Learning detection
for dropped file
40->109
49
cmd.exe
40->49
started
51
WerFault.exe
3
10
43->51
started
signatures13
process14
dnsIp15
65
92.255.111.23, 38134, 49849
CONTINENTAL_GROUP-ASRU
Russian Federation
45->65
125
Tries to harvest and
steal browser information
(history, passwords,
etc)
45->125
127
Tries to steal Crypto
Currency Wallets
45->127
53
conhost.exe
49->53
started
signatures16
process17
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.