Threat name:
RedLine, Vidar, Xmrig
Alert
Classification:
troj.spyw.evad.mine
Adds a directory exclusion to Windows Defender
Allocates memory in foreign processes
Antivirus detection for dropped file
C2 URLs / IPs found in malware configuration
Connects to a pastebin service (likely for C&C)
Creates files in the system32 config directory
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
DLL side loading technique detected
Drops executables to the windows directory (C:\Windows) and starts them
Encrypted powershell cmdline option found
Found hidden mapped module (file has been removed from disk)
Found many strings related to Crypto-Wallets (likely being stolen)
Hooks files or directories query functions (used to hide files and directories)
Hooks processes query functions (used to hide processes)
Hooks registry keys query functions (used to hide registry keys)
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies power options to not sleep / hibernate
Modifies the context of a thread in another process (thread injection)
Modifies the prolog of user mode functions (user mode inline hooks)
Modifies the windows firewall
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Obfuscated command line found
PE file contains section with special chars
PE file has nameless sections
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample is not signed and drops a device driver
Sample uses process hollowing technique
Sigma detected: Schedule system process
Sigma detected: Stop multiple services
Snort IDS alert for network traffic
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Crypto Currency Wallets
Uses cmd line tools excessively to alter registry or file data
Uses netsh to modify the Windows network and firewall settings
Uses powercfg.exe to modify the power settings
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Yara detected RedLine Stealer
Yara detected Vidar stealer
Yara detected Xmrig cryptocurrency miner
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
729340
Sample:
PjGCTo5SJi.exe
Startdate:
24/10/2022
Architecture:
WINDOWS
Score:
100
107
pastebin.com
2->107
153
Snort IDS alert for
network traffic
2->153
155
Malicious sample detected
(through community Yara
rule)
2->155
157
Antivirus detection
for dropped file
2->157
159
18 other signatures
2->159
11
PjGCTo5SJi.exe
1
2->11
started
14
powershell.exe
2->14
started
16
powershell.exe
2->16
started
18
2 other processes
2->18
signatures3
process4
signatures5
169
Writes to foreign memory
regions
11->169
171
Injects a PE file into
a foreign processes
11->171
20
vbc.exe
15
10
11->20
started
25
conhost.exe
11->25
started
173
Creates files in the
system32 config directory
14->173
175
Modifies the context
of a thread in another
process (thread injection)
14->175
177
Sample uses process
hollowing technique
14->177
27
conhost.exe
14->27
started
29
conhost.exe
16->29
started
process6
dnsIp7
109
79.137.192.7, 39946, 49683
PSKSET-ASRU
Russian Federation
20->109
111
adigitalshop.com
151.106.122.215, 443, 49684
PLUSSERVER-ASN1DE
Germany
20->111
113
3 other IPs or domains
20->113
89
C:\Users\user\AppData\Local\...\Launcher.exe, PE32
20->89
dropped
91
C:\Users\user\AppData\Local\...\test.exe, PE32
20->91
dropped
93
C:\Users\user\AppData\Local\...\chrome.exe, MS-DOS
20->93
dropped
95
C:\Users\user\AppData\Local\...\brave.exe, PE32+
20->95
dropped
161
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
20->161
163
Queries sensitive disk
information (via WMI,
Win32_DiskDrive, often
done to detect virtual
machines)
20->163
165
Tries to harvest and
steal browser information
(history, passwords,
etc)
20->165
167
Tries to steal Crypto
Currency Wallets
20->167
31
chrome.exe
20->31
started
35
brave.exe
2
20->35
started
37
test.exe
1
20->37
started
39
Launcher.exe
20->39
started
file8
signatures9
process10
dnsIp11
97
C:\WindowsbehaviorgraphoogleUpdate.exe, PE32
31->97
dropped
129
Multi AV Scanner detection
for dropped file
31->129
131
Detected unpacking (changes
PE section rights)
31->131
133
Machine Learning detection
for dropped file
31->133
151
4 other signatures
31->151
42
GoogleUpdate.exe
31->42
started
55
3 other processes
31->55
99
C:\Users\user\AppData\Local\Temp\63B3.tmp, PE32+
35->99
dropped
101
C:\Program Filesbehaviorgraphoogle\Chrome\updater.exe, PE32+
35->101
dropped
135
Writes to foreign memory
regions
35->135
137
Modifies the context
of a thread in another
process (thread injection)
35->137
139
Found hidden mapped
module (file has been
removed from disk)
35->139
141
Maps a DLL or memory
area into another process
35->141
46
cmd.exe
35->46
started
48
cmd.exe
35->48
started
57
4 other processes
35->57
143
Allocates memory in
foreign processes
37->143
145
Injects a PE file into
a foreign processes
37->145
50
vbc.exe
37->50
started
59
3 other processes
37->59
115
140.82.121.4, 443, 49775, 49776
GITHUBUS
United States
39->115
117
pastebin.com
172.67.34.170, 443, 49753
CLOUDFLARENETUS
United States
39->117
119
2 other IPs or domains
39->119
103
C:\ProgramData\Dllhost\dllhost.exe, PE32
39->103
dropped
105
C:\ProgramData\Dllhost\WinRing0x64.sys, PE32+
39->105
dropped
147
Antivirus detection
for dropped file
39->147
149
Sample is not signed
and drops a device driver
39->149
53
cmd.exe
39->53
started
61
7 other processes
39->61
file12
signatures13
process14
dnsIp15
121
141.95.93.189, 443, 49691, 49693
DFNVereinzurFoerderungeinesDeutschenForschungsnetzese
Germany
42->121
123
api.peer2profit.com
172.66.40.196, 443, 49689, 49690
CLOUDFLARENETUS
United States
42->123
179
Detected unpacking (changes
PE section rights)
42->179
181
Detected unpacking (overwrites
its own PE header)
42->181
183
Uses netsh to modify
the Windows network
and firewall settings
42->183
185
Modifies the windows
firewall
42->185
63
netsh.exe
42->63
started
67
2 other processes
42->67
187
Uses cmd line tools
excessively to alter
registry or file data
46->187
189
Uses powercfg.exe to
modify the power settings
46->189
191
Modifies power options
to not sleep / hibernate
46->191
69
11 other processes
46->69
71
5 other processes
48->71
125
t.me
149.154.167.99, 443, 49692
TELEGRAMRU
United Kingdom
50->125
127
78.47.204.168, 49699, 80
HETZNER-ASDE
Germany
50->127
87
C:\ProgramData\sqlite3.dll, PE32
50->87
dropped
193
Tries to harvest and
steal Putty / WinSCP
information (sessions,
passwords, etc)
50->193
195
Tries to harvest and
steal browser information
(history, passwords,
etc)
50->195
197
DLL side loading technique
detected
50->197
199
Tries to steal Crypto
Currency Wallets
50->199
65
cmd.exe
50->65
started
201
Encrypted powershell
cmdline option found
53->201
73
2 other processes
53->73
75
6 other processes
55->75
77
3 other processes
57->77
79
9 other processes
61->79
file16
signatures17
process18
process19
81
conhost.exe
63->81
started
83
conhost.exe
67->83
started
85
conhost.exe
67->85
started
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.