Threat name:
Amadey Raccoon RedLine SmokeLoader
Alert
Classification:
troj.spyw.evad
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
Antivirus detection for URL or domain
Benign windows process drops PE files
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Connects to many ports of the same IP (likely port scanning)
Contain functionality to detect virtual machines
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Contains functionality to infect the boot sector
Contains functionality to inject code into remote processes
Contains functionality to steal Internet Explorer form passwords
Creates a thread in another existing process (thread injection)
Deletes itself after installation
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Found many strings related to Crypto-Wallets (likely being stolen)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Hides threads from debuggers
Injects a PE file into a foreign processes
Machine Learning detection for sample
Maps a DLL or memory area into another process
May check the online IP address of the machine
Multi AV Scanner detection for domain / URL
PE file has nameless sections
Performs DNS queries to domains with low reputation
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Sigma detected: Suspicius Add Task From User AppData Temp
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to evade analysis by execution special instruction which cause usermode exception
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected Amadeys stealer DLL
Yara detected Raccoon Stealer
Yara detected RedLine Stealer
Yara detected SmokeLoader
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
535248
Sample:
1JDfNLQU3S.exe
Startdate:
07/12/2021
Architecture:
WINDOWS
Score:
100
87
mvcc.xyz
2->87
115
Snort IDS alert for
network traffic (e.g.
based on Emerging Threat
rules)
2->115
117
Multi AV Scanner detection
for domain / URL
2->117
119
Antivirus detection
for URL or domain
2->119
121
15 other signatures
2->121
12
1JDfNLQU3S.exe
2->12
started
14
iuihtbh
2->14
started
signatures3
process4
signatures5
17
1JDfNLQU3S.exe
12->17
started
167
Contains functionality
to inject code into
remote processes
14->167
169
Injects a PE file into
a foreign processes
14->169
20
iuihtbh
14->20
started
process6
signatures7
107
Checks for kernel code
integrity (NtQuerySystemInformation(CodeIntegrityInformation))
17->107
109
Maps a DLL or memory
area into another process
17->109
111
Checks if the current
machine is a virtual
machine (disk enumeration)
17->111
22
explorer.exe
12
17->22
injected
113
Creates a thread in
another existing process
(thread injection)
20->113
process8
dnsIp9
89
185.233.81.115, 443, 49793
SUPERSERVERSDATACENTERRU
Russian Federation
22->89
91
185.186.142.166, 49787, 80
ASKONTELRU
Russian Federation
22->91
93
8 other IPs or domains
22->93
69
C:\Users\user\AppData\Roaming\iuihtbh, PE32
22->69
dropped
71
C:\Users\user\AppData\Local\Temp334.exe, PE32
22->71
dropped
73
C:\Users\user\AppData\Local\Temp\B7ED.exe, PE32
22->73
dropped
75
7 other malicious files
22->75
dropped
137
System process connects
to network (likely due
to code injection or
exploit)
22->137
139
Benign windows process
drops PE files
22->139
141
Deletes itself after
installation
22->141
143
Hides that the sample
has been downloaded
from the Internet (zone.identifier)
22->143
27
B7ED.exe
4
22->27
started
31
55C6.exe
76
22->31
started
34
208.exe
22->34
started
36
5 other processes
22->36
file10
signatures11
process12
dnsIp13
95
45.9.20.149, 42871, 49806
DEDIPATH-LLCUS
Russian Federation
27->95
145
Detected unpacking (changes
PE section rights)
27->145
147
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
27->147
149
Query firmware table
information (likely
to detect VMs)
27->149
165
5 other signatures
27->165
97
91.219.236.97, 49805, 80
SERVERASTRA-ASHU
Hungary
31->97
99
91.219.236.27, 49804, 80
SERVERASTRA-ASHU
Hungary
31->99
77
C:\Users\user\AppData\LocalLow\sqlite3.dll, PE32
31->77
dropped
79
C:\Users\user\AppData\...\vcruntime140.dll, PE32
31->79
dropped
81
C:\Users\user\AppData\...\ucrtbase.dll, PE32
31->81
dropped
85
56 other files (none is malicious)
31->85
dropped
151
Detected unpacking (overwrites
its own PE header)
31->151
153
Tries to steal Mail
credentials (via file
/ registry access)
31->153
155
Contains functionality
to steal Internet Explorer
form passwords
31->155
157
Tries to harvest and
steal browser information
(history, passwords,
etc)
31->157
83
C:\Users\user\AppData\Local\...\tkools.exe, PE32
34->83
dropped
38
tkools.exe
34->38
started
41
cmd.exe
34->41
started
43
cmd.exe
34->43
started
47
2 other processes
34->47
101
t.me
149.154.167.99, 443, 49844
TELEGRAMRU
United Kingdom
36->101
103
api.ipify.org.herokudns.com
3.220.57.224, 443, 49846
AMAZON-AESUS
United States
36->103
105
api.ipify.org
36->105
159
May check the online
IP address of the machine
36->159
161
Tries to detect sandboxes
and other dynamic analysis
tools (window names)
36->161
163
Tries to evade analysis
by execution special
instruction which cause
usermode exception
36->163
45
4589.exe
36->45
started
file14
signatures15
process16
signatures17
123
Detected unpacking (changes
PE section rights)
38->123
125
Detected unpacking (overwrites
its own PE header)
38->125
127
Uses schtasks.exe or
at.exe to add and modify
task schedules
38->127
49
cmd.exe
38->49
started
51
conhost.exe
41->51
started
53
cmd.exe
41->53
started
55
cacls.exe
41->55
started
57
conhost.exe
43->57
started
63
2 other processes
43->63
129
Checks for kernel code
integrity (NtQuerySystemInformation(CodeIntegrityInformation))
45->129
131
Maps a DLL or memory
area into another process
45->131
133
Checks if the current
machine is a virtual
machine (disk enumeration)
45->133
135
Creates a thread in
another existing process
(thread injection)
45->135
59
conhost.exe
47->59
started
61
cacls.exe
47->61
started
65
2 other processes
47->65
process18
process19
67
conhost.exe
49->67
started
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.