Threat name:
Raccoon RedLine SmokeLoader Tofsee Xmrig
Alert
Classification:
troj.spyw.evad.mine
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
Benign windows process drops PE files
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Contains functionality to inject code into remote processes
Contains functionality to inject threads in other processes
Contains functionality to steal Internet Explorer form passwords
Creates a thread in another existing process (thread injection)
Creates files in alternative data streams (ADS)
Deletes itself after installation
Detected Stratum mining protocol
Detected unpacking (changes PE section rights)
Drops executables to the windows directory (C:\Windows) and starts them
Found strings related to Crypto-Mining
Hides that the sample has been downloaded from the Internet (zone.identifier)
Hides threads from debuggers
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
May check the online IP address of the machine
Modifies the windows firewall
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
PE file has nameless sections
Performs DNS queries to domains with low reputation
Query firmware table information (likely to detect VMs)
Sigma detected: Copying Sensitive Files with Credential Data
Sigma detected: Suspect Svchost Activity
Sigma detected: Suspicious Svchost Process
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to resolve many domain names, but no domain seems valid
Uses known network protocols on non-standard ports
Uses netsh to modify the Windows network and firewall settings
Writes to foreign memory regions
Yara detected Raccoon Stealer
Yara detected RedLine Stealer
Yara detected SmokeLoader
Yara detected Xmrig cryptocurrency miner
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
473390
Sample:
OCrlOxN8uU.exe
Startdate:
29/08/2021
Architecture:
WINDOWS
Score:
100
92
www.google.com
2->92
94
zoa.thelogonow.com
2->94
96
52 other IPs or domains
2->96
126
Snort IDS alert for
network traffic (e.g.
based on Emerging Threat
rules)
2->126
128
Sigma detected: Xmrig
2->128
130
Multi AV Scanner detection
for domain / URL
2->130
136
26 other signatures
2->136
11
OCrlOxN8uU.exe
2->11
started
14
nzgaflyg.exe
2->14
started
16
wwtwwbr
2->16
started
18
5 other processes
2->18
signatures3
132
System process connects
to network (likely due
to code injection or
exploit)
92->132
134
Tries to resolve many
domain names, but no
domain seems valid
94->134
process4
signatures5
182
Detected unpacking (changes
PE section rights)
11->182
184
Contains functionality
to inject code into
remote processes
11->184
186
Injects a PE file into
a foreign processes
11->186
20
OCrlOxN8uU.exe
11->20
started
188
Writes to foreign memory
regions
14->188
190
Allocates memory in
foreign processes
14->190
23
svchost.exe
14->23
started
192
Machine Learning detection
for dropped file
16->192
27
wwtwwbr
16->27
started
29
WerFault.exe
18->29
started
process6
dnsIp7
138
Checks for kernel code
integrity (NtQuerySystemInformation(CodeIntegrityInformation))
20->138
140
Maps a DLL or memory
area into another process
20->140
142
Checks if the current
machine is a virtual
machine (disk enumeration)
20->142
31
explorer.exe
21
20->31
injected
98
www.google.com
23->98
100
mx.lycos.de.cust.b.hostedemail.com
23->100
102
33 other IPs or domains
23->102
90
C:\Windows\SysWOW64\...\systemprofile:.repos, data
23->90
dropped
144
System process connects
to network (likely due
to code injection or
exploit)
23->144
146
Creates files in alternative
data streams (ADS)
23->146
148
Performs DNS queries
to domains with low
reputation
23->148
150
Injects a PE file into
a foreign processes
23->150
152
Creates a thread in
another existing process
(thread injection)
27->152
file8
154
Tries to resolve many
domain names, but no
domain seems valid
98->154
signatures9
process10
dnsIp11
110
readinglistforaugust7.xyz
31->110
112
readinglistforaugust6.xyz
31->112
114
11 other IPs or domains
31->114
74
C:\Users\user\AppData\Roaming\wwtwwbr, PE32
31->74
dropped
76
C:\Users\user\AppData\Local\Temp06C.exe, PE32
31->76
dropped
78
C:\Users\user\AppData\Local\Temp\DA31.exe, PE32
31->78
dropped
80
8 other files (7 malicious)
31->80
dropped
116
System process connects
to network (likely due
to code injection or
exploit)
31->116
118
Benign windows process
drops PE files
31->118
120
Performs DNS queries
to domains with low
reputation
31->120
124
2 other signatures
31->124
36
C1FB.exe
31->36
started
39
E06C.exe
2
31->39
started
42
A4DD.exe
31->42
started
44
5 other processes
31->44
file12
122
Tries to resolve many
domain names, but no
domain seems valid
112->122
signatures13
process14
dnsIp15
156
Multi AV Scanner detection
for dropped file
36->156
158
Detected unpacking (changes
PE section rights)
36->158
160
Query firmware table
information (likely
to detect VMs)
36->160
162
Tries to detect sandboxes
and other dynamic analysis
tools (window names)
36->162
47
conhost.exe
36->47
started
84
C:\Users\user\AppData\Local\...\nzgaflyg.exe, PE32
39->84
dropped
164
Machine Learning detection
for dropped file
39->164
166
Uses netsh to modify
the Windows network
and firewall settings
39->166
168
Modifies the windows
firewall
39->168
49
cmd.exe
1
39->49
started
52
cmd.exe
2
39->52
started
54
sc.exe
39->54
started
60
3 other processes
39->60
170
Hides threads from debuggers
42->170
172
Tries to detect sandboxes
/ dynamic malware analysis
system (registry check)
42->172
56
conhost.exe
42->56
started
104
geoiptool.com
158.69.65.151, 443, 49745, 49748
OVHFR
Canada
44->104
106
telete.in
195.201.225.248
HETZNER-ASDE
Germany
44->106
108
4 other IPs or domains
44->108
86
C:\Users\user\AppData\Roaming\...\smss.exe, PE32
44->86
dropped
88
C:\Users\user\AppData\LocalLow\sqlite3.dll, PE32
44->88
dropped
174
May check the online
IP address of the machine
44->174
176
Contains functionality
to inject threads in
other processes
44->176
178
Contains functionality
to steal Internet Explorer
form passwords
44->178
180
5 other signatures
44->180
58
WerFault.exe
20
9
44->58
started
file16
signatures17
process18
file19
82
C:\Windows\SysWOW64\...\nzgaflyg.exe (copy), PE32
49->82
dropped
62
conhost.exe
49->62
started
64
conhost.exe
52->64
started
66
conhost.exe
54->66
started
68
conhost.exe
60->68
started
70
conhost.exe
60->70
started
72
conhost.exe
60->72
started
process20
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.