MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3d7ba99d7b360819146cd6223b2d668e8b1a661023f5b36932860bc84271eecd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Adware.FileTour


Vendor detections: 9


Intelligence 9 IOCs 2 YARA File information Comments

SHA256 hash: 3d7ba99d7b360819146cd6223b2d668e8b1a661023f5b36932860bc84271eecd
SHA3-384 hash: 0dfd1816333c74a1132617b362a635d6e495f44b445b4cea4466e7505a80936c19146f0084a8385a786f9b00fcf9a568
SHA1 hash: 0f080abd03c143f54bb0cbc7ac682b0c828a000c
MD5 hash: 28636401da782ddf74e654e6d946af76
humanhash: cup-king-venus-island
File name:28636401DA782DDF74E654E6D946AF76.exe
Download: download sample
Signature Adware.FileTour
File size:4'026'978 bytes
First seen:2021-08-22 14:15:23 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 32569d67dc210c5cb9a759b08da2bdb3 (122 x RedLineStealer, 42 x DiamondFox, 37 x RaccoonStealer)
ssdeep 98304:xRCvLUBsgni5rb8JnSl9yaBVnzTuSE5wkDb4V6Tr7J:x6LUCgi5rb8ol9RtE5wkAM1
Threatray 392 similar samples on MalwareBazaar
TLSH T1D71633707F8988BEDA898175E78C7BF5F65CC380A7050DC327C4828D2F3A8AA455F466
dhash icon 848c5454baf47474 (2'088 x Adware.Neoreklami, 101 x RedLineStealer, 33 x DiamondFox)
Reporter abuse_ch
Tags:Adware.FileTour exe


Avatar
abuse_ch
Adware.FileTour C2:
86.106.181.31:38670

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
86.106.181.31:38670 https://threatfox.abuse.ch/ioc/192571/
185.180.231.69:42875 https://threatfox.abuse.ch/ioc/192572/

Intelligence


File Origin
# of uploads :
1
# of downloads :
190
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
28636401DA782DDF74E654E6D946AF76.exe
Verdict:
No threats detected
Analysis date:
2021-08-22 14:16:10 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Searching for the window
Running batch commands
Connection attempt
Sending a custom TCP request
DNS request
Sending an HTTP GET request
Deleting a recently created file
Launching a process
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
RedLine Socelars Vidar
Detection:
malicious
Classification:
troj.adwa.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
.NET source code contains very large strings
.NET source code references suspicious native API functions
Adds a directory exclusion to Windows Defender
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Creates a thread in another existing process (thread injection)
Creates HTML files with .exe extension (expired dropper behavior)
Creates processes via WMI
Detected unpacking (changes PE section rights)
Disable Windows Defender real time protection (registry)
Drops PE files to the document folder of the user
Drops PE files to the startup folder
Machine Learning detection for dropped file
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Obfuscated command line found
PE file has a writeable .text section
Query firmware table information (likely to detect VMs)
Sets debug register (to hijack the execution of another thread)
Sigma detected: Powershell Defender Exclusion
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: Suspicious Svchost Process
Submitted sample is a known malware sample
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Writes to foreign memory regions
Yara detected RedLine Stealer
Yara detected Socelars
Yara detected Vidar stealer
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 469492 Sample: YZ1xv9YUAP.exe Startdate: 22/08/2021 Architecture: WINDOWS Score: 100 144 Antivirus detection for URL or domain 2->144 146 Antivirus detection for dropped file 2->146 148 Multi AV Scanner detection for dropped file 2->148 150 13 other signatures 2->150 12 YZ1xv9YUAP.exe 18 2->12         started        15 rundll32.exe 2->15         started        process3 file4 102 C:\Users\user\AppData\...\setup_install.exe, PE32 12->102 dropped 104 C:\Users\user\AppData\...\Wed15f94f82567f.exe, PE32 12->104 dropped 106 C:\Users\user\...\Wed1595f777e32404.exe, PE32 12->106 dropped 108 13 other files (3 malicious) 12->108 dropped 17 setup_install.exe 1 12->17         started        21 rundll32.exe 15->21         started        process5 dnsIp6 122 172.67.142.91 CLOUDFLARENETUS United States 17->122 124 127.0.0.1 unknown unknown 17->124 152 Adds a directory exclusion to Windows Defender 17->152 23 cmd.exe 1 17->23         started        25 cmd.exe 1 17->25         started        28 cmd.exe 1 17->28         started        32 8 other processes 17->32 154 Writes to foreign memory regions 21->154 156 Allocates memory in foreign processes 21->156 158 Creates a thread in another existing process (thread injection) 21->158 30 svchost.exe 21->30 injected signatures7 process8 signatures9 34 Wed15f94f82567f.exe 23->34         started        184 Submitted sample is a known malware sample 25->184 186 Obfuscated command line found 25->186 188 Uses ping.exe to sleep 25->188 194 2 other signatures 25->194 39 powershell.exe 12 25->39         started        41 Wed15156f2613c99fcf8.exe 1 14 28->41         started        190 Sets debug register (to hijack the execution of another thread) 30->190 192 Modifies the context of a thread in another process (thread injection) 30->192 43 svchost.exe 30->43         started        45 Wed157806d79d1e.exe 32->45         started        47 Wed15251f7879.exe 32->47         started        49 Wed155a25e62a3deb4.exe 2 32->49         started        51 4 other processes 32->51 process10 dnsIp11 128 185.233.185.134 YURTEH-ASUA Russian Federation 34->128 130 37.0.10.214 WKD-ASIE Netherlands 34->130 138 13 other IPs or domains 34->138 88 C:\Users\...\y5DrFVAEHGBEplwn2FIqyROw.exe, PE32 34->88 dropped 90 C:\Users\...\x8Jy5_xvSttE47fTg6dIXNcI.exe, PE32 34->90 dropped 92 C:\Users\...\vaVQ7iXQn2eqSdPSVquoVgLC.exe, PE32 34->92 dropped 100 40 other files (34 malicious) 34->100 dropped 164 Drops PE files to the document folder of the user 34->164 166 Creates HTML files with .exe extension (expired dropper behavior) 34->166 168 Tries to harvest and steal browser information (history, passwords, etc) 34->168 170 Disable Windows Defender real time protection (registry) 34->170 53 _I6mqCW1P8ORhgqYd898oOot.exe 34->53         started        132 208.95.112.1 TUT-ASUS United States 41->132 140 4 other IPs or domains 41->140 94 C:\Users\user\AppData\...\fastsystem.exe, PE32+ 41->94 dropped 96 C:\Users\user\AppData\...\aaa_011[1].dll, DOS 41->96 dropped 172 Drops PE files to the startup folder 41->172 134 34.97.69.225 GOOGLEUS United States 43->134 174 Query firmware table information (likely to detect VMs) 43->174 55 cmd.exe 45->55         started        57 dllhost.exe 45->57         started        176 Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation)) 47->176 178 Checks if the current machine is a virtual machine (disk enumeration) 47->178 59 explorer.exe 47->59 injected 180 Creates processes via WMI 49->180 61 Wed155a25e62a3deb4.exe 49->61         started        136 162.159.135.233 CLOUDFLARENETUS United States 51->136 98 C:\Users\user\AppData\Local\...\LzmwAqmV.exe, PE32 51->98 dropped 182 Detected unpacking (changes PE section rights) 51->182 65 LzmwAqmV.exe 51->65         started        file12 signatures13 process14 dnsIp15 67 cmd.exe 55->67         started        70 conhost.exe 55->70         started        72 rundll32.exe 59->72         started        142 104.21.70.98 CLOUDFLARENETUS United States 61->142 112 C:\Users\user\AppData\Local\Temp\sqlite.dll, PE32 61->112 dropped 74 conhost.exe 61->74         started        114 C:\Users\user\AppData\Local\Temp\3.exe, PE32 65->114 dropped 116 C:\Users\user\AppData\Local\Temp\2.exe, PE32 65->116 dropped 118 C:\Users\user\AppData\Local\...\Chrome 5.exe, PE32+ 65->118 dropped 120 2 other files (none is malicious) 65->120 dropped 76 Chrome 5.exe 65->76         started        file16 process17 file18 160 Obfuscated command line found 67->160 162 Uses ping.exe to sleep 67->162 79 Riconobbe.exe.com 67->79         started        81 PING.EXE 67->81         started        84 findstr.exe 67->84         started        110 C:\Users\user\AppData\...\services64.exe, PE32+ 76->110 dropped signatures19 process20 dnsIp21 86 Riconobbe.exe.com 79->86         started        126 192.168.2.4 unknown unknown 81->126 process22
Threat name:
Win32.Trojan.ArkeiStealer
Status:
Malicious
First seen:
2021-08-18 19:49:18 UTC
AV detection:
32 of 46 (69.57%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:glupteba family:metasploit family:redline family:smokeloader family:vidar botnet:706 botnet:pab3 aspackv2 backdoor dropper infostealer loader persistence stealer themida trojan
Behaviour
Kills process with taskkill
Runs ping.exe
Script User-Agent
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Adds Run key to start application
Legitimate hosting services abused for malware hosting/C2
Looks up external IP address via web service
Loads dropped DLL
Themida packer
ASPack v2.12-2.42
Downloads MZ/PE file
Executes dropped EXE
Vidar Stealer
Glupteba
Glupteba Payload
MetaSploit
Process spawned unexpected child process
RedLine
RedLine Payload
SmokeLoader
Vidar
Malware Config
C2 Extraction:
185.215.113.15:61506
https://eduarroma.tumblr.com/
http://aucmoney.com/upload/
http://thegymmum.com/upload/
http://atvcampingtrips.com/upload/
http://kuapakualaman.com/upload/
http://renatazarazua.com/upload/
http://nasufmutlu.com/upload/
Unpacked files
SH256 hash:
092f7cdb24e1f159ff96f8722709f11763ed8a7b6d30030c3c8c061ff1a17076
MD5 hash:
34fdd72a0040886d7afd3e9207bf9f58
SHA1 hash:
2a833dfa6d27d18e61a45c4842132f36aef52e36
SH256 hash:
1ab460eac81001bfa0da8cbadfd4fba0ad0f371742a2c725ff5cf71bdd8e2b9f
MD5 hash:
1dc95107f7dd6d1392bb8d9b53b76916
SHA1 hash:
b26f9c90ad4656d2ddf3e96da967e0f65a9623e1
SH256 hash:
d1ff2f8a510fb4d25dd861e4cd5196585ccdd66cd6e941941e13d634da825f32
MD5 hash:
e3ed5e6a62ece3cf158688bce4161fbf
SHA1 hash:
5a8c4dddf69e8650952b0d29987cc6edfe25fb0b
SH256 hash:
ab9bb888f6235eaee1ad52cd9b4d1f960ea09743ff80919d0095383f3683c583
MD5 hash:
eff546ee925781db419befdf93bd045d
SHA1 hash:
1129b509403fa589b50310f99f77c69ecc7f8314
SH256 hash:
a18e5d223da775448e2e111101fe1f4ab919be801fd435d3a278718aa5e6ccba
MD5 hash:
0c6cae115465a83f05d3ff391fd009ac
SHA1 hash:
066ea93bb540ae4be0d2e522d4bb59eec74053ad
SH256 hash:
3e35832690fd1115024f918f4bc37e756b1617ae628e55b94f0e04045e57b49b
MD5 hash:
77c6eb4eb2a045c304ae95ef5bbaa2b2
SHA1 hash:
eeb4a9ab13957bfafd6e015f65c09ba65b3d699c
SH256 hash:
44d33d40c9362cd060b8696cf2848b6ec4b4d591738d12a07241820e88c1772e
MD5 hash:
ad2bdb5c9b71b3908ec920a3ebd33513
SHA1 hash:
c4e528056f461fff91c659dcc9e2c0e39468b60f
SH256 hash:
c22d73c0e9923ec307ff03639ea96a928b417987a42e1d263c12de6e7b41cffb
MD5 hash:
d28bdd8c0752afa50a10cd52d0525be1
SHA1 hash:
a8a856736b32721b700b9ee231751b54bf6a6dc6
SH256 hash:
598fec81466082f9c4fdcc70adc961f2fa7ae1eaa7faf9ed21092aa095034d74
MD5 hash:
ad492b41dd1a76ceb5a597ee74053495
SHA1 hash:
9abdaa776f5cbf8a72591104f492296ccded3187
SH256 hash:
762bfc4ac412480a909b440086f0e7ac77f087a2f9e103f19c6f37f413cc3a7e
MD5 hash:
633cb69dbc02bf10ce09073c85307595
SHA1 hash:
9a65551cc03917ec9fc82a4ca53841ac662938f0
SH256 hash:
fff543452ed6fae9135f3f114f01cb70b4f398618a2958d2497aa3ca591df014
MD5 hash:
fe2cfb63c029b1be76de10fd8e6f721a
SHA1 hash:
5eb9bc4f1d00425064bd8b4e4e3870e76df4e971
SH256 hash:
e4099414d49ef439e1e14fb01f39b979a0cea38acc105853cfa7f5143209c422
MD5 hash:
99fdfd7b331dfa56fb02229c3907b273
SHA1 hash:
0d4e898251afb44388fe546a528d57bc20b9389e
SH256 hash:
ed6a085b92a19e26ec1eef9ea8ed876d5518fc5ca3af33b49e16cbb85dd9941d
MD5 hash:
65ddd41a12be72b55ff42f0ef001a377
SHA1 hash:
97f8ce2ea2d0059c9fcf60bc00d43235bad1c11e
SH256 hash:
2da835a57ab9f4cf74a9d0242cb0bb8d5e597034d3a3b134a8e61c5b0ff380b0
MD5 hash:
49ca17f27e06f97fac403fc7f5a6b314
SHA1 hash:
ee589eb580c6e6af8da078711b3e50a05654da6c
SH256 hash:
6c33d6e3cdc870eaf680ee887a2fd4f9aa903ebc684d1fcbd3a5c0d7bc6901fd
MD5 hash:
09db5f9961aa1384f378b1e6afbe48d3
SHA1 hash:
07384dac9c76a1497b3e0ec7dda44953e79d47cd
SH256 hash:
3d7ba99d7b360819146cd6223b2d668e8b1a661023f5b36932860bc84271eecd
MD5 hash:
28636401da782ddf74e654e6d946af76
SHA1 hash:
0f080abd03c143f54bb0cbc7ac682b0c828a000c
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments