MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5bbc833edf2e7c061fd34fe1aba85ff56746dbe0875eafcc945c264ac45193ae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DiamondFox


Vendor detections: 9


Intelligence 9 IOCs 1 YARA 10 File information Comments

SHA256 hash: 5bbc833edf2e7c061fd34fe1aba85ff56746dbe0875eafcc945c264ac45193ae
SHA3-384 hash: fbc6e6561390d5e59494c9846e8eb4eae35b205642b1702cfd59a82da466d5f3ce740a561edf5e4f7ef9a3f78129b0ba
SHA1 hash: 210b371d8c3d4e1bc3e913173207590ec41c7710
MD5 hash: 720ac82bbf6ae7c41ea0630be8a40710
humanhash: speaker-snake-nuts-aspen
File name:720AC82BBF6AE7C41EA0630BE8A40710.exe
Download: download sample
Signature DiamondFox
File size:3'882'077 bytes
First seen:2021-09-02 01:01:05 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash c05041e01f84e1ccca9c4451f3b6a383 (141 x RedLineStealer, 101 x GuLoader, 64 x DiamondFox)
ssdeep 49152:9gxFlcj5VXxQ4Ql8k5YPvMsv2T7zQiyBEGAgBiILY6kX6Xovi8pHPu8YiW1SQ845:yfUhOVYPTWQpPAOiIUne5sPukE9AtbsR
Threatray 471 similar samples on MalwareBazaar
TLSH T1E906335E6BDAA36BF6BE47F66D0D9773A18311CA0249C2337B836B3F30520935419689
dhash icon b2a89c96a2cada72 (2'283 x Formbook, 981 x Loki, 803 x AgentTesla)
Reporter abuse_ch
Tags:DiamondFox exe


Avatar
abuse_ch
DiamondFox C2:
http://45.142.215.144/

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://45.142.215.144/ https://threatfox.abuse.ch/ioc/204183/

Intelligence


File Origin
# of uploads :
1
# of downloads :
186
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
https://www.google.com
Verdict:
Malicious activity
Analysis date:
2021-08-29 15:18:20 UTC
Tags:
trojan evasion rat redline loader stealer opendir raccoon

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Creating a process from a recently created file
Creating a file
Searching for the window
Running batch commands
Connection attempt
Sending a custom TCP request
DNS request
Sending an HTTP GET request
Deleting a recently created file
Launching a process
Sending a UDP request
Result
Threat name:
RedLine Vidar
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
.NET source code contains very large strings
Adds a directory exclusion to Windows Defender
Antivirus detection for dropped file
Antivirus detection for URL or domain
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Contains functionality to steal Chrome passwords or cookies
Creates a thread in another existing process (thread injection)
Creates HTML files with .exe extension (expired dropper behavior)
Creates processes via WMI
Detected unpacking (changes PE section rights)
Disable Windows Defender real time protection (registry)
Drops PE files to the document folder of the user
Found many strings related to Crypto-Wallets (likely being stolen)
Machine Learning detection for dropped file
Machine Learning detection for sample
Maps a DLL or memory area into another process
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
PE file has a writeable .text section
PE file has nameless sections
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: Powershell Defender Exclusion
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: Suspicious Svchost Process
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected RedLine Stealer
Yara detected Vidar stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 476158 Sample: 53lnF4fzSf.exe Startdate: 02/09/2021 Architecture: WINDOWS Score: 100 78 88.99.66.31 HETZNER-ASDE Germany 2->78 80 34.97.69.225 GOOGLEUS United States 2->80 82 3 other IPs or domains 2->82 100 Multi AV Scanner detection for domain / URL 2->100 102 Antivirus detection for URL or domain 2->102 104 Antivirus detection for dropped file 2->104 106 17 other signatures 2->106 10 53lnF4fzSf.exe 10 2->10         started        signatures3 process4 file5 46 C:\Users\user\AppData\...\setup_installer.exe, PE32 10->46 dropped 13 setup_installer.exe 16 10->13         started        process6 file7 48 C:\Users\user\AppData\...\setup_install.exe, PE32 13->48 dropped 50 C:\Users\user\AppData\...\Sun14eb4b7c17.exe, PE32 13->50 dropped 52 C:\Users\user\AppData\...\Sun14d2ba445ad3.exe, PE32 13->52 dropped 54 11 other files (6 malicious) 13->54 dropped 16 setup_install.exe 1 13->16         started        process8 dnsIp9 74 172.67.190.165 CLOUDFLARENETUS United States 16->74 76 127.0.0.1 unknown unknown 16->76 98 Adds a directory exclusion to Windows Defender 16->98 20 cmd.exe 1 16->20         started        22 cmd.exe 1 16->22         started        24 cmd.exe 16->24         started        26 7 other processes 16->26 signatures10 process11 signatures12 29 Sun14c78e5159b8.exe 20->29         started        34 Sun14eb4b7c17.exe 22->34         started        36 Sun1479047a006c5.exe 24->36         started        108 Adds a directory exclusion to Windows Defender 26->108 38 Sun14115415e7a48116.exe 1 26->38         started        40 Sun1477d99f5afb5a49.exe 3 26->40         started        42 Sun14d2ba445ad3.exe 26->42         started        44 3 other processes 26->44 process13 dnsIp14 84 37.0.10.214 WKD-ASIE Netherlands 29->84 86 37.0.10.237 WKD-ASIE Netherlands 29->86 94 10 other IPs or domains 29->94 56 C:\Users\...\zVuy80lQffUrqR3tefaXGpbJ.exe, PE32 29->56 dropped 58 C:\Users\...\xWdNCkI_K0PzI507poMghHS0.exe, PE32 29->58 dropped 60 C:\Users\...\uyG5ltdzWPSDCUy0UBWO4RCF.exe, PE32 29->60 dropped 68 47 other files (46 malicious) 29->68 dropped 110 Drops PE files to the document folder of the user 29->110 112 Creates HTML files with .exe extension (expired dropper behavior) 29->112 114 Tries to harvest and steal browser information (history, passwords, etc) 29->114 116 Disable Windows Defender real time protection (registry) 29->116 118 Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation)) 34->118 120 Maps a DLL or memory area into another process 34->120 134 2 other signatures 34->134 62 C:\Users\user\AppData\Local\Temp\2.exe, PE32 36->62 dropped 70 7 other files (none is malicious) 36->70 dropped 122 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 36->122 124 Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines) 36->124 88 208.95.112.1 TUT-ASUS United States 38->88 90 45.136.151.102 ENZUINC-US Latvia 38->90 126 Contains functionality to steal Chrome passwords or cookies 38->126 96 2 other IPs or domains 40->96 64 C:\Users\user\AppData\Local\Temp\sqlite.dll, PE32 40->64 dropped 128 Creates processes via WMI 40->128 92 104.21.45.243 CLOUDFLARENETUS United States 42->92 72 5 other files (none is malicious) 42->72 dropped 130 Detected unpacking (changes PE section rights) 42->130 66 C:\Users\user\AppData\...\Sun1410432520b.tmp, PE32 44->66 dropped 132 Antivirus detection for dropped file 44->132 file15 signatures16
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2021-08-29 20:40:35 UTC
AV detection:
19 of 26 (73.08%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:redline family:smokeloader family:vidar botnet:706 aspackv2 backdoor infostealer stealer trojan
Behaviour
Creates scheduled task(s)
Script User-Agent
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Legitimate hosting services abused for malware hosting/C2
Looks up external IP address via web service
Loads dropped DLL
ASPack v2.12-2.42
Downloads MZ/PE file
Executes dropped EXE
Vidar Stealer
Process spawned unexpected child process
RedLine
RedLine Payload
SmokeLoader
Vidar
Malware Config
C2 Extraction:
https://eduarroma.tumblr.com/
http://varmisende.com/upload/
http://fernandomayol.com/upload/
http://nextlytm.com/upload/
http://people4jan.com/upload/
http://asfaltwerk.com/upload/
Unpacked files
SH256 hash:
a18e5d223da775448e2e111101fe1f4ab919be801fd435d3a278718aa5e6ccba
MD5 hash:
0c6cae115465a83f05d3ff391fd009ac
SHA1 hash:
066ea93bb540ae4be0d2e522d4bb59eec74053ad
SH256 hash:
1e47b0a87b714febf0f805a2c319a150cc8bd58d738669c76c975a64d40130ab
MD5 hash:
6cbca955ae2bb778cf9de6cef5d114a7
SHA1 hash:
527feb36a0cbd2c348df1862bb2d4516ed9bad6f
SH256 hash:
835c9b5e60ebf50a888e851d1c7218d436490613ec04a04055b73fbddf73edf3
MD5 hash:
6961557695f34a53cf8224be7c265fbe
SHA1 hash:
f52d34d0b1dbd181f2acb21f42d875d514afb6f7
SH256 hash:
3771ec17ece279c44d1060dc976fba3a4a7bc2368b142558fff79dc5251eaf5e
MD5 hash:
e090a885a7c508719e44bb15e71e1236
SHA1 hash:
e576ba4039c49e18c271f7e1a6df333d71b05774
SH256 hash:
07c98ebadc8f866e96c721e1135a80623311de7cdcc129b72f70adc0e5dde79c
MD5 hash:
18a83f5a7d45e94c0dd733bc04c86c2b
SHA1 hash:
b6c9d920b5d0c648792849f92d734ace939c7125
SH256 hash:
fbffb84931a267fab6c24cf08723fa029cb85c2315f01d5b1f41922350adb831
MD5 hash:
052270e8e9cfb3512932e0df484caef4
SHA1 hash:
85305fee690beea8458bab5d55d0368c47340501
SH256 hash:
5141358e3cf7e38a08f24756b11c09e0aee1fec5f772fcdae2b76119499089cf
MD5 hash:
b51276d58889e5059fe2aebe2c9a7ffc
SHA1 hash:
818c793937698bea493e5f04113474b8b8b3b9f9
SH256 hash:
1114cfcfc3a653c10bdf33854bcfc06107dde68c53dd7932e920a8a0efbcbfdd
MD5 hash:
4687ba4892d5d9dde1f5f2c82935a600
SHA1 hash:
3fc3fe5c2ec62e9387a03f61d91c5d5bb7eb2b68
SH256 hash:
a1648c7cabe9610b76929b68c8eb77e96774f99830086a680ff23f73d54a14c7
MD5 hash:
8542fc7fd092dd26be9ec1422d499253
SHA1 hash:
16fbce14433d813507f40a386de28931c41c05f7
SH256 hash:
dd3b75cac9b5278b6d756a7f8b3b45b3eb920e7d2d8e54622a8b02fb850f24ab
MD5 hash:
73ba520cf0a1f0fe9d80505c9a95c5dc
SHA1 hash:
0803381244a8e4ca82f69ee470f508db6dbc7d05
SH256 hash:
e1cc6a9d780602fe6e789bf5c3a27e87e197a4e3bf7c8138ea2f9dfec70fb963
MD5 hash:
f707252b9c9579677fffb013e0cfc646
SHA1 hash:
8ab483023fa8773afb8c13464c39c5b8e687f126
SH256 hash:
e427f8ef21691e3d8c2313d11129ad08ddef69a158eca2f77c170603478ff0c4
MD5 hash:
0dedd909aae9aa0a89b4422106310e9e
SHA1 hash:
271d36afa5b729ee590cf8066166ca5e9c9d0340
SH256 hash:
424eb094b40901ea9e2a8b53ce7ee29c9b9c2401cc85447a9117723d63789cbe
MD5 hash:
9846c1e317e308f46a807bf0ccd2f085
SHA1 hash:
23d85d7d9da727e048dd1c0349b35d2299f26d77
SH256 hash:
e43bcd56602249eb712981f762cac077c61be08ff5a13464859687b1d2427b81
MD5 hash:
810b58f42e4957bc9c03d8178bc0abd5
SHA1 hash:
fec00bdad4fa9cd4ce4bdbfae73e5de4ea876496
SH256 hash:
4a8cdf5213ab3980cb6c713b55c550bba04714581230d7b834b384e19c9f296f
MD5 hash:
eea45669aec27b8b548c64c723e6428f
SHA1 hash:
8b7c85349a764d763db8ab44cd9198c66a3bf776
SH256 hash:
dd1c53620f0d391708dea3cd31b515571fd8f95f59435f77b3914ec16671aff8
MD5 hash:
baea5c2925549b479d0a6b18e2345e24
SHA1 hash:
bc5da27c47d0ce94fc2b64631f29633ff3c78791
SH256 hash:
a30763894230aaa780d3b4bd42da4d54e1579855b86cebca117d3c7fc16f8b1a
MD5 hash:
8c64ea1a48a2dcdaf51cdab2ac761eb9
SHA1 hash:
e1e1d02bc2ef9fd13978974d9596debcbb553953
SH256 hash:
5bbc833edf2e7c061fd34fe1aba85ff56746dbe0875eafcc945c264ac45193ae
MD5 hash:
720ac82bbf6ae7c41ea0630be8a40710
SHA1 hash:
210b371d8c3d4e1bc3e913173207590ec41c7710
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_SUSPICIOUS_EXE_Referenfces_Messaging_Clients
Author:ditekSHen
Description:Detects executables referencing many email and collaboration clients. Observed in information stealers
Rule name:INDICATOR_SUSPICIOUS_EXE_SQLQuery_ConfidentialDataStore
Author:ditekSHen
Description:Detects executables containing SQL queries to confidential data stores. Observed in infostealers
Rule name:INDICATOR_SUSPICIOUS_EXE_WindDefender_AntiEmaulation
Author:ditekSHen
Description:Detects executables containing potential Windows Defender anti-emulation checks
Rule name:MALWARE_Win_RedLine
Author:ditekSHen
Description:Detects RedLine infostealer
Rule name:MALWARE_Win_Vidar
Author:ditekSHen
Description:Detects Vidar / ArkeiStealer
Rule name:RedOctoberPluginCollectInfo
Rule name:SUSP_XORed_Mozilla
Author:Florian Roth
Description:Detects suspicious XORed keyword - Mozilla/5.0
Reference:Internal Research
Rule name:SUSP_XORed_MSDOS_Stub_Message
Author:Florian Roth
Description:Detects suspicious XORed MSDOS stub message
Reference:https://yara.readthedocs.io/en/latest/writingrules.html#xor-strings
Rule name:Vidar
Author:kevoreilly
Description:Vidar Payload
Rule name:win_raccoon_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.raccoon.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments