MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 723e570331aa3284a7b94f247edd6c395df4dc0f55f1d263f418207c28ef0dbe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DiamondFox


Vendor detections: 10


Intelligence 10 IOCs 1 YARA File information Comments

SHA256 hash: 723e570331aa3284a7b94f247edd6c395df4dc0f55f1d263f418207c28ef0dbe
SHA3-384 hash: 04642a73e71ded41f5f12446b287d2c4a94c86c652a9a77a4832b00dd7349b4c10a7593380f1861618c2fb76daaa7af1
SHA1 hash: 37963628fd5ef4fbf99e03145374a31c99e54685
MD5 hash: a47e4ba5794dfd910a1402833d5f379e
humanhash: double-march-kansas-shade
File name:A47E4BA5794DFD910A1402833D5F379E.exe
Download: download sample
Signature DiamondFox
File size:4'108'083 bytes
First seen:2021-08-21 21:10:23 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash c05041e01f84e1ccca9c4451f3b6a383 (141 x RedLineStealer, 101 x GuLoader, 64 x DiamondFox)
ssdeep 98304:yZQHaZj1nYFguGgVS1HcjTUYCPENx9wX8/gH28y14PsgjlbD3h:yZQGnAguGQS1Hc3UYP9d4W8y14BlbLh
Threatray 393 similar samples on MalwareBazaar
TLSH T17E1633F914DA6175D0B5C631CF2FC69FBB9B556529A892D33E920F284802B908E1FFD0
dhash icon b2a89c96a2cada72 (2'283 x Formbook, 981 x Loki, 803 x AgentTesla)
Reporter abuse_ch
Tags:DiamondFox exe


Avatar
abuse_ch
DiamondFox C2:
31.44.3.94:62655

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
31.44.3.94:62655 https://threatfox.abuse.ch/ioc/192542/

Intelligence


File Origin
# of uploads :
1
# of downloads :
155
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
A47E4BA5794DFD910A1402833D5F379E.exe
Verdict:
No threats detected
Analysis date:
2021-08-21 21:11:53 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Creating a process from a recently created file
Creating a file
Searching for the window
Running batch commands
Connection attempt
Sending a custom TCP request
DNS request
Sending an HTTP GET request
Deleting a recently created file
Launching a process
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
RedLine Socelars Vidar
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains very large strings
.NET source code references suspicious native API functions
Adds a directory exclusion to Windows Defender
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Creates a thread in another existing process (thread injection)
Creates HTML files with .exe extension (expired dropper behavior)
Creates processes via WMI
Disable Windows Defender real time protection (registry)
Drops PE files to the document folder of the user
Machine Learning detection for dropped file
Machine Learning detection for sample
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Obfuscated command line found
PE file contains section with special chars
PE file has a writeable .text section
Sigma detected: Powershell Defender Exclusion
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: Suspicious Svchost Process
Submitted sample is a known malware sample
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Writes to foreign memory regions
Yara detected RedLine Stealer
Yara detected Socelars
Yara detected Vidar stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 469291 Sample: H2qT0LhVIi.exe Startdate: 21/08/2021 Architecture: WINDOWS Score: 100 118 34.97.69.225 GOOGLEUS United States 2->118 136 Antivirus detection for URL or domain 2->136 138 Antivirus detection for dropped file 2->138 140 Multi AV Scanner detection for dropped file 2->140 142 14 other signatures 2->142 14 H2qT0LhVIi.exe 10 2->14         started        17 rundll32.exe 2->17         started        signatures3 process4 file5 114 C:\Users\user\AppData\...\setup_installer.exe, PE32 14->114 dropped 19 setup_installer.exe 18 14->19         started        22 rundll32.exe 17->22         started        process6 file7 82 C:\Users\user\AppData\...\setup_install.exe, PE32 19->82 dropped 84 C:\Users\user\...\Wed01cc14a7b232c573c.exe, PE32 19->84 dropped 86 C:\Users\user\...\Wed01b1b688489137a.exe, PE32+ 19->86 dropped 88 13 other files (2 malicious) 19->88 dropped 25 setup_install.exe 1 19->25         started        148 Writes to foreign memory regions 22->148 150 Allocates memory in foreign processes 22->150 152 Creates a thread in another existing process (thread injection) 22->152 signatures8 process9 dnsIp10 132 172.67.142.91 CLOUDFLARENETUS United States 25->132 134 127.0.0.1 unknown unknown 25->134 168 Adds a directory exclusion to Windows Defender 25->168 29 cmd.exe 1 25->29         started        31 cmd.exe 1 25->31         started        34 cmd.exe 25->34         started        36 8 other processes 25->36 signatures11 process12 signatures13 38 Wed0187dd5121696b.exe 29->38         started        170 Submitted sample is a known malware sample 31->170 172 Obfuscated command line found 31->172 174 Uses ping.exe to sleep 31->174 176 2 other signatures 31->176 43 powershell.exe 12 31->43         started        45 Wed01e6754f9438ea6c7.exe 34->45         started        47 Wed018143c5ab.exe 36->47         started        49 Wed01cc14a7b232c573c.exe 36->49         started        51 Wed018f781281d3.exe 2 36->51         started        53 4 other processes 36->53 process14 dnsIp15 120 185.233.185.134 YURTEH-ASUA Russian Federation 38->120 122 37.0.10.214 WKD-ASIE Netherlands 38->122 128 12 other IPs or domains 38->128 90 C:\Users\...\zayMO9Yll1ZmqCGgm78vQZoQ.exe, PE32 38->90 dropped 92 C:\Users\...\thf3tzPcUb2h70DKm0he5rP7.exe, PE32 38->92 dropped 94 C:\Users\...\t5nroikLTWQLVAKqB18iegqF.exe, PE32 38->94 dropped 102 39 other files (36 malicious) 38->102 dropped 154 Drops PE files to the document folder of the user 38->154 156 Creates HTML files with .exe extension (expired dropper behavior) 38->156 158 Tries to harvest and steal browser information (history, passwords, etc) 38->158 160 Disable Windows Defender real time protection (registry) 38->160 96 C:\Users\user\AppData\Local\...\LzmwAqmV.exe, PE32 45->96 dropped 55 LzmwAqmV.exe 45->55         started        58 cmd.exe 47->58         started        60 dllhost.exe 47->60         started        162 Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation)) 49->162 164 Checks if the current machine is a virtual machine (disk enumeration) 49->164 62 explorer.exe 49->62 injected 166 Creates processes via WMI 51->166 64 Wed018f781281d3.exe 51->64         started        124 208.95.112.1 TUT-ASUS United States 53->124 126 8.8.8.8 GOOGLEUS United States 53->126 130 5 other IPs or domains 53->130 98 C:\Users\user\AppData\Roaming\2386911.exe, PE32 53->98 dropped 100 C:\Users\user\AppData\...\aaa_011[1].dll, DOS 53->100 dropped file16 signatures17 process18 dnsIp19 104 C:\Users\user\AppData\Local\Temp\4.exe, PE32 55->104 dropped 106 C:\Users\user\AppData\Local\Temp\3.exe, PE32 55->106 dropped 108 C:\Users\user\AppData\Local\Temp\2.exe, PE32 55->108 dropped 112 5 other files (1 malicious) 55->112 dropped 67 cmd.exe 58->67         started        70 conhost.exe 58->70         started        116 172.67.222.125 CLOUDFLARENETUS United States 64->116 110 C:\Users\user\AppData\Local\Temp\sqlite.dll, PE32 64->110 dropped 72 conhost.exe 64->72         started        file20 process21 signatures22 144 Obfuscated command line found 67->144 146 Uses ping.exe to sleep 67->146 74 Volevo.exe.com 67->74         started        76 findstr.exe 67->76         started        78 PING.EXE 67->78         started        process23 process24 80 Volevo.exe.com 74->80         started       
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2021-08-18 14:28:31 UTC
AV detection:
22 of 28 (78.57%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:redline family:smokeloader family:socelars family:vidar botnet:706 botnet:pab3 aspackv2 backdoor infostealer persistence stealer trojan
Behaviour
Creates scheduled task(s)
Delays execution with timeout.exe
Kills process with taskkill
Script User-Agent
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Adds Run key to start application
Legitimate hosting services abused for malware hosting/C2
Looks up external IP address via web service
Loads dropped DLL
ASPack v2.12-2.42
Downloads MZ/PE file
Executes dropped EXE
Vidar Stealer
Process spawned unexpected child process
RedLine
RedLine Payload
SmokeLoader
Socelars
Socelars Payload
Vidar
Malware Config
C2 Extraction:
https://lenak513.tumblr.com/
http://aucmoney.com/upload/
http://thegymmum.com/upload/
http://atvcampingtrips.com/upload/
http://kuapakualaman.com/upload/
http://renatazarazua.com/upload/
http://nasufmutlu.com/upload/
185.215.113.15:61506
Unpacked files
SH256 hash:
416e63fb614101d5644592d5f589f358f8d5a41dd6812a717cbf05470864ac6f
MD5 hash:
45a47d815f2291bc7fc0112d36aaad83
SHA1 hash:
db1dc02b2d64c4c3db89b5df3124dd87d43059d5
SH256 hash:
136544bc040bbb4a2915801631d2f5e47af9833a821fa647e184b79a88126767
MD5 hash:
1a7440165b4ee076ec8091c43051b55b
SHA1 hash:
c60d95eaf930dc99ef54c888f964e823cdf4cc9d
SH256 hash:
81dc60cc45f0a7764e6ae80a369645bcdcddde64df191d6cb70662dea29fb231
MD5 hash:
abff4c83cabfa4212164d913ee7d90fe
SHA1 hash:
ba20497addbb51945a9c9d4a3d02f31108c78a84
SH256 hash:
c50e98bac80f7c9e2f29fa03f38dbdd9e9fd9ff499b7b6b320340989356046fd
MD5 hash:
8d37ad8e3931e498b0086f50ba2f524b
SHA1 hash:
99b8441d6e3a56e3ef6bf4d486e64682b0740e32
SH256 hash:
61dca772de36ba4c8289764cd59630b022bc81151131754a0f33f48d76b762e0
MD5 hash:
c666d5cee0492f77ab7a4b985cc0e901
SHA1 hash:
8c400610ce8cbe4bd4fc7332b5730e1ad40f9215
SH256 hash:
e1cc6a9d780602fe6e789bf5c3a27e87e197a4e3bf7c8138ea2f9dfec70fb963
MD5 hash:
f707252b9c9579677fffb013e0cfc646
SHA1 hash:
8ab483023fa8773afb8c13464c39c5b8e687f126
SH256 hash:
8bf0ce3b488e4215fff1132571de0f40f8a8e139669f75e222f8c613d7085a1f
MD5 hash:
71b01acca3a78d7ec7a7e334f7b12687
SHA1 hash:
bca5481e16487b1e42c77878f03dbccfae6b7d03
SH256 hash:
2e19e19649c9a7c2ee8f294c062275a3729a504530efa7003d427098e86352e1
MD5 hash:
12f56b8148c714e8f954123ebf995d28
SHA1 hash:
86af269d17268ed7d56d09a62bbdc4d8c46a71ac
SH256 hash:
1ab460eac81001bfa0da8cbadfd4fba0ad0f371742a2c725ff5cf71bdd8e2b9f
MD5 hash:
1dc95107f7dd6d1392bb8d9b53b76916
SHA1 hash:
b26f9c90ad4656d2ddf3e96da967e0f65a9623e1
SH256 hash:
d1ff2f8a510fb4d25dd861e4cd5196585ccdd66cd6e941941e13d634da825f32
MD5 hash:
e3ed5e6a62ece3cf158688bce4161fbf
SHA1 hash:
5a8c4dddf69e8650952b0d29987cc6edfe25fb0b
SH256 hash:
ab9bb888f6235eaee1ad52cd9b4d1f960ea09743ff80919d0095383f3683c583
MD5 hash:
eff546ee925781db419befdf93bd045d
SHA1 hash:
1129b509403fa589b50310f99f77c69ecc7f8314
SH256 hash:
c199d7f1ceae35752ac78e035b5cb0fd3b8b9c37c4edd8503f2a7e96dc560a1a
MD5 hash:
4d39a0d1cbf6c1c17730711c0c313ae3
SHA1 hash:
a08d73267b7a2a23d3f207ce72c5a42b1dd73ac9
SH256 hash:
3df96afb2d5276c7028bc81ed10443154375217e8b7e84b5b330d0ac72969cac
MD5 hash:
f3760021c807d4009718616013c0409c
SHA1 hash:
6f0dead7515630f4ec2af8fc11fc0d3733ea638c
SH256 hash:
090d3ac8205c2c071a01ffd4db257d34072b145ee1d231e4c3283382f4e006ee
MD5 hash:
08d18ad8ec972e882be503d63dfe95c9
SHA1 hash:
6ff887d3b3d0f24a51f2769f76f65f11e219cc7e
SH256 hash:
d0c2208cac9cf894507b4d442c821dc2d85fd7fbb0d0ff5bc181cec4b3bfc6b9
MD5 hash:
7d0827371ad8d2a3c017fdd9b380edd3
SHA1 hash:
c2c1f423b6d22dc91b69e2261bd447e7f9f18640
Parent samples :
c9e1de1c6ddd3ffd9c87ebdbcf9bd5b7064af9f60f650ae50573b05a49af8327
1e71bcb4133949eaa1bead27b4e01f03f7802c6b92f61acbb6b8d7c8faf419d7
3ecf5237981fc6575586fe2e13f9afe240b132b58d7bc071296ec3816b150d26
bbfda112b2d2742ec593b14cf9a0d2558cedaa24ae89d0cc9b5c94b94705c772
feb872b8a43d6a65ed3aa7e97dfa6c729c9e6fdf31ca913cbdbf2051d990fd36
f8387262e71195a4db4a0ca0fe68b973e225b8dfe7b475580d19240a760d1e73
fbb957b3e36ba1dda0b65986117fd8555041d747810a100b47da4a90a1dfd693
5e30143f53af82ff891d9801ccff6b30e3dc7f3401bba597accb26e2d3b8b25d
fa5995b67f40f6c2cf7f3edba1e5a2213f2b083a35b13503af7a6203b4b8c33a
a6b218813c937087c078983f17d2520b0c2e7ad5d0cc41bfdf1d0cb540e4470a
440a157bbd8c8332d4edc63e6dc1399777e73bfb7ef3c5a356ab98fa56d1feea
95fb9ca82017f2a6bc59df0d72fc6f90043e135799d25e9922d4943da4c36874
007c6dfe4466894d678c06e6b30df77225450225ddd8e904e731cab32e82c512
9e7bf4b2bd7f30ea9d9dca6bc80d28c5b43202df1477a4d46f695e096dce17ba
c71463ac4fb8dd985b249b61e54888137bea84dab7c202546e230eb450fc0969
34b896d2e6470b2bd8facb9a796e0a521b78ec4956a573b5b38cacdc42622caa
8b738c9057baa2c3219120919226e95659cccec0dc61aca579bba58c7090719e
f6b2cd5327818418db45f70ed99bc6751d836eaf503a9bf33602af0c74f61e83
b426a6cb4005e266bf9b91b30d46fbbd0d6c541ac40d295aa99b8b7ef45e0edf
d43af0c0a5058412c903698b4ac55f150f6a20cac43344b5a596906780dac1f7
b4ca0b94b1a4e5b2ed28ad66c2df781b5add3c46cf5232b64b3a5253bcc341e8
1d40c76cecaabdf1e1d0004aa15cb469aa4374d1d0b2e48a47e588b1f84113d6
afdb413119fa2e0755a4885146d44547b97096d700d2b1236c6aba8f9bb9719d
7e74f3e8d070de8a3d3488dc7e68281d2450f28f79ee84edf3e0ea7c62bd7f91
d11d8d13e611c17ae61db286984170b2eb6802d2c23630e3211b9cfddaef09e6
d1dae6a275073c722606d35b783b4d176c0d8e0feff6c903c27ab9f0f8d7ab07
7c86e8c4143be0e27af9558ca46b3b4d7c5bee5e58e18902757bc02f6a3863a2
28319673d8f382142e223302ede1e0e497ccac2cd7a9814715726335e78c29c7
b130fe2fceada2a1980b6a0015c1bc1a9c1ee08f6229d99e43de82351da541fa
48a4042854a402824d35f4c95aed1e448d652d79ed0c251635acbc073200dfcf
e1f193deaa71595b668320d294635988f66c0f1ab1ab218e08fe3ae87fe10838
90f608b784fc8eac0a899d6aec257ec4beaf836e0cc808c7496f131aba61bef0
8435702911a3d6ebac7acef5aff7bc30395427892c1ddf39647b912a93260258
5bbb7a91ebfa925b0765103006bdde91f19c648ae792fab9dbc73832f3b2423c
SH256 hash:
90d0c29083013a83eb6d12ba7d637e5c9ddc4931486569eddb6c3b25beaf01ce
MD5 hash:
56082f45883af76b82e8f7c73cb313e8
SHA1 hash:
106e36b496e4ac15881db2af4fca51709d8c8639
SH256 hash:
723e570331aa3284a7b94f247edd6c395df4dc0f55f1d263f418207c28ef0dbe
MD5 hash:
a47e4ba5794dfd910a1402833d5f379e
SHA1 hash:
37963628fd5ef4fbf99e03145374a31c99e54685
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments