MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 78e623c6620f1b07f200e69f8d0127229cd3f415575e249b3539aa020c62e4d8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DiamondFox


Vendor detections: 8


Intelligence 8 IOCs 1 YARA File information Comments

SHA256 hash: 78e623c6620f1b07f200e69f8d0127229cd3f415575e249b3539aa020c62e4d8
SHA3-384 hash: 8ada9e626e757dbee7b996a65ac44ddf7451dce70c592b8f042775988fdda3b5fe4795b235299ea01956e6e96b3446a9
SHA1 hash: dd65aee16954c62a471d43ca7664d65dafa6e3e2
MD5 hash: 0286f9b59396cd300da7e312acde0650
humanhash: artist-alanine-blue-winner
File name:0286F9B59396CD300DA7E312ACDE0650.exe
Download: download sample
Signature DiamondFox
File size:4'537'040 bytes
First seen:2021-08-29 20:30:55 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 32569d67dc210c5cb9a759b08da2bdb3 (122 x RedLineStealer, 42 x DiamondFox, 37 x RaccoonStealer)
ssdeep 98304:xCCvLUBsgg6+Nf/mWmCI9kBqwTNOu8XRAB3jlFblKNlBWzFiSt7/C4:xzLUCgh+oz9kBZJyABTlalI5iSx64
Threatray 432 similar samples on MalwareBazaar
TLSH T1082633053255C0FBFA030132A84DDFFEB5FDCBE807106E9353A9DA461E35A96B60B856
dhash icon 848c5454baf47474 (2'088 x Adware.Neoreklami, 101 x RedLineStealer, 33 x DiamondFox)
Reporter abuse_ch
Tags:DiamondFox exe


Avatar
abuse_ch
DiamondFox C2:
http://5.181.156.252/

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://5.181.156.252/ https://threatfox.abuse.ch/ioc/201911/

Intelligence


File Origin
# of uploads :
1
# of downloads :
141
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Searching for the window
Running batch commands
Connection attempt
Sending a custom TCP request
DNS request
Sending an HTTP GET request
Launching a process
Deleting a recently created file
Creating a window
Creating a process with a hidden window
Connection attempt to an infection source
Launching cmd.exe command interpreter
Creating a file
Reading critical registry keys
Sending a UDP request
Using the Windows Management Instrumentation requests
Unauthorized injection to a recently created process
Query of malicious DNS domain
Sending a TCP request to an infection source
Blocking the Windows Defender launch
Sending an HTTP POST request to an infection source
Malware family:
Generic Malware
Verdict:
Malicious
Result
Threat name:
RedLine Socelars Vidar
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
Benign windows process drops PE files
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Creates a thread in another existing process (thread injection)
Creates processes via WMI
Detected unpacking (changes PE section rights)
Disable Windows Defender real time protection (registry)
Found C&C like URL pattern
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Machine Learning detection for dropped file
Maps a DLL or memory area into another process
May check the online IP address of the machine
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Obfuscated command line found
PE file has a writeable .text section
Performs DNS queries to domains with low reputation
Sigma detected: Powershell Defender Exclusion
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: Suspicious Svchost Process
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Submitted sample is a known malware sample
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Crypto Currency Wallets
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Writes to foreign memory regions
Yara detected RedLine Stealer
Yara detected Socelars
Yara detected Vidar
Yara detected Vidar stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 473549 Sample: 9SpunvBBtZ.exe Startdate: 29/08/2021 Architecture: WINDOWS Score: 100 129 144.202.76.47 AS-CHOOPAUS United States 2->129 131 google.vrthcobj.com 2->131 167 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->167 169 Multi AV Scanner detection for domain / URL 2->169 171 Found malware configuration 2->171 173 16 other signatures 2->173 13 9SpunvBBtZ.exe 18 2->13         started        16 rundll32.exe 2->16         started        18 svchost.exe 1 2->18         started        20 3 other processes 2->20 signatures3 process4 file5 121 C:\Users\user\AppData\...\setup_install.exe, PE32 13->121 dropped 123 C:\Users\user\AppData\...\Sat01ae6a02b12.exe, PE32 13->123 dropped 125 C:\Users\user\...\Sat0191dd9aa7513876e.exe, PE32 13->125 dropped 127 13 other files (7 malicious) 13->127 dropped 22 setup_install.exe 1 13->22         started        26 rundll32.exe 16->26         started        process6 dnsIp7 135 hsiens.xyz 172.67.142.91, 49708, 80 CLOUDFLARENETUS United States 22->135 137 127.0.0.1 unknown unknown 22->137 175 Performs DNS queries to domains with low reputation 22->175 177 Adds a directory exclusion to Windows Defender 22->177 28 cmd.exe 22->28         started        30 cmd.exe 1 22->30         started        32 cmd.exe 1 22->32         started        39 8 other processes 22->39 179 Writes to foreign memory regions 26->179 181 Allocates memory in foreign processes 26->181 183 Creates a thread in another existing process (thread injection) 26->183 35 svchost.exe 26->35 injected 37 svchost.exe 26->37 injected signatures8 process9 signatures10 41 Sat0167ecaf5f3d9e0ae.exe 28->41         started        46 Sat0152d2e7e2627.exe 30->46         started        159 Submitted sample is a known malware sample 32->159 161 Obfuscated command line found 32->161 163 Uses ping.exe to sleep 32->163 165 2 other signatures 32->165 48 powershell.exe 25 32->48         started        50 Sat0191dd9aa7513876e.exe 87 39->50         started        52 Sat0121d914644cacc0a.exe 39->52         started        54 Sat01ae6a02b12.exe 39->54         started        56 4 other processes 39->56 process11 dnsIp12 139 cdn.discordapp.com 162.159.129.233, 443, 49712 CLOUDFLARENETUS United States 41->139 95 C:\Users\user\AppData\Local\...\LzmwAqmV.exe, PE32 41->95 dropped 193 Antivirus detection for dropped file 41->193 195 Machine Learning detection for dropped file 41->195 58 LzmwAqmV.exe 41->58         started        197 Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation)) 46->197 199 Maps a DLL or memory area into another process 46->199 201 Checks if the current machine is a virtual machine (disk enumeration) 46->201 61 explorer.exe 46->61 injected 147 2 other IPs or domains 50->147 97 C:\Users\user\AppData\...\freebl3[1].dll, PE32 50->97 dropped 99 C:\Users\user\AppData\...\vcruntime140[1].dll, PE32 50->99 dropped 101 C:\Users\user\AppData\...\msvcp140[1].dll, PE32 50->101 dropped 105 9 other files (none is malicious) 50->105 dropped 203 Detected unpacking (changes PE section rights) 50->203 205 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 50->205 207 Tries to harvest and steal browser information (history, passwords, etc) 50->207 209 Tries to steal Crypto Currency Wallets 50->209 65 cmd.exe 52->65         started        67 dllhost.exe 52->67         started        141 37.0.10.237, 49715, 49726, 80 WKD-ASIE Netherlands 54->141 143 37.0.10.214, 49713, 80 WKD-ASIE Netherlands 54->143 149 2 other IPs or domains 54->149 211 May check the online IP address of the machine 54->211 213 Disable Windows Defender real time protection (registry) 54->213 145 ip-api.com 208.95.112.1, 49709, 80 TUT-ASUS United States 56->145 151 5 other IPs or domains 56->151 103 C:\Users\user\AppData\...\aaa_v013[1].dll, DOS 56->103 dropped 215 Creates processes via WMI 56->215 69 Sat01419f8e1c6b.exe 56->69         started        file13 signatures14 process15 dnsIp16 107 C:\Users\user\AppData\Local\Temp\4.exe, PE32 58->107 dropped 109 C:\Users\user\AppData\Local\Temp\3.exe, PE32 58->109 dropped 111 C:\Users\user\AppData\Local\Temp\2.exe, PE32 58->111 dropped 117 5 other files (1 malicious) 58->117 dropped 71 1.exe 58->71         started        74 Chrome3.exe 58->74         started        155 190.219.225.108 CableOndaPA Panama 61->155 113 C:\Users\user\AppData\Roaming\aideihh, PE32 61->113 dropped 217 Benign windows process drops PE files 61->217 219 Hides that the sample has been downloaded from the Internet (zone.identifier) 61->219 77 rundll32.exe 61->77         started        79 cmd.exe 65->79         started        81 conhost.exe 65->81         started        157 live.goatgame.live 172.67.222.125, 443, 49711 CLOUDFLARENETUS United States 69->157 115 C:\Users\user\AppData\Local\Temp\sqlite.dll, PE32 69->115 dropped 83 conhost.exe 69->83         started        file17 signatures18 process19 file20 185 Antivirus detection for dropped file 71->185 187 Machine Learning detection for dropped file 71->187 119 C:\Users\user\AppData\...\services64.exe, PE32+ 74->119 dropped 189 Obfuscated command line found 79->189 191 Uses ping.exe to sleep 79->191 85 PING.EXE 79->85         started        88 Piu.exe.com 79->88         started        90 findstr.exe 79->90         started        signatures21 process22 dnsIp23 133 192.168.2.3, 443, 49199, 49563 unknown unknown 85->133 92 Piu.exe.com 88->92         started        process24 dnsIp25 153 mfBkjRLTfwLSsveoSyZ.mfBkjRLTfwLSsveoSyZ 92->153
Threat name:
Win32.Trojan.Azorult
Status:
Malicious
First seen:
2021-08-29 01:19:21 UTC
AV detection:
17 of 25 (68.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:glupteba family:metasploit family:redline family:smokeloader family:vidar botnet:292.08 botnet:706 botnet:norman botnet:pub1 aspackv2 backdoor dropper infostealer loader persistence stealer suricata themida trojan
Behaviour
Checks SCSI registry key(s)
Creates scheduled task(s)
Kills process with taskkill
Runs ping.exe
Script User-Agent
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Adds Run key to start application
Legitimate hosting services abused for malware hosting/C2
Looks up external IP address via web service
Loads dropped DLL
Themida packer
ASPack v2.12-2.42
Downloads MZ/PE file
Executes dropped EXE
Vidar Stealer
Glupteba
Glupteba Payload
MetaSploit
Process spawned unexpected child process
RedLine
RedLine Payload
SmokeLoader
Vidar
suricata: ET MALWARE Suspicious Zipped Filename in Outbound POST Request (Passwords.txt)
suricata: ET MALWARE Vidar/Arkei Stealer Client Data Upload
Malware Config
C2 Extraction:
http://aucmoney.com/upload/
http://thegymmum.com/upload/
http://atvcampingtrips.com/upload/
http://kuapakualaman.com/upload/
http://renatazarazua.com/upload/
http://nasufmutlu.com/upload/
http://readinglistforaugust1.xyz/
http://readinglistforaugust2.xyz/
http://readinglistforaugust3.xyz/
http://readinglistforaugust4.xyz/
http://readinglistforaugust5.xyz/
http://readinglistforaugust6.xyz/
http://readinglistforaugust7.xyz/
http://readinglistforaugust8.xyz/
http://readinglistforaugust9.xyz/
http://readinglistforaugust10.xyz/
http://readinglistforaugust1.site/
http://readinglistforaugust2.site/
http://readinglistforaugust3.site/
http://readinglistforaugust4.site/
http://readinglistforaugust5.site/
http://readinglistforaugust6.site/
http://readinglistforaugust7.site/
http://readinglistforaugust8.site/
http://readinglistforaugust9.site/
http://readinglistforaugust10.site/
http://readinglistforaugust1.club/
http://readinglistforaugust2.club/
http://readinglistforaugust3.club/
http://readinglistforaugust4.club/
http://readinglistforaugust5.club/
http://readinglistforaugust6.club/
http://readinglistforaugust7.club/
http://readinglistforaugust8.club/
http://readinglistforaugust9.club/
http://readinglistforaugust10.club/
viacetequn.site:80
https://eduarroma.tumblr.com/
95.181.152.47:15089
45.14.49.184:25321
Unpacked files
SH256 hash:
a18e5d223da775448e2e111101fe1f4ab919be801fd435d3a278718aa5e6ccba
MD5 hash:
0c6cae115465a83f05d3ff391fd009ac
SHA1 hash:
066ea93bb540ae4be0d2e522d4bb59eec74053ad
SH256 hash:
feacf0ca0c6af0eba09c8e235527d1eb0979005051ef68abba1a38f7815c0f84
MD5 hash:
806c20eb3d12ef4ed586250503b66948
SHA1 hash:
92d0c7844988c60a21b8bbbeb55aa350a3499254
SH256 hash:
8963306b8dc579e19514edd491facb365cd40e16aaeecd475f2c355a724272bc
MD5 hash:
400653e50c7a17bba9549b6a191c0a1f
SHA1 hash:
11a7ce981de51465001bc0dfb3c348b4f2284d84
SH256 hash:
8a50b4a3ca9075a5e08e3f806db877c1b88305d13ba351276beed4a6fec8dd26
MD5 hash:
e75e1440eb164e13fa365e10ff894e7f
SHA1 hash:
0c24e02233a60a2eaeb293636c306d60acafe1ae
SH256 hash:
3001a2f2078c662d868c8893fac751274028d1b43ba3a8d96ae703a162d25892
MD5 hash:
896f2994b5067ca2dde8a62d8fc79328
SHA1 hash:
0230b505866ece8874ccf4a3fa939ff26be0ea77
SH256 hash:
1d53a1741021d44478a5beea3fe9c2dad1d06f432f241acb36e6b9b31660c814
MD5 hash:
bbf07901d12da487eb9edc8a8f1d33c8
SHA1 hash:
f5564a97cc708c758acbb658332a41997d89aa7a
SH256 hash:
045825d13745aa9ef8cc93d332352990494067726a364dadf47c51bed728ab14
MD5 hash:
eb31b0cd0d9b6de414d180de5c93e8bb
SHA1 hash:
ec9713322d130db1f728b9ff1b02cb70900c0f67
SH256 hash:
67706b5ae1d207bd7b0057fbb44e31547092cd80fb901e45775fb40f9cdccf0c
MD5 hash:
653c79fbffe6166096dedb08f0f12316
SHA1 hash:
e5bd2cac33fd6c4742fa70d74e3de7c989af1718
SH256 hash:
ad05101ae1ec45000fcdc1b0affa4bdbe8527679648341214a79e0bf1fb15e09
MD5 hash:
aee8e3e9464a5102f590bc00742971c9
SHA1 hash:
c6638b9de9601a52c2e6f249e2e8842f58247808
SH256 hash:
8a77dd50b720322088fbe92aeba219cc744bd664ff660058b1949c3b9b428bac
MD5 hash:
d1d4b4d26a9b9714a02c252fb46b72ce
SHA1 hash:
af9e34a28f8f408853d3cd504f03ae43c03cc24f
SH256 hash:
bdd9bd0cd6ef4ff8fe3eb342a26b2807368168981ad7575bda97095f1daf92ce
MD5 hash:
cd735fe854e7d8ed00490e7ca2c90698
SHA1 hash:
9ef46b0895cab1cc4de70ee7e58d90c7ced4c232
SH256 hash:
6f2ebb994b673284d9ab68282b430a1187260d433121e3fc8f2207fd6e4ade79
MD5 hash:
061b73b8ee45a2fa238b777498b441d0
SHA1 hash:
93d30e87c008d82995bbeea40cff37ad4199291b
SH256 hash:
2d8367588fab918f6954284a84496a422d40998f1b07d51dea4fd95bb84908a9
MD5 hash:
0e65597c6cc80cc36f20f7ea4a5b82ed
SHA1 hash:
c9d6ebfac9b712106b8628f1216a7a164ecb8898
SH256 hash:
5ca727417702b226e534c56de05a4ebd98d1875c49000016548406e5f2570e79
MD5 hash:
d13b5d69718d084048c140d959377510
SHA1 hash:
5cf4c164f2d7c813e8ad568c4c528fc5d05d210f
SH256 hash:
2c07e202b323b6387575e7e69df41dfaf48d70ff1e851be4067e8fb8cca6d829
MD5 hash:
8e6a5968958c9b35d66a505d46e723aa
SHA1 hash:
b0b30644511550018b2cb0276d9f50c5906a9d55
SH256 hash:
3d7b882b2e916817a13b3c3133781238c1d59ba9c8c8ac756f705cc390109a62
MD5 hash:
7cfde9493beb4bafe2abb152d137c7bd
SHA1 hash:
4bc709209fae2fdcf15b45ed269f9d1449bc52b0
SH256 hash:
49da05d2ac963e85cdd72e61cea512acdf7f28fb65f0f8e677ecb45a013ad4e8
MD5 hash:
df7e4ca29b9c78c2feca2f9318315cae
SHA1 hash:
a918ad054d38c2f8548b681e63e63effc76efcc9
SH256 hash:
78e623c6620f1b07f200e69f8d0127229cd3f415575e249b3539aa020c62e4d8
MD5 hash:
0286f9b59396cd300da7e312acde0650
SHA1 hash:
dd65aee16954c62a471d43ca7664d65dafa6e3e2
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments