Threat name:
Cryptbot RedLine SmokeLoader Tofsee Vida
Alert
Classification:
troj.spyw.evad
.NET source code contains potential unpacker
.NET source code contains very large array initializations
.NET source code references suspicious native API functions
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
Benign windows process drops PE files
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Connects to many ports of the same IP (likely port scanning)
Contains functionality to detect sleep reduction / modifications
Contains functionality to inject code into remote processes
Creates a thread in another existing process (thread injection)
Deletes itself after installation
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Drops executables to the windows directory (C:\Windows) and starts them
Found many strings related to Crypto-Wallets (likely being stolen)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Hides threads from debuggers
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Maps a DLL or memory area into another process
Modifies the windows firewall
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
PE file has nameless sections
Performs DNS queries to domains with low reputation
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Sigma detected: Copying Sensitive Files with Credential Data
Sigma detected: Suspect Svchost Activity
Sigma detected: Suspicious Svchost Process
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to evade analysis by execution special instruction which cause usermode exception
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Uses netsh to modify the Windows network and firewall settings
Writes to foreign memory regions
Yara detected RedLine Stealer
Yara detected SmokeLoader
Yara detected Vidar stealer
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
530952
Sample:
mV7xCB2tb7.exe
Startdate:
30/11/2021
Architecture:
WINDOWS
Score:
100
80
quadoil.ru
185.231.245.147, 443, 49759, 49780
TEAM-HOSTASRU
Russian Federation
2->80
82
microsoft-com.mail.protection.outlook.com
104.47.54.36, 25, 49756
MICROSOFT-CORP-MSN-AS-BLOCKUS
United States
2->82
84
10 other IPs or domains
2->84
106
Snort IDS alert for
network traffic (e.g.
based on Emerging Threat
rules)
2->106
108
Multi AV Scanner detection
for domain / URL
2->108
110
Antivirus detection
for URL or domain
2->110
112
25 other signatures
2->112
11
mV7xCB2tb7.exe
2->11
started
14
uueuhfj
2->14
started
16
ludlzrzi.exe
2->16
started
signatures3
process4
signatures5
122
Contains functionality
to inject code into
remote processes
11->122
124
Injects a PE file into
a foreign processes
11->124
18
mV7xCB2tb7.exe
11->18
started
126
Machine Learning detection
for dropped file
14->126
21
uueuhfj
14->21
started
128
Detected unpacking (changes
PE section rights)
16->128
130
Detected unpacking (overwrites
its own PE header)
16->130
132
Writes to foreign memory
regions
16->132
134
Allocates memory in
foreign processes
16->134
process6
signatures7
98
Checks for kernel code
integrity (NtQuerySystemInformation(CodeIntegrityInformation))
18->98
100
Maps a DLL or memory
area into another process
18->100
102
Checks if the current
machine is a virtual
machine (disk enumeration)
18->102
23
explorer.exe
16
18->23
injected
28
conhost.exe
18->28
started
104
Creates a thread in
another existing process
(thread injection)
21->104
process8
dnsIp9
86
192.162.246.70, 49703, 80
DATACHEAP-LLC-ASRU
Russian Federation
23->86
88
211.59.14.90, 49772, 80
SKB-ASSKBroadbandCoLtdKR
Korea Republic of
23->88
90
6 other IPs or domains
23->90
70
C:\Users\user\AppData\Roaming\uueuhfj, PE32
23->70
dropped
72
C:\Users\user\AppData\Roaming\hseuhfj, PE32
23->72
dropped
74
C:\Users\user\AppData\Local\Temp\FD42.exe, PE32
23->74
dropped
76
10 other malicious files
23->76
dropped
114
System process connects
to network (likely due
to code injection or
exploit)
23->114
116
Benign windows process
drops PE files
23->116
118
Deletes itself after
installation
23->118
120
Hides that the sample
has been downloaded
from the Internet (zone.identifier)
23->120
30
AEF.exe
4
23->30
started
34
FD42.exe
2
23->34
started
37
F9BA.exe
23->37
started
39
3 other processes
23->39
file10
signatures11
process12
dnsIp13
92
45.9.20.149, 42871, 49768
DEDIPATH-LLCUS
Russian Federation
30->92
136
Multi AV Scanner detection
for dropped file
30->136
138
Query firmware table
information (likely
to detect VMs)
30->138
140
Tries to detect sandboxes
and other dynamic analysis
tools (window names)
30->140
154
3 other signatures
30->154
64
C:\Users\user\AppData\Local\...\ludlzrzi.exe, PE32
34->64
dropped
142
Detected unpacking (changes
PE section rights)
34->142
144
Detected unpacking (overwrites
its own PE header)
34->144
146
Machine Learning detection
for dropped file
34->146
156
2 other signatures
34->156
41
cmd.exe
1
34->41
started
44
cmd.exe
2
34->44
started
46
sc.exe
34->46
started
54
3 other processes
34->54
148
Checks for kernel code
integrity (NtQuerySystemInformation(CodeIntegrityInformation))
37->148
158
3 other signatures
37->158
94
192.168.2.1
unknown
unknown
39->94
96
file-file-host4.com
39->96
66
C:\Users\user\AppData\...\sqlite3[1].dll, PE32
39->66
dropped
68
C:\ProgramData\sqlite3.dll, PE32
39->68
dropped
150
Antivirus detection
for dropped file
39->150
152
Tries to harvest and
steal browser information
(history, passwords,
etc)
39->152
160
3 other signatures
39->160
48
conhost.exe
39->48
started
50
EEF9.exe
39->50
started
52
A51F.exe
39->52
started
file14
signatures15
process16
file17
78
C:\Windows\SysWOW64\...\ludlzrzi.exe (copy), PE32
41->78
dropped
56
conhost.exe
41->56
started
58
conhost.exe
44->58
started
60
conhost.exe
46->60
started
62
conhost.exe
54->62
started
process18
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.