MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8f2789b6a628a92f9f6313305b255c405f867c49161bb864263dcfef5a6f712d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DiamondFox


Vendor detections: 11


Intelligence 11 IOCs 1 YARA File information Comments

SHA256 hash: 8f2789b6a628a92f9f6313305b255c405f867c49161bb864263dcfef5a6f712d
SHA3-384 hash: 9d8932c6cf5164d4b41f36c2b29ac7da4148e76a76c2995f8fed83fa2a1fea41a935328e89500eb51b489b20f7a61e6f
SHA1 hash: ce71aa0cadf61f081f22890fbb391cc536068942
MD5 hash: d1d2ed561cc81996d7f28424253acac7
humanhash: november-rugby-eleven-gee
File name:8F2789B6A628A92F9F6313305B255C405F867C49161BB.exe
Download: download sample
Signature DiamondFox
File size:3'665'707 bytes
First seen:2021-08-11 04:00:56 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash c05041e01f84e1ccca9c4451f3b6a383 (141 x RedLineStealer, 101 x GuLoader, 64 x DiamondFox)
ssdeep 49152:Eg5CcEMhKKA4iNE41WnmZLaFDZGxJyq4sBxNtBSZYT+D+yP7kipYYvwDmly4Bg7+:J5CcEMhdrz4TSDZynVB78dKYYD90VSlI
Threatray 303 similar samples on MalwareBazaar
TLSH T1C80633039C75DBB6CE0F68F28B9DA4427EF8C5346A55C352C72EA9E8F0681A4915F30D
dhash icon b2a89c96a2cada72 (2'283 x Formbook, 981 x Loki, 803 x AgentTesla)
Reporter abuse_ch
Tags:DiamondFox exe


Avatar
abuse_ch
DiamondFox C2:
http://ggc-partners.in/decision.php

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://ggc-partners.in/decision.php https://threatfox.abuse.ch/ioc/170210/

Intelligence


File Origin
# of uploads :
1
# of downloads :
133
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
main_setup_x86x64.exe
Verdict:
Malicious activity
Analysis date:
2021-06-27 15:37:49 UTC
Tags:
trojan loader stealer vidar evasion rat redline

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Creating a process from a recently created file
Creating a file
Searching for the window
Moving a recently created file
Running batch commands
Connection attempt
Sending a custom TCP request
DNS request
Launching the default Windows debugger (dwwin.exe)
Creating a window
Launching a process
Sending an HTTP GET request
Creating a process with a hidden window
Reading critical registry keys
Deleting a recently created file
Sending a UDP request
Sending an HTTP POST request
Unauthorized injection to a recently created process
Blocking the Windows Defender launch
Connection attempt to an infection source
Unauthorized injection to a recently created process by context flags manipulation
Query of malicious DNS domain
Sending a TCP request to an infection source
Sending an HTTP GET request to an infection source
Unauthorized injection to a system process
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
RedLine SmokeLoader Vidar
Detection:
malicious
Classification:
troj.spyw.evad.mine
Score:
100 / 100
Signature
.NET source code contains very large strings
.NET source code references suspicious native API functions
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
Checks if the current machine is a virtual machine (disk enumeration)
Creates a thread in another existing process (thread injection)
Disable Windows Defender real time protection (registry)
DLL reload attack detected
Drops PE files to the document folder of the user
Found many strings related to Crypto-Wallets (likely being stolen)
Found strings related to Crypto-Mining
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
PE file has a writeable .text section
PE file has nameless sections
Query firmware table information (likely to detect VMs)
Renames NTDLL to bypass HIPS
Sets debug register (to hijack the execution of another thread)
Sigma detected: Suspicious Svchost Process
Tries to harvest and steal browser information (history, passwords, etc)
Writes to foreign memory regions
Yara detected RedLine Stealer
Yara detected SmokeLoader
Yara detected Vidar stealer
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 463013 Sample: 8F2789B6A628A92F9F6313305B2... Startdate: 11/08/2021 Architecture: WINDOWS Score: 100 153 Antivirus detection for URL or domain 2->153 155 Antivirus detection for dropped file 2->155 157 Multi AV Scanner detection for dropped file 2->157 159 14 other signatures 2->159 12 8F2789B6A628A92F9F6313305B255C405F867C49161BB.exe 10 2->12         started        15 svchost.exe 2->15         started        18 svchost.exe 1 2->18         started        20 2 other processes 2->20 process3 dnsIp4 121 C:\Users\user\AppData\...\setup_installer.exe, PE32 12->121 dropped 22 setup_installer.exe 16 12->22         started        151 23.211.4.86 AKAMAI-ASUS United States 15->151 file5 process6 file7 89 C:\Users\user\AppData\Local\...\sonia_8.txt, PE32 22->89 dropped 91 C:\Users\user\AppData\Local\...\sonia_7.txt, PE32 22->91 dropped 93 C:\Users\user\AppData\Local\...\sonia_6.txt, PE32 22->93 dropped 95 11 other files (none is malicious) 22->95 dropped 25 setup_install.exe 1 22->25         started        process8 dnsIp9 139 127.0.0.1 unknown unknown 25->139 113 C:\Users\user\AppData\...\sonia_7.exe (copy), PE32 25->113 dropped 115 C:\Users\user\AppData\...\sonia_6.exe (copy), PE32 25->115 dropped 117 C:\Users\user\AppData\...\sonia_3.exe (copy), PE32 25->117 dropped 119 5 other files (1 malicious) 25->119 dropped 29 cmd.exe 1 25->29         started        31 cmd.exe 1 25->31         started        33 cmd.exe 1 25->33         started        35 7 other processes 25->35 file10 process11 dnsIp12 38 sonia_6.exe 29->38         started        43 sonia_1.exe 5 31->43         started        45 sonia_2.exe 1 33->45         started        123 52.182.143.212 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 35->123 47 sonia_4.exe 1 35->47         started        49 sonia_7.exe 35->49         started        51 sonia_3.exe 12 35->51         started        53 2 other processes 35->53 process13 dnsIp14 125 136.144.41.133 WORLDSTREAMNL Netherlands 38->125 127 136.144.41.201 WORLDSTREAMNL Netherlands 38->127 133 17 other IPs or domains 38->133 97 C:\Users\...\zK8hSv3eUYotqGVUZF_tdNvE.exe, PE32 38->97 dropped 99 C:\Users\...\ytn7Vsm9cxxp7oe7a_GcKqHp.exe, PE32 38->99 dropped 101 C:\Users\...\yTgpsojEGTWV9qLrzPIOomEW.exe, PE32 38->101 dropped 111 37 other files (34 malicious) 38->111 dropped 169 Drops PE files to the document folder of the user 38->169 171 Disable Windows Defender real time protection (registry) 38->171 103 C:\Users\user\AppData\Local\Temp\axhub.dll, PE32 43->103 dropped 55 rundll32.exe 43->55         started        105 C:\Users\user\AppData\Local\Temp\CC4F.tmp, PE32 45->105 dropped 173 DLL reload attack detected 45->173 175 Renames NTDLL to bypass HIPS 45->175 177 Maps a DLL or memory area into another process 45->177 181 2 other signatures 45->181 58 explorer.exe 45->58 injected 129 208.95.112.1 TUT-ASUS United States 47->129 135 2 other IPs or domains 47->135 107 C:\Users\user\AppData\...\jfiag3g_gg.exe, PE32 47->107 dropped 60 jfiag3g_gg.exe 47->60         started        62 jfiag3g_gg.exe 47->62         started        179 Injects a PE file into a foreign processes 49->179 65 sonia_7.exe 49->65         started        131 74.114.154.18 AUTOMATTICUS Canada 51->131 67 WerFault.exe 51->67         started        137 2 other IPs or domains 53->137 109 C:\Users\user\AppData\Local\...\sonia_8.tmp, PE32 53->109 dropped 70 sonia_8.tmp 53->70         started        file15 signatures16 process17 dnsIp18 161 Writes to foreign memory regions 55->161 163 Allocates memory in foreign processes 55->163 165 Creates a thread in another existing process (thread injection) 55->165 72 svchost.exe 55->72 injected 75 svchost.exe 55->75 injected 167 Tries to harvest and steal browser information (history, passwords, etc) 60->167 143 192.168.2.1 unknown unknown 62->143 145 87.251.71.195 RMINJINERINGRU Russian Federation 65->145 81 C:\ProgramData\Microsoft\...\Report.wer, Little-endian 67->81 dropped 147 194.163.135.248 NEXINTO-DE Germany 70->147 149 185.227.110.219 LEASEWEB-NL-AMS-01NetherlandsNL Netherlands 70->149 83 C:\Users\user\AppData\Local\Temp\...\idp.dll, PE32 70->83 dropped 85 C:\Users\user\AppData\Local\...\_shfoldr.dll, PE32 70->85 dropped 87 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 70->87 dropped file19 signatures20 process21 signatures22 183 Sets debug register (to hijack the execution of another thread) 72->183 185 Modifies the context of a thread in another process (thread injection) 72->185 77 svchost.exe 72->77         started        process23 dnsIp24 141 198.13.62.186 AS-CHOOPAUS United States 77->141 187 Query firmware table information (likely to detect VMs) 77->187 signatures25
Threat name:
Win32.Trojan.Glupteba
Status:
Malicious
First seen:
2021-06-27 11:41:19 UTC
AV detection:
24 of 28 (85.71%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:redline family:smokeloader family:vidar botnet:706 botnet:937 botnet:servani aspackv2 backdoor evasion infostealer stealer suricata themida trojan upx vmprotect
Behaviour
Checks SCSI registry key(s)
Checks processor information in registry
Kills process with taskkill
Modifies data under HKEY_USERS
Modifies registry class
Modifies system certificate store
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of UnmapMainImage
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Drops file in System32 directory
Suspicious use of SetThreadContext
Legitimate hosting services abused for malware hosting/C2
Looks up external IP address via web service
Checks computer location settings
Loads dropped DLL
Themida packer
ASPack v2.12-2.42
Downloads MZ/PE file
Executes dropped EXE
UPX packed file
VMProtect packed file
Vidar Stealer
Modifies Windows Defender Real-time Protection settings
RedLine
RedLine Payload
SmokeLoader
Suspicious use of NtCreateProcessExOtherParentProcess
Suspicious use of NtCreateUserProcessOtherParentProcess
Vidar
suricata: ET MALWARE GCleaner Downloader Activity M1
suricata: ET MALWARE Possible Dridex Download URI Struct with no referer
suricata: ET MALWARE Possible Windows executable sent when remote host claims to send a Text File
suricata: ET MALWARE Suspicious Zipped Filename in Outbound POST Request (Passwords.txt)
suricata: ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile
suricata: ET MALWARE Vidar/Arkei Stealer Client Data Upload
suricata: ET MALWARE Vidar/Arkei/Megumin/Oski Stealer Data Exfil
Malware Config
C2 Extraction:
https://sergeevih43.tumblr.com/
87.251.71.195:82
http://ppcspb.com/upload/
http://mebbing.com/upload/
http://twcamel.com/upload/
http://howdycash.com/upload/
http://lahuertasonora.com/upload/
http://kpotiques.com/upload/
http://aucmoney.com/upload/
http://thegymmum.com/upload/
http://atvcampingtrips.com/upload/
http://kuapakualaman.com/upload/
http://renatazarazua.com/upload/
http://nasufmutlu.com/upload/
https://lenak513.tumblr.com/
Dropper Extraction:
http://91.241.19.52/Api/GetFile2
Unpacked files
SH256 hash:
0c2ade2993927f6de828e30c07156c19751b55650a05c965631ca0ea1c983498
MD5 hash:
cc0d6b6813f92dbf5be3ecacf44d662a
SHA1 hash:
b968c57a14ddada4128356f6e39fb66c6d864d3f
SH256 hash:
55361941ab12c7edd987c706d25423d868f756fab1028d99eeffacdabf3da4ca
MD5 hash:
4de4b7bc0a92902422c4204fcfa58150
SHA1 hash:
587e0299ea32cc836281998941daa60f471e3480
SH256 hash:
40ca14be87ccee1c66cce8ce07d7ed9b94a0f7b46d84f9147c4bbf6ddab75a67
MD5 hash:
7165e9d7456520d1f1644aa26da7c423
SHA1 hash:
177f9116229a021e24f80c4059999c4c52f9e830
SH256 hash:
de427ec4cbf5ced1935dfc885e1c7fd3899ebc9d5465a5fcfa213556a5fd2e67
MD5 hash:
f4a6ad0d61120257614f97a62c7d812a
SHA1 hash:
db7bd48b5400233d440dfe9c556aab938b6f75f4
SH256 hash:
8bffd03b544965ff5d3588821d84c985c1b5d6d184afd60560e2cbefe9d49a2e
MD5 hash:
21b97c585040846e0a9d8b8cb7615ab7
SHA1 hash:
6cd4fe4106a9cf685341c3f2670867d6064c4687
SH256 hash:
d417bd4de6a5227f5ea5cff3567e74fe2b2a25c0a80123b7b37b27db89adc384
MD5 hash:
5668cb771643274ba2c375ec6403c266
SHA1 hash:
dd78b03428b99368906fe62fc46aaaf1db07a8b9
SH256 hash:
10a122bd647c88aa23f96687e26b251862e83be9dbb89532f4a578689547972d
MD5 hash:
89c739ae3bbee8c40a52090ad0641d31
SHA1 hash:
d0f7dc9a0a3e52af0f9f9736f26e401636c420a1
SH256 hash:
982fe03f39f07e83f06fc03c2151c3bbc4cc1e8e9a2c29f2342dc802e5f493a6
MD5 hash:
1268e66aa1b02137a1fbdeac58efcab1
SHA1 hash:
a822c4435ebc41cc0550b05f0678658f22db61fc
SH256 hash:
6eb240d2420486563bc3bb928c667d42340369d81777be298202461e852cfa4f
MD5 hash:
6fb2033a62a80f3edd7891655a883343
SHA1 hash:
90e23d196d1ad6e2f431dff17f156d3c501dc251
SH256 hash:
ba2e7b2b3be8430306f3f4c6ed3e16e9d11787e3e9ae00ceb58a790602e8d065
MD5 hash:
72b50ef11d6af5f78130843b725774d9
SHA1 hash:
6bc06fa5204c0d601304cad54275ab2c5d6396e0
SH256 hash:
2d0dce0229d0a7c50b7b83eb353b9fc86ce9c1633f91c30f993ef2ff94112a67
MD5 hash:
051d125840519e302b88ed1bac7f4432
SHA1 hash:
3540429bb14f3ca747b60407a0196002b471a827
SH256 hash:
9f251d5f05a267eb6ce4a99eb17ed954610604c0a6741c29dc2f53dfb1f08297
MD5 hash:
b35429243cde1ce73e5536800eb7d45e
SHA1 hash:
3053cf91c3db2174e18977e7aa36f9df6321a16e
SH256 hash:
e1cc6a9d780602fe6e789bf5c3a27e87e197a4e3bf7c8138ea2f9dfec70fb963
MD5 hash:
f707252b9c9579677fffb013e0cfc646
SHA1 hash:
8ab483023fa8773afb8c13464c39c5b8e687f126
SH256 hash:
e427f8ef21691e3d8c2313d11129ad08ddef69a158eca2f77c170603478ff0c4
MD5 hash:
0dedd909aae9aa0a89b4422106310e9e
SHA1 hash:
271d36afa5b729ee590cf8066166ca5e9c9d0340
SH256 hash:
02870576625dd2bb801d07b12b7dbe4dce565c1129bcbce6c13c548d46ebf047
MD5 hash:
90f185ecb220f4b2c6729ada7a258088
SHA1 hash:
62d4d7c6c6edd6a373f2e21cd75b0f7ea8b9882c
SH256 hash:
8f2789b6a628a92f9f6313305b255c405f867c49161bb864263dcfef5a6f712d
MD5 hash:
d1d2ed561cc81996d7f28424253acac7
SHA1 hash:
ce71aa0cadf61f081f22890fbb391cc536068942
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments