Threat name:
PureLog Stealer, RedLine, RisePro Steale
Alert
Classification:
rans.troj.adwa.spyw.expl.evad
.NET source code contains method to dynamically call methods (often used by packers)
Adds extensions / path to Windows Defender exclusion list (Registry)
AI detected suspicious sample
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Contains functionality to detect sleep reduction / modifications
Contains functionality to infect the boot sector
Contains functionality to inject threads in other processes
Creates HTML files with .exe extension (expired dropper behavior)
Detected unpacking (changes PE section rights)
Disable Windows Defender real time protection (registry)
Disables Windows Defender (deletes autostart)
Drops PE files to the document folder of the user
Drops PE files to the startup folder
Drops PE files with a suspicious file extension
Exclude list of file types from scheduled, custom, and real-time scanning
Found direct / indirect Syscall (likely to bypass EDR)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Found stalling execution ending in API Sleep call
Hides threads from debuggers
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Modifies Group Policy settings
Modifies power options to not sleep / hibernate
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Overwrites code with unconditional jumps - possibly settings hooks in foreign process
PE file contains section with special chars
PE file has nameless sections
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Sigma detected: Disable power options
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Crypto Currency Wallets
Tries to steal Mail credentials (via file / registry access)
Uses powercfg.exe to modify the power settings
Uses schtasks.exe or at.exe to add and modify task schedules
Writes many files with high entropy
Writes to foreign memory regions
Yara detected Generic Downloader
Yara detected Powershell download and execute
Yara detected PureLog Stealer
Yara detected RedLine Stealer
Yara detected RisePro Stealer
Yara detected UAC Bypass using CMSTP
Yara detected Vidar stealer
behaviorgraph
top1
signatures2
2
Behavior Graph
ID:
1453289
Sample:
UmMgwOUPt5.exe
Startdate:
06/06/2024
Architecture:
WINDOWS
Score:
100
140
Found malware configuration
2->140
142
Malicious sample detected
(through community Yara
rule)
2->142
144
Antivirus detection
for URL or domain
2->144
146
20 other signatures
2->146
8
UmMgwOUPt5.exe
11
53
2->8
started
13
svchost.exe
2->13
started
15
svchost.exe
2->15
started
17
2 other processes
2->17
process3
dnsIp4
130
176.111.174.109
WILWAWPL
Russian Federation
8->130
132
94.232.45.38
WELLWEBNL
Russian Federation
8->132
138
20 other IPs or domains
8->138
82
C:\Users\...\vKFWj2E2SexRwx9Z0fAA34Fv.exe, PE32
8->82
dropped
84
C:\Users\...\tlIbT2dN7D7sZbG70jaOlQs4.exe, PE32
8->84
dropped
86
C:\Users\...\rwLYKGin3MXETsgK_IAzug81.exe, PE32
8->86
dropped
88
25 other malicious files
8->88
dropped
186
Overwrites code with
unconditional jumps
- possibly settings
hooks in foreign process
8->186
188
Drops PE files to the
document folder of the
user
8->188
190
Creates HTML files with
.exe extension (expired
dropper behavior)
8->190
192
7 other signatures
8->192
19
j8wVddc0tmfSFVJqtZS2FzLb.exe
8->19
started
22
akdPwjtQ5882j9P89iA4UBY2.exe
2
62
8->22
started
26
VzeA_ihziRa3FzOzpsJfRx5V.exe
8->26
started
28
13 other processes
8->28
134
184.28.90.27
AKAMAI-ASUS
United States
13->134
136
127.0.0.1
unknown
unknown
13->136
file5
signatures6
process7
dnsIp8
64
C:\Users\...\j8wVddc0tmfSFVJqtZS2FzLb.tmp, PE32
19->64
dropped
30
j8wVddc0tmfSFVJqtZS2FzLb.tmp
19->30
started
124
147.45.47.126
FREE-NET-ASFREEnetEU
Russian Federation
22->124
126
104.26.4.15
CLOUDFLARENETUS
United States
22->126
76
3 other malicious files
22->76
dropped
166
Detected unpacking (changes
PE section rights)
22->166
168
Tries to steal Mail
credentials (via file
/ registry access)
22->168
170
Found many strings related
to Crypto-Wallets (likely
being stolen)
22->170
180
6 other signatures
22->180
33
schtasks.exe
22->33
started
66
C:\Users\user\AppData\Local\Temp\...\scrt.dll, PE32
26->66
dropped
68
C:\Users\user\AppData\...\thirdparty.dll, PE32
26->68
dropped
70
C:\Users\user\AppData\Local\...\sciterui.dll, PE32
26->70
dropped
78
10 other malicious files
26->78
dropped
172
Writes many files with
high entropy
26->172
128
172.67.202.186
CLOUDFLARENETUS
United States
28->128
72
C:\...\PpfsSWY66vXc47tZe8X_tipk.exe (copy), PE32+
28->72
dropped
74
C:\Users\user\AppData\Local\...\Install.exe, PE32
28->74
dropped
80
14 other malicious files
28->80
dropped
174
Overwrites code with
unconditional jumps
- possibly settings
hooks in foreign process
28->174
176
Query firmware table
information (likely
to detect VMs)
28->176
178
Tries to detect sandboxes
and other dynamic analysis
tools (window names)
28->178
182
11 other signatures
28->182
35
RegAsm.exe
28->35
started
39
MSBuild.exe
28->39
started
41
MSBuild.exe
28->41
started
43
8 other processes
28->43
file9
signatures10
process11
dnsIp12
92
C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+
30->92
dropped
94
C:\Users\user\AppData\Local\...\_iscrypt.dll, PE32
30->94
dropped
96
C:\Users\user\AppData\Local\...\_RegDLL.tmp, PE32
30->96
dropped
104
34 other files (23 malicious)
30->104
dropped
45
consoledictaphone32.exe
30->45
started
48
consoledictaphone32.exe
30->48
started
51
conhost.exe
33->51
started
112
149.154.167.99
TELEGRAMRU
United Kingdom
35->112
114
116.202.190.18
HETZNER-ASDE
Germany
35->114
98
C:\Users\user\AppData\Local\...\sqls[1].dll, PE32
35->98
dropped
148
Tries to harvest and
steal Putty / WinSCP
information (sessions,
passwords, etc)
35->148
150
Tries to harvest and
steal ftp login credentials
35->150
152
Tries to harvest and
steal browser information
(history, passwords,
etc)
35->152
164
2 other signatures
35->164
116
5.42.65.63
RU-KSTVKolomnaGroupofcompaniesGuarantee-tvRU
Russian Federation
39->116
154
Tries to steal Crypto
Currency Wallets
39->154
156
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
41->156
158
Queries sensitive disk
information (via WMI,
Win32_DiskDrive, often
done to detect virtual
machines)
41->158
53
conhost.exe
41->53
started
118
95.101.111.148
TELEFONICATELXIUSES
European Union
43->118
120
35.81.211.41
MERIT-AS-14US
United States
43->120
122
2 other IPs or domains
43->122
100
C:\Users\user\AppData\Local\...\Install.exe, PE32
43->100
dropped
102
C:\Users\user\AppData\Local\...\Child.pif, PE32
43->102
dropped
160
Queries sensitive network
adapter information
(via WMI, Win32_NetworkAdapter,
often done to detect
virtual machines)
43->160
162
Drops PE files with
a suspicious file extension
43->162
55
Install.exe
43->55
started
58
conhost.exe
43->58
started
60
conhost.exe
43->60
started
62
conhost.exe
43->62
started
file13
signatures14
process15
dnsIp16
90
C:\ProgramData\...\PCI Bridge 6.5.66.exe, PE32
45->90
dropped
106
93.123.39.193
NET1-ASBG
Bulgaria
48->106
108
194.59.31.219
COMBAHTONcombahtonGmbHDE
Germany
48->108
110
141.98.234.31
CH-NET-ASRO
Russian Federation
48->110
184
Multi AV Scanner detection
for dropped file
55->184
file17
signatures18
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.url : hxxp://irfanrashid.com/wp-content/server3/AppGate2103v01.exe