Threat name:
RedLine SmokeLoader Tofsee
Alert
Classification:
troj.spyw.evad
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
.NET source code contains very large array initializations
.NET source code references suspicious native API functions
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
Benign windows process drops PE files
Changes security center settings (notifications, updates, antivirus, firewall)
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Contains functionality to inject code into remote processes
Creates a thread in another existing process (thread injection)
Deletes itself after installation
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Drops executables to the windows directory (C:\Windows) and starts them
Found many strings related to Crypto-Wallets (likely being stolen)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Hides threads from debuggers
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Maps a DLL or memory area into another process
Modifies the windows firewall
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Performs DNS queries to domains with low reputation
Query firmware table information (likely to detect VMs)
Sigma detected: Copying Sensitive Files with Credential Data
Sigma detected: Suspect Svchost Activity
Sigma detected: Suspicious Svchost Process
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Uses known network protocols on non-standard ports
Uses netsh to modify the Windows network and firewall settings
Writes to foreign memory regions
Yara detected RedLine Stealer
Yara detected SmokeLoader
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
485828
Sample:
EboN6H947L.exe
Startdate:
19/09/2021
Architecture:
WINDOWS
Score:
100
88
microsoft-com.mail.protection.outlook.com
52.101.24.0, 25, 49796
MICROSOFT-CORP-MSN-AS-BLOCKUS
United States
2->88
90
defeatwax.ru
193.56.146.188, 443, 49800, 49843
LVLT-10753US
unknown
2->90
92
4 other IPs or domains
2->92
134
Snort IDS alert for
network traffic (e.g.
based on Emerging Threat
rules)
2->134
136
Multi AV Scanner detection
for domain / URL
2->136
138
Antivirus detection
for URL or domain
2->138
140
20 other signatures
2->140
11
EboN6H947L.exe
2->11
started
14
bgidiuc
2->14
started
16
rhcoiuyq.exe
2->16
started
18
11 other processes
2->18
signatures3
process4
dnsIp5
150
Detected unpacking (changes
PE section rights)
11->150
21
EboN6H947L.exe
11->21
started
152
Multi AV Scanner detection
for dropped file
14->152
154
Machine Learning detection
for dropped file
14->154
156
Contains functionality
to inject code into
remote processes
14->156
158
Injects a PE file into
a foreign processes
14->158
24
bgidiuc
14->24
started
160
Detected unpacking (overwrites
its own PE header)
16->160
162
Writes to foreign memory
regions
16->162
164
Allocates memory in
foreign processes
16->164
94
127.0.0.1
unknown
unknown
18->94
96
192.168.2.1
unknown
unknown
18->96
98
kevonahira2.top
18->98
166
Changes security center
settings (notifications,
updates, antivirus,
firewall)
18->166
26
WerFault.exe
18->26
started
signatures6
process7
signatures8
142
Checks for kernel code
integrity (NtQuerySystemInformation(CodeIntegrityInformation))
21->142
144
Maps a DLL or memory
area into another process
21->144
146
Checks if the current
machine is a virtual
machine (disk enumeration)
21->146
28
explorer.exe
17
21->28
injected
148
Creates a thread in
another existing process
(thread injection)
24->148
process9
dnsIp10
106
193.56.146.41, 49771, 9080
LVLT-10753US
unknown
28->106
108
216.128.137.31, 80
AS-CHOOPAUS
United States
28->108
110
4 other IPs or domains
28->110
80
C:\Users\user\AppData\Roaming\bgidiuc, PE32
28->80
dropped
82
C:\Users\user\AppData\Local\Temp\BBA5.exe, PE32
28->82
dropped
84
C:\Users\user\AppData\Local\Temp\AF30.exe, PE32
28->84
dropped
86
6 other malicious files
28->86
dropped
168
System process connects
to network (likely due
to code injection or
exploit)
28->168
170
Benign windows process
drops PE files
28->170
172
Deletes itself after
installation
28->172
174
Hides that the sample
has been downloaded
from the Internet (zone.identifier)
28->174
33
7232.exe
28->33
started
37
9DF8.exe
28->37
started
39
BBA5.exe
3
28->39
started
42
4 other processes
28->42
file11
signatures12
process13
dnsIp14
76
C:\Users\user\AppData\Local\...\rhcoiuyq.exe, PE32
33->76
dropped
112
Detected unpacking (changes
PE section rights)
33->112
114
Detected unpacking (overwrites
its own PE header)
33->114
116
Machine Learning detection
for dropped file
33->116
132
2 other signatures
33->132
44
cmd.exe
33->44
started
47
cmd.exe
33->47
started
49
sc.exe
33->49
started
60
3 other processes
33->60
118
Multi AV Scanner detection
for dropped file
37->118
120
Query firmware table
information (likely
to detect VMs)
37->120
122
Tries to detect sandboxes
and other dynamic analysis
tools (window names)
37->122
102
188.124.36.242, 25802, 49835
SELECTELRU
Russian Federation
39->102
124
Hides threads from debuggers
39->124
126
Tries to detect sandboxes
/ dynamic malware analysis
system (registry check)
39->126
51
conhost.exe
39->51
started
104
a.uguu.se
144.76.201.136, 443, 49779, 49806
HETZNER-ASDE
Germany
42->104
128
Antivirus detection
for dropped file
42->128
130
Injects a PE file into
a foreign processes
42->130
53
AF30.exe
2
42->53
started
56
conhost.exe
42->56
started
58
A721.exe
42->58
started
62
2 other processes
42->62
file15
signatures16
process17
dnsIp18
78
C:\Windows\SysWOW64\...\rhcoiuyq.exe (copy), PE32
44->78
dropped
64
conhost.exe
44->64
started
66
conhost.exe
47->66
started
68
conhost.exe
49->68
started
100
146.70.35.170, 30905, 49834
TENET-1ZA
United Kingdom
53->100
70
conhost.exe
60->70
started
72
conhost.exe
60->72
started
74
conhost.exe
60->74
started
file19
process20
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.