Threat name:
Raccoon RedLine SmokeLoader
Alert
Classification:
troj.spyw.evad
.NET source code contains method to dynamically call methods (often used by packers)
Antivirus detection for URL or domain
Benign windows process drops PE files
C2 URLs / IPs found in malware configuration
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Connects to many ports of the same IP (likely port scanning)
Contain functionality to detect virtual machines
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Contains functionality to infect the boot sector
Contains functionality to inject code into remote processes
Creates a thread in another existing process (thread injection)
Deletes itself after installation
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Hides threads from debuggers
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Maps a DLL or memory area into another process
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
PE file has nameless sections
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Sigma detected: Conti Backup Database
Sigma detected: Disable or Delete Windows Eventlog
Sigma detected: PowerShell SAM Copy
Sigma detected: Suspicious PowerShell Invocations - Generic
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to evade analysis by execution special instruction which cause usermode exception
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Yara detected Raccoon Stealer
Yara detected RedLine Stealer
Yara detected SmokeLoader
behaviorgraph
top1
signatures2
2
Behavior Graph
ID:
534452
Sample:
pAOT82hUwe.exe
Startdate:
06/12/2021
Architecture:
WINDOWS
Score:
100
60
Multi AV Scanner detection
for domain / URL
2->60
62
Found malware configuration
2->62
64
Antivirus detection
for URL or domain
2->64
66
14 other signatures
2->66
9
pAOT82hUwe.exe
2->9
started
12
trsbaiv
2->12
started
process3
signatures4
82
Contains functionality
to inject code into
remote processes
9->82
84
Injects a PE file into
a foreign processes
9->84
14
pAOT82hUwe.exe
9->14
started
86
Multi AV Scanner detection
for dropped file
12->86
88
Machine Learning detection
for dropped file
12->88
17
trsbaiv
12->17
started
process5
signatures6
110
Checks for kernel code
integrity (NtQuerySystemInformation(CodeIntegrityInformation))
14->110
112
Maps a DLL or memory
area into another process
14->112
114
Checks if the current
machine is a virtual
machine (disk enumeration)
14->114
19
explorer.exe
4
14->19
injected
116
Creates a thread in
another existing process
(thread injection)
17->116
process7
dnsIp8
50
skylynx.biz.ua
178.208.83.42, 443, 49845
VDSINA-ASRU
Russian Federation
19->50
52
185.233.81.115, 443, 49741
SUPERSERVERSDATACENTERRU
Russian Federation
19->52
54
9 other IPs or domains
19->54
42
C:\Users\user\AppData\Roaming\trsbaiv, PE32
19->42
dropped
44
C:\Users\user\AppData\Local\Temp\D75A.exe, PE32
19->44
dropped
46
C:\Users\user\AppData\Local\Temp\8402.exe, PE32
19->46
dropped
48
4 other malicious files
19->48
dropped
74
System process connects
to network (likely due
to code injection or
exploit)
19->74
76
Benign windows process
drops PE files
19->76
78
Deletes itself after
installation
19->78
80
Hides that the sample
has been downloaded
from the Internet (zone.identifier)
19->80
24
D75A.exe
5
19->24
started
28
8402.exe
19->28
started
30
51C.exe
19->30
started
32
2 other processes
19->32
file9
signatures10
process11
dnsIp12
58
45.9.20.149, 42871, 49773
DEDIPATH-LLCUS
Russian Federation
24->58
90
Multi AV Scanner detection
for dropped file
24->90
92
Detected unpacking (changes
PE section rights)
24->92
94
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
24->94
108
7 other signatures
24->108
96
Query firmware table
information (likely
to detect VMs)
28->96
98
Tries to detect sandboxes
and other dynamic analysis
tools (window names)
28->98
100
Contains functionality
to infect the boot sector
28->100
102
Machine Learning detection
for dropped file
30->102
104
Injects a PE file into
a foreign processes
30->104
34
51C.exe
30->34
started
106
Detected unpacking (overwrites
its own PE header)
32->106
37
1F7B.exe
32->37
started
40
3045.exe
32->40
started
signatures13
process14
dnsIp15
68
Maps a DLL or memory
area into another process
34->68
70
Checks if the current
machine is a virtual
machine (disk enumeration)
34->70
72
Creates a thread in
another existing process
(thread injection)
34->72
56
91.219.236.207, 80
SERVERASTRA-ASHU
Hungary
37->56
signatures16
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.