Threat name:
Amadey Raccoon RedLine SmokeLoader Tofse
Alert
Classification:
troj.spyw.evad
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code references suspicious native API functions
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
Benign windows process drops PE files
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Contains functionality to detect sleep reduction / modifications
Contains functionality to inject code into remote processes
Creates a thread in another existing process (thread injection)
Deletes itself after installation
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Drops executables to the windows directory (C:\Windows) and starts them
Found evasive API chain (may stop execution after checking computer name)
Found evasive API chain (may stop execution after checking locale)
Found evasive API chain (may stop execution after checking mutex)
Found evasive API chain (may stop execution after reading information in the PEB, e.g. number of processors)
Found many strings related to Crypto-Wallets (likely being stolen)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Maps a DLL or memory area into another process
Modifies the windows firewall
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
PE file has nameless sections
Sigma detected: Copying Sensitive Files with Credential Data
Sigma detected: Suspect Svchost Activity
Sigma detected: Suspicious Svchost Process
Sigma detected: Suspicius Add Task From User AppData Temp
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Tries to evade analysis by execution special instruction which cause usermode exception
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses netsh to modify the Windows network and firewall settings
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Yara detected Amadeys stealer DLL
Yara detected Raccoon Stealer
Yara detected RedLine Stealer
Yara detected SmokeLoader
Yara detected Vidar stealer
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
553117
Sample:
zmbGUZTICp.exe
Startdate:
14/01/2022
Architecture:
WINDOWS
Score:
100
93
185.215.113.35, 49766, 49767, 49771
WHOLESALECONNECTIONSNL
Portugal
2->93
95
patmushta.info
2->95
97
microsoft-com.mail.protection.outlook.com
2->97
127
Snort IDS alert for
network traffic (e.g.
based on Emerging Threat
rules)
2->127
129
Multi AV Scanner detection
for domain / URL
2->129
131
Antivirus detection
for URL or domain
2->131
133
23 other signatures
2->133
11
zmbGUZTICp.exe
2->11
started
14
tejjnepq.exe
2->14
started
16
gdrgbdj
2->16
started
18
3 other processes
2->18
signatures3
process4
dnsIp5
167
Contains functionality
to inject code into
remote processes
11->167
169
Injects a PE file into
a foreign processes
11->169
21
zmbGUZTICp.exe
11->21
started
171
Detected unpacking (changes
PE section rights)
14->171
173
Detected unpacking (overwrites
its own PE header)
14->173
175
Writes to foreign memory
regions
14->175
177
Allocates memory in
foreign processes
14->177
24
svchost.exe
14->24
started
27
gdrgbdj
16->27
started
99
127.0.0.1
unknown
unknown
18->99
29
WerFault.exe
18->29
started
signatures6
process7
dnsIp8
157
Checks for kernel code
integrity (NtQuerySystemInformation(CodeIntegrityInformation))
21->157
159
Maps a DLL or memory
area into another process
21->159
161
Checks if the current
machine is a virtual
machine (disk enumeration)
21->161
31
explorer.exe
10
21->31
injected
103
microsoft-com.mail.protection.outlook.com
40.93.207.0, 25, 49726
MICROSOFT-CORP-MSN-AS-BLOCKUS
United States
24->103
105
patmushta.info
94.142.143.116, 443, 49728, 49778
IHOR-ASRU
Russian Federation
24->105
163
System process connects
to network (likely due
to code injection or
exploit)
24->163
165
Creates a thread in
another existing process
(thread injection)
27->165
signatures9
process10
dnsIp11
113
185.233.81.115, 443, 49703
SUPERSERVERSDATACENTERRU
Russian Federation
31->113
115
188.166.28.199, 80
DIGITALOCEAN-ASNUS
Netherlands
31->115
117
11 other IPs or domains
31->117
73
C:\Users\user\AppData\Roaming\gdrgbdj, PE32
31->73
dropped
75
C:\Users\user\AppData\Local\Temp\A7F0.exe, PE32
31->75
dropped
77
C:\Users\user\AppData\Local\Temp\3F71.exe, PE32
31->77
dropped
79
9 other files (7 malicious)
31->79
dropped
119
System process connects
to network (likely due
to code injection or
exploit)
31->119
121
Benign windows process
drops PE files
31->121
123
Deletes itself after
installation
31->123
125
Hides that the sample
has been downloaded
from the Internet (zone.identifier)
31->125
36
2DB3.exe
31->36
started
39
309C.exe
2
31->39
started
42
A7F0.exe
31->42
started
45
2 other processes
31->45
file12
signatures13
process14
dnsIp15
135
Detected unpacking (changes
PE section rights)
36->135
137
Detected unpacking (overwrites
its own PE header)
36->137
139
Found evasive API chain
(may stop execution
after checking mutex)
36->139
155
4 other signatures
36->155
81
C:\Users\user\AppData\Local\...\tejjnepq.exe, PE32
39->81
dropped
141
Machine Learning detection
for dropped file
39->141
143
Uses netsh to modify
the Windows network
and firewall settings
39->143
145
Modifies the windows
firewall
39->145
47
cmd.exe
1
39->47
started
50
cmd.exe
2
39->50
started
52
sc.exe
1
39->52
started
59
3 other processes
39->59
107
185.163.45.70, 80
MIVOCLOUDMD
Moldova Republic of
42->107
109
185.163.204.22, 49775, 80
CAUCASUS-CABLE-SYSTEMCCSAutonomousSystemGE
Germany
42->109
111
185.163.204.24, 49776, 80
CAUCASUS-CABLE-SYSTEMCCSAutonomousSystemGE
Germany
42->111
83
C:\Users\user\AppData\LocalLow\sqlite3.dll, PE32
42->83
dropped
85
C:\Users\user\AppData\...\vcruntime140.dll, PE32
42->85
dropped
87
C:\Users\user\AppData\...\ucrtbase.dll, PE32
42->87
dropped
89
15 other files (none is malicious)
42->89
dropped
147
Tries to steal Mail
credentials (via file
/ registry access)
42->147
149
Tries to harvest and
steal browser information
(history, passwords,
etc)
42->149
151
Antivirus detection
for dropped file
45->151
153
Injects a PE file into
a foreign processes
45->153
54
3F71.exe
45->54
started
57
WerFault.exe
20
9
45->57
started
file16
signatures17
process18
dnsIp19
91
C:\Windows\SysWOW64\...\tejjnepq.exe (copy), PE32
47->91
dropped
61
conhost.exe
47->61
started
63
conhost.exe
50->63
started
65
conhost.exe
52->65
started
101
86.107.197.138, 38133, 49764
MOD-EUNL
Romania
54->101
67
conhost.exe
59->67
started
69
conhost.exe
59->69
started
71
conhost.exe
59->71
started
file20
process21
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.