Threat name:
RedLine SmokeLoader Tofsee Vidar
Alert
Classification:
troj.spyw.evad
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
Antivirus detection for dropped file
Antivirus detection for URL or domain
Benign windows process drops PE files
Changes security center settings (notifications, updates, antivirus, firewall)
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Contains functionality to detect sleep reduction / modifications
Contains functionality to inject code into remote processes
Creates a thread in another existing process (thread injection)
Deletes itself after installation
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Found many strings related to Crypto-Wallets (likely being stolen)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Hides threads from debuggers
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Maps a DLL or memory area into another process
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses process hollowing technique
Sigma detected: Copying Sensitive Files with Credential Data
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to evade analysis by execution special instruction which cause usermode exception
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Yara detected RedLine Stealer
Yara detected SmokeLoader
Yara detected Vidar stealer
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
545202
Sample:
POWKlAddNj.exe
Startdate:
25/12/2021
Architecture:
WINDOWS
Score:
100
83
t.me
2->83
99
Snort IDS alert for
network traffic (e.g.
based on Emerging Threat
rules)
2->99
101
Multi AV Scanner detection
for domain / URL
2->101
103
Antivirus detection
for URL or domain
2->103
105
16 other signatures
2->105
11
POWKlAddNj.exe
2->11
started
14
tjigfca
2->14
started
16
svchost.exe
2->16
started
18
8 other processes
2->18
signatures3
process4
dnsIp5
141
Contains functionality
to inject code into
remote processes
11->141
143
Injects a PE file into
a foreign processes
11->143
21
POWKlAddNj.exe
11->21
started
145
Machine Learning detection
for dropped file
14->145
24
tjigfca
14->24
started
147
Changes security center
settings (notifications,
updates, antivirus,
firewall)
16->147
26
MpCmdRun.exe
16->26
started
85
192.168.2.1
unknown
unknown
18->85
signatures6
process7
signatures8
133
Checks for kernel code
integrity (NtQuerySystemInformation(CodeIntegrityInformation))
21->133
135
Maps a DLL or memory
area into another process
21->135
137
Checks if the current
machine is a virtual
machine (disk enumeration)
21->137
28
explorer.exe
14
21->28
injected
139
Creates a thread in
another existing process
(thread injection)
24->139
33
conhost.exe
26->33
started
process9
dnsIp10
93
host-data-coin-11.com
28->93
95
185.233.81.115, 443, 49769
SUPERSERVERSDATACENTERRU
Russian Federation
28->95
97
18 other IPs or domains
28->97
75
C:\Users\user\AppData\Roaming\tjigfca, PE32
28->75
dropped
77
C:\Users\user\AppData\Roaming\rjigfca, PE32
28->77
dropped
79
C:\Users\user\AppData\Local\Temp9B4.exe, PE32
28->79
dropped
81
11 other malicious files
28->81
dropped
149
System process connects
to network (likely due
to code injection or
exploit)
28->149
151
Benign windows process
drops PE files
28->151
153
Deletes itself after
installation
28->153
155
Hides that the sample
has been downloaded
from the Internet (zone.identifier)
28->155
35
D2DF.exe
5
28->35
started
39
5E23.exe
28->39
started
42
E9B4.exe
28->42
started
44
3 other processes
28->44
file11
signatures12
process13
dnsIp14
87
45.9.20.149, 49836, 7526
DEDIPATH-LLCUS
Russian Federation
35->87
107
Multi AV Scanner detection
for dropped file
35->107
109
Detected unpacking (changes
PE section rights)
35->109
111
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
35->111
127
3 other signatures
35->127
89
file-file-host4.com
39->89
69
C:\Users\user\AppData\...\sqlite3[1].dll, PE32
39->69
dropped
71
C:\ProgramData\sqlite3.dll, PE32
39->71
dropped
113
Detected unpacking (overwrites
its own PE header)
39->113
115
Machine Learning detection
for dropped file
39->115
117
Tries to harvest and
steal browser information
(history, passwords,
etc)
39->117
119
Contains functionality
to detect sleep reduction
/ modifications
39->119
46
cmd.exe
39->46
started
121
Checks for kernel code
integrity (NtQuerySystemInformation(CodeIntegrityInformation))
42->121
123
Maps a DLL or memory
area into another process
42->123
129
2 other signatures
42->129
91
2.56.59.98, 48767, 49863
GBTCLOUDUS
Netherlands
44->91
73
C:\Users\user\AppData\Local\...\ygoyazrp.exe, PE32
44->73
dropped
125
Tries to detect sandboxes
and other dynamic analysis
tools (window names)
44->125
131
3 other signatures
44->131
48
cmd.exe
44->48
started
51
cmd.exe
44->51
started
53
sc.exe
44->53
started
55
7CD8.exe
44->55
started
file15
signatures16
process17
file18
57
conhost.exe
46->57
started
59
timeout.exe
46->59
started
67
C:\Windows\SysWOW64\...\ygoyazrp.exe (copy), PE32
48->67
dropped
61
conhost.exe
48->61
started
63
conhost.exe
51->63
started
65
conhost.exe
53->65
started
process19
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.