Threat name:
Raccoon SmokeLoader Tofsee Vidar Xmrig
Alert
Classification:
spre.troj.spyw.evad.mine
Allocates memory in foreign processes
Antivirus detection for dropped file
Benign windows process drops PE files
Binary or sample is protected by dotNetProtector
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Contains functionality to inject code into remote processes
Contains functionality to steal Internet Explorer form passwords
Creates a thread in another existing process (thread injection)
Creates files in alternative data streams (ADS)
Deletes itself after installation
Detected Stratum mining protocol
Detected unpacking (changes PE section rights)
Drops executables to the windows directory (C:\Windows) and starts them
Found strings related to Crypto-Mining
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
May check the online IP address of the machine
Modifies the windows firewall
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Performs DNS queries to domains with low reputation
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Send many emails (e-Mail Spam)
Sigma detected: Copying Sensitive Files with Credential Data
Sigma detected: Suspect Svchost Activity
Sigma detected: Suspicious Svchost Process
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
System process connects to network (likely due to code injection or exploit)
Tries to delay execution (extensive OutputDebugStringW loop)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to resolve many domain names, but no domain seems valid
Tries to steal Crypto Currency Wallets
Tries to steal Mail credentials (via file access)
Uses netsh to modify the Windows network and firewall settings
Writes to foreign memory regions
Yara detected Raccoon Stealer
Yara detected SmokeLoader
Yara detected Vidar stealer
Yara detected Xmrig cryptocurrency miner
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
474107
Sample:
La60esvnOK.exe
Startdate:
30/08/2021
Architecture:
WINDOWS
Score:
100
129
www.instagram.com
2->129
131
srokmooeqn.com
2->131
133
44 other IPs or domains
2->133
155
Snort IDS alert for
network traffic (e.g.
based on Emerging Threat
rules)
2->155
157
Sigma detected: Xmrig
2->157
159
Multi AV Scanner detection
for domain / URL
2->159
165
19 other signatures
2->165
11
La60esvnOK.exe
2->11
started
14
ynawiham.exe
2->14
started
16
fhhuvis
2->16
started
18
5 other processes
2->18
signatures3
161
Tries to resolve many
domain names, but no
domain seems valid
129->161
163
System process connects
to network (likely due
to code injection or
exploit)
131->163
process4
signatures5
199
Detected unpacking (changes
PE section rights)
11->199
201
Contains functionality
to inject code into
remote processes
11->201
203
Injects a PE file into
a foreign processes
11->203
20
La60esvnOK.exe
11->20
started
205
Writes to foreign memory
regions
14->205
207
Allocates memory in
foreign processes
14->207
23
svchost.exe
14->23
started
27
fhhuvis
16->27
started
29
WerFault.exe
18->29
started
31
WerFault.exe
18->31
started
33
WerFault.exe
18->33
started
process6
dnsIp7
167
Checks for kernel code
integrity (NtQuerySystemInformation(CodeIntegrityInformation))
20->167
169
Maps a DLL or memory
area into another process
20->169
171
Checks if the current
machine is a virtual
machine (disk enumeration)
20->171
35
explorer.exe
15
20->35
injected
143
95.216.195.92, 419, 49740, 49767
HETZNER-ASDE
Germany
23->143
145
www.leroymerlin.fr
23->145
147
73 other IPs or domains
23->147
99
C:\Windows\SysWOW64\...\systemprofile:.repos, data
23->99
dropped
173
System process connects
to network (likely due
to code injection or
exploit)
23->173
175
Creates files in alternative
data streams (ADS)
23->175
177
Performs DNS queries
to domains with low
reputation
23->177
179
Injects a PE file into
a foreign processes
23->179
40
svchost.exe
23->40
started
181
Creates a thread in
another existing process
(thread injection)
27->181
file8
183
Detected Stratum mining
protocol
143->183
signatures9
process10
dnsIp11
135
readinglistforaugust8.xyz
35->135
137
readinglistforaugust7.xyz
35->137
141
10 other IPs or domains
35->141
91
C:\Users\user\AppData\Roaming\fhhuvis, PE32
35->91
dropped
93
C:\Users\user\AppData\Local\Temp\FE1B.exe, PE32
35->93
dropped
95
C:\Users\user\AppData\Local\Temp\FC9E.exe, PE32
35->95
dropped
97
5 other files (4 malicious)
35->97
dropped
185
System process connects
to network (likely due
to code injection or
exploit)
35->185
187
Benign windows process
drops PE files
35->187
189
Performs DNS queries
to domains with low
reputation
35->189
193
4 other signatures
35->193
42
426.exe
2
35->42
started
46
FC9E.exe
35->46
started
48
explorer.exe
35->48
started
53
8 other processes
35->53
139
fastpool.xyz
213.91.128.133, 10060, 49814
BTC-ASBULGARIABG
Bulgaria
40->139
51
conhost.exe
40->51
started
file12
191
Tries to resolve many
domain names, but no
domain seems valid
137->191
signatures13
process14
dnsIp15
111
C:\Users\user\AppData\Local\...\ynawiham.exe, PE32
42->111
dropped
209
Detected unpacking (changes
PE section rights)
42->209
211
Machine Learning detection
for dropped file
42->211
213
Uses netsh to modify
the Windows network
and firewall settings
42->213
215
Modifies the windows
firewall
42->215
55
cmd.exe
42->55
started
57
cmd.exe
42->57
started
60
sc.exe
42->60
started
70
3 other processes
42->70
217
Writes to foreign memory
regions
46->217
231
2 other signatures
46->231
62
RegSvcs.exe
46->62
started
121
readinglistforaugust8.xyz
48->121
219
System process connects
to network (likely due
to code injection or
exploit)
48->219
221
Tries to harvest and
steal Putty / WinSCP
information (sessions,
passwords, etc)
48->221
223
Tries to steal Mail
credentials (via file
access)
48->223
123
www.google.com
53->123
125
193.38.54.196
SERVERIUS-ASNL
Russian Federation
53->125
127
4 other IPs or domains
53->127
113
unknown (copy), SQLite
53->113
dropped
115
C:\Users\user\AppData\...\sqlite3[1].dll, PE32
53->115
dropped
117
C:\Users\user\AppData\LocalLow\sqlite3.dll, PE32
53->117
dropped
119
C:\ProgramData\sqlite3.dll, PE32
53->119
dropped
225
Contains functionality
to steal Internet Explorer
form passwords
53->225
227
Tries to harvest and
steal browser information
(history, passwords,
etc)
53->227
233
2 other signatures
53->233
66
cmd.exe
53->66
started
68
WerFault.exe
53->68
started
file16
229
Performs DNS queries
to domains with low
reputation
123->229
signatures17
process18
dnsIp19
72
conhost.exe
55->72
started
101
C:\Windows\SysWOW64\...\ynawiham.exe (copy), PE32
57->101
dropped
75
conhost.exe
57->75
started
77
conhost.exe
60->77
started
149
iplogger.org
88.99.66.31, 443, 49751, 49752
HETZNER-ASDE
Germany
62->149
151
bitbucket.org
104.192.141.1, 443, 49795
AMAZON-02US
United States
62->151
153
3 other IPs or domains
62->153
103
C:\ProgramData\Systemd\xmrig.exe, PE32+
62->103
dropped
105
C:\ProgramData\Systemd\old.exe (copy), PE32+
62->105
dropped
107
C:\ProgramData\Data\old.exe (copy), PE32+
62->107
dropped
109
2 other files (1 malicious)
62->109
dropped
235
May check the online
IP address of the machine
62->235
79
conhost.exe
62->79
started
81
conhost.exe
66->81
started
83
timeout.exe
66->83
started
85
conhost.exe
70->85
started
87
conhost.exe
70->87
started
89
conhost.exe
70->89
started
file20
signatures21
process22
signatures23
195
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
72->195
197
Queries sensitive disk
information (via WMI,
Win32_DiskDrive, often
done to detect virtual
machines)
72->197
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.