MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc08aa33da827c3199f3f0345606b97b83bc508239c4c24f02a78d6e996bca09. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 11


Intelligence 11 IOCs YARA 3 File information Comments

SHA256 hash: dc08aa33da827c3199f3f0345606b97b83bc508239c4c24f02a78d6e996bca09
SHA3-384 hash: a35f8c152e280ff0a914fb79ee9c68367f3d8c00fff0806639184979d67abc7b6b5e5ad4d22384741099364f0a4cdfbe
SHA1 hash: 16b7a96e3c43e82ca962bd94ae1898f796c9cd00
MD5 hash: d57c5086ea166bc56e091761a43781ff
humanhash: hamper-eighteen-nitrogen-lemon
File name:SecuriteInfo.com.Trojan.DownLoader44.36703.22938.13598
Download: download sample
File size:1'894'520 bytes
First seen:2024-10-23 11:51:14 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 0ebb3c09b06b1666d307952e824c8697 (15 x RedLineStealer, 13 x LgoogLoader, 7 x NanoCore)
ssdeep 49152:QkcpPHMSx81aREdJOQp5+V7Mac3NL4V8tSBjETYH7nI90/6Rn:Qkc1HMSxfR03wFMa6L4ISB4Mnw0/6t
TLSH T16F95331292CA183FC8C23370A4E69B676B6C7C61264956A7E32F88E425311F5F47C76F
TrID 46.6% (.CPL) Windows Control Panel Item (generic) (57583/11/19)
25.2% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
8.5% (.EXE) Win64 Executable (generic) (10522/11/4)
5.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.0% (.EXE) Win16 NE executable (generic) (5038/12/1)
Magika pebin
File icon (PE):PE icon
dhash icon 848c5454baf47474 (2'466 x Adware.Neoreklami, 102 x RedLineStealer, 65 x N-able)
Reporter SecuriteInfoCom
Tags:exe signed

Code Signing Certificate

Organisation:Knowhow Electel Inc.
Issuer:DigiCert EV Code Signing CA (SHA2)
Algorithm:sha256WithRSAEncryption
Valid from:2021-02-23T00:00:00Z
Valid to:2024-02-12T23:59:59Z
Serial number: 072d97eebca5557ea62617208c28cb0a
Intelligence: 3 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: 63906a4702715f4a713f2c321577718d8ea438609c3253ad92e352fe826823ba
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
407
Origin country :
FR FR
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
SecuriteInfo.com.Trojan.DownLoader44.36703.22938.13598
Verdict:
Malicious activity
Analysis date:
2024-10-23 11:53:50 UTC
Tags:
adware upx

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
Powershell Dridex
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Creating a process with a hidden window
Creating a window
Creating a file in the Program Files subdirectories
Сreating synchronization primitives
DNS request
Connection attempt
Sending an HTTP GET request
Launching a process
Searching for synchronization primitives
Searching for the window
Firewall traversal
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
advpack CAB fingerprint greyware installer keylogger lolbin microsoft_visual_cc overlay packed packed packed packer_detected rijndael rundll32 setupapi sfx shell32
Result
Threat name:
n/a
Detection:
malicious
Classification:
rans.evad
Score:
54 / 100
Signature
Contains functionality to automate explorer (e.g. start an application)
Contains functionalty to change the wallpaper
Creates HTML files with .exe extension (expired dropper behavior)
Found stalling execution ending in API Sleep call
Modifies the windows firewall
Suricata IDS alerts for network traffic
Uses ipconfig to lookup or modify the Windows network settings
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  10/10
Tags:
discovery evasion persistence trojan upx
Behaviour
Gathers network information
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
System policy modification
Checks whether UAC is enabled
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Executes dropped EXE
Loads dropped DLL
Checks computer location settings
UPX packed file
Adds Run key to start application
Modifies firewall policy service
Verdict:
Malicious
Tags:
stealer redline
YARA:
detect_Redline_Stealer
Unpacked files
SH256 hash:
ee6b2572c71c29ad79eb965f196b52c6a2b8054618340a802a42380a3c0e2662
MD5 hash:
e55e10753a0aa4732f564a477cd07e98
SHA1 hash:
d9869f15b07404ec7218afd2e686e42a5bba6133
SH256 hash:
cb5ca829c2e7422b34009e39f2151bd405418e52f05b0b8521dc652889b10437
MD5 hash:
8809f53ab58b2bb962aef51bd4ccebad
SHA1 hash:
54dd3320f1ed478eccf7f7c60c523a8304c0f2ac
SH256 hash:
4d7093e117fddcc870158cfaf3b1fef1a4498dfc8462970d90c04084a7b3ee7e
MD5 hash:
2db15317058a354950bd20ec823ab76d
SHA1 hash:
98fc6852179de6ae8bd39925703c7302777bb35d
SH256 hash:
357585f8529a7940bbd4cace7e2bc190596a7a7fc4108506f7e3c18e16aa7372
MD5 hash:
2be5d08f39770fcaadb056f0f900ae7b
SHA1 hash:
92877f2c12bee74072544784267292abf86d5bb1
SH256 hash:
30655bef90bc9ba7c6fa2c5b6b13101aed8d665e71a7bef1324f67e3a227d18c
MD5 hash:
339e47b851c1c4a61ffa73f17c8290c6
SHA1 hash:
6735d77786109d3cf29b1c20fd36d120ab11adec
SH256 hash:
dc08aa33da827c3199f3f0345606b97b83bc508239c4c24f02a78d6e996bca09
MD5 hash:
d57c5086ea166bc56e091761a43781ff
SHA1 hash:
16b7a96e3c43e82ca962bd94ae1898f796c9cd00
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_Redline_Stealer
Author:Varp0s
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe dc08aa33da827c3199f3f0345606b97b83bc508239c4c24f02a78d6e996bca09

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
CHECK_TRUST_INFORequires Elevated Execution (level:requireAdministrator)high
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User AuthorizationADVAPI32.dll::AllocateAndInitializeSid
ADVAPI32.dll::EqualSid
ADVAPI32.dll::FreeSid
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::AdjustTokenPrivileges
ADVAPI32.dll::GetTokenInformation
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CreateProcessA
ADVAPI32.dll::OpenProcessToken
KERNEL32.dll::CloseHandle
KERNEL32.dll::CreateThread
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryExA
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::GetDriveTypeA
KERNEL32.dll::GetVolumeInformationA
KERNEL32.dll::GetSystemInfo
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateDirectoryA
KERNEL32.dll::CreateFileA
KERNEL32.dll::DeleteFileA
KERNEL32.dll::GetWindowsDirectoryA
KERNEL32.dll::GetSystemDirectoryA
KERNEL32.dll::GetFileAttributesA
WIN_BASE_USER_APIRetrieves Account InformationADVAPI32.dll::LookupPrivilegeValueA
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegCreateKeyExA
ADVAPI32.dll::RegOpenKeyExA
ADVAPI32.dll::RegQueryInfoKeyA
ADVAPI32.dll::RegQueryValueExA
ADVAPI32.dll::RegSetValueExA
WIN_USER_APIPerforms GUI ActionsUSER32.dll::PeekMessageA

Comments