Threat name:
RedLine SmokeLoader Tofsee Vidar
Alert
Classification:
troj.spyw.evad
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
Benign windows process drops PE files
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Contains functionality to detect sleep reduction / modifications
Contains functionality to inject code into remote processes
Creates a thread in another existing process (thread injection)
Deletes itself after installation
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Drops executables to the windows directory (C:\Windows) and starts them
Found evasive API chain (may stop execution after checking computer name)
Found evasive API chain (may stop execution after checking locale)
Found evasive API chain (may stop execution after checking mutex)
Found evasive API chain (may stop execution after reading information in the PEB, e.g. number of processors)
Found many strings related to Crypto-Wallets (likely being stolen)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Maps a DLL or memory area into another process
Modifies the windows firewall
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Performs DNS queries to domains with low reputation
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: Copying Sensitive Files with Credential Data
Sigma detected: Suspect Svchost Activity
Sigma detected: Suspicious Svchost Process
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Uses netsh to modify the Windows network and firewall settings
Uses the Telegram API (likely for C&C communication)
Writes to foreign memory regions
Yara detected RedLine Stealer
Yara detected SmokeLoader
Yara detected Vidar stealer
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
553418
Sample:
xy4V0UyNNa.exe
Startdate:
14/01/2022
Architecture:
WINDOWS
Score:
100
83
transfer.sh
2->83
85
patmushta.info
2->85
87
7 other IPs or domains
2->87
111
Snort IDS alert for
network traffic (e.g.
based on Emerging Threat
rules)
2->111
113
Multi AV Scanner detection
for domain / URL
2->113
115
Antivirus detection
for URL or domain
2->115
117
21 other signatures
2->117
11
xy4V0UyNNa.exe
2->11
started
14
lnagngtg.exe
2->14
started
16
jcewded
2->16
started
18
5 other processes
2->18
signatures3
process4
dnsIp5
151
Contains functionality
to inject code into
remote processes
11->151
153
Injects a PE file into
a foreign processes
11->153
21
xy4V0UyNNa.exe
11->21
started
155
Detected unpacking (changes
PE section rights)
14->155
157
Detected unpacking (overwrites
its own PE header)
14->157
159
Writes to foreign memory
regions
14->159
161
Allocates memory in
foreign processes
14->161
24
svchost.exe
14->24
started
163
Machine Learning detection
for dropped file
16->163
27
jcewded
16->27
started
89
192.168.2.1
unknown
unknown
18->89
29
WerFault.exe
18->29
started
signatures6
process7
dnsIp8
141
Checks for kernel code
integrity (NtQuerySystemInformation(CodeIntegrityInformation))
21->141
143
Maps a DLL or memory
area into another process
21->143
145
Checks if the current
machine is a virtual
machine (disk enumeration)
21->145
31
explorer.exe
10
21->31
injected
91
microsoft-com.mail.protection.outlook.com
52.101.24.0, 25, 49850
MICROSOFT-CORP-MSN-AS-BLOCKUS
United States
24->91
93
patmushta.info
94.142.143.116, 443, 49862
IHOR-ASRU
Russian Federation
24->93
147
System process connects
to network (likely due
to code injection or
exploit)
24->147
149
Creates a thread in
another existing process
(thread injection)
27->149
signatures9
process10
dnsIp11
97
185.233.81.115, 443, 49768
SUPERSERVERSDATACENTERRU
Russian Federation
31->97
99
188.166.28.199, 80
DIGITALOCEAN-ASNUS
Netherlands
31->99
101
9 other IPs or domains
31->101
71
C:\Users\user\AppData\Roaming\jcewded, PE32
31->71
dropped
73
C:\Users\user\AppData\Local\Temp\F5CD.exe, PE32
31->73
dropped
75
C:\Users\user\AppData\Local\Temp\F377.exe, PE32
31->75
dropped
77
12 other malicious files
31->77
dropped
103
System process connects
to network (likely due
to code injection or
exploit)
31->103
105
Benign windows process
drops PE files
31->105
107
Deletes itself after
installation
31->107
109
Hides that the sample
has been downloaded
from the Internet (zone.identifier)
31->109
36
F377.exe
3
31->36
started
39
55A1.exe
31->39
started
41
EA4E.exe
2
31->41
started
44
2 other processes
31->44
file12
signatures13
process14
file15
119
Antivirus detection
for dropped file
36->119
121
Multi AV Scanner detection
for dropped file
36->121
123
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
36->123
137
2 other signatures
36->137
46
F377.exe
2
36->46
started
125
Detected unpacking (changes
PE section rights)
39->125
127
Detected unpacking (overwrites
its own PE header)
39->127
129
Found evasive API chain
(may stop execution
after checking mutex)
39->129
139
4 other signatures
39->139
81
C:\Users\user\AppData\Local\...\lnagngtg.exe, PE32
41->81
dropped
131
Machine Learning detection
for dropped file
41->131
133
Uses netsh to modify
the Windows network
and firewall settings
41->133
135
Modifies the windows
firewall
41->135
50
cmd.exe
1
41->50
started
53
cmd.exe
2
41->53
started
55
sc.exe
41->55
started
59
2 other processes
41->59
57
WerFault.exe
3
10
44->57
started
signatures16
process17
dnsIp18
95
86.107.197.138, 38133, 49875
MOD-EUNL
Romania
46->95
165
Tries to harvest and
steal browser information
(history, passwords,
etc)
46->165
167
Tries to steal Crypto
Currency Wallets
46->167
79
C:\Windows\SysWOW64\...\lnagngtg.exe (copy), PE32
50->79
dropped
61
conhost.exe
50->61
started
63
conhost.exe
53->63
started
65
conhost.exe
55->65
started
67
conhost.exe
59->67
started
69
conhost.exe
59->69
started
file19
signatures20
process21
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.