Threat name:
Raccoon RedLine SmokeLoader Zeppelin
Alert
Classification:
rans.troj.spyw.evad
.NET source code contains method to dynamically call methods (often used by packers)
Allocates memory in foreign processes
Antivirus detection for URL or domain
Benign windows process drops PE files
C2 URLs / IPs found in malware configuration
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Connects to many ports of the same IP (likely port scanning)
Contains functionality to inject threads in other processes
Contains functionality to steal Internet Explorer form passwords
Creates a thread in another existing process (thread injection)
Deletes itself after installation
Deletes shadow drive data (may be related to ransomware)
Detected unpacking (changes PE section rights)
Drops PE files with benign system names
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Hides threads from debuggers
Injects code into the Windows Explorer (explorer.exe)
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
May check the online IP address of the machine
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
PE file contains section with special chars
PE file has nameless sections
Performs DNS queries to domains with low reputation
Query firmware table information (likely to detect VMs)
Sigma detected: System File Execution Location Anomaly
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file access)
Writes to foreign memory regions
Yara detected Raccoon Stealer
Yara detected RansomwareGeneric
Yara detected RedLine Stealer
Yara detected SmokeLoader
Yara detected Zeppelin Ransomware
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
473458
Sample:
sG41vsm1Pe.exe
Startdate:
29/08/2021
Architecture:
WINDOWS
Score:
100
64
www.geodatatool.com
2->64
66
geoiptool.com
2->66
102
Multi AV Scanner detection
for domain / URL
2->102
104
Found malware configuration
2->104
106
Malicious sample detected
(through community Yara
rule)
2->106
108
16 other signatures
2->108
10
sG41vsm1Pe.exe
2->10
started
13
hgswsbg
2->13
started
15
hgswsbg
2->15
started
signatures3
process4
signatures5
116
Detected unpacking (changes
PE section rights)
10->116
17
sG41vsm1Pe.exe
10->17
started
118
Multi AV Scanner detection
for dropped file
13->118
120
Machine Learning detection
for dropped file
13->120
20
hgswsbg
13->20
started
22
hgswsbg
15->22
started
process6
signatures7
94
Checks for kernel code
integrity (NtQuerySystemInformation(CodeIntegrityInformation))
17->94
96
Maps a DLL or memory
area into another process
17->96
98
Checks if the current
machine is a virtual
machine (disk enumeration)
17->98
24
explorer.exe
15
17->24
injected
100
Creates a thread in
another existing process
(thread injection)
20->100
process8
dnsIp9
68
185.49.70.90, 2080
LEASEWEB-DE-FRA-10DE
United Kingdom
24->68
70
readinglistforaugust2.xyz
95.213.224.6, 49733, 80
SELECTELRU
Russian Federation
24->70
72
8 other IPs or domains
24->72
52
C:\Users\user\AppData\Roaming\hgswsbg, PE32
24->52
dropped
54
C:\Users\user\AppData\Local\Temp\F8C8.exe, PE32
24->54
dropped
56
C:\Users\user\AppData\Local\Temp\91AD.exe, PE32
24->56
dropped
58
5 other malicious files
24->58
dropped
122
System process connects
to network (likely due
to code injection or
exploit)
24->122
124
Benign windows process
drops PE files
24->124
126
Performs DNS queries
to domains with low
reputation
24->126
128
4 other signatures
24->128
29
11FF.exe
2
17
24->29
started
34
481.exe
15
3
24->34
started
36
explorer.exe
24->36
started
38
12 other processes
24->38
file10
signatures11
process12
dnsIp13
80
www.geodatatool.com
158.69.65.151, 443, 49746, 49747
OVHFR
Canada
29->80
82
geoiptool.com
29->82
60
C:\Users\user\AppData\Roaming\...\lsass.exe, PE32
29->60
dropped
130
Multi AV Scanner detection
for dropped file
29->130
132
May check the online
IP address of the machine
29->132
134
Machine Learning detection
for dropped file
29->134
150
5 other signatures
29->150
40
lsass.exe
29->40
started
44
notepad.exe
29->44
started
84
136.243.65.8, 48715, 49767
HETZNER-ASDE
Germany
34->84
136
Detected unpacking (changes
PE section rights)
34->136
138
Query firmware table
information (likely
to detect VMs)
34->138
140
Tries to detect sandboxes
and other dynamic analysis
tools (window names)
34->140
152
2 other signatures
34->152
46
conhost.exe
34->46
started
86
readinglistforaugust7.xyz
36->86
142
System process connects
to network (likely due
to code injection or
exploit)
36->142
144
Tries to harvest and
steal Putty / WinSCP
information (sessions,
passwords, etc)
36->144
146
Tries to steal Mail
credentials (via file
access)
36->146
148
Performs DNS queries
to domains with low
reputation
36->148
88
geoiptool.com
38->88
90
5.181.156.252, 49768, 80
MIVOCLOUDMD
Moldova Republic of
38->90
92
telete.in
195.201.225.248, 443, 49766
HETZNER-ASDE
Germany
38->92
62
C:\Users\user\AppData\LocalLow\sqlite3.dll, PE32
38->62
dropped
154
2 other signatures
38->154
48
WerFault.exe
20
9
38->48
started
50
WerFault.exe
38->50
started
file14
signatures15
process16
dnsIp17
74
iplogger.org
88.99.66.31, 443, 49759, 49760
HETZNER-ASDE
Germany
40->74
76
www.geodatatool.com
40->76
78
geoiptool.com
40->78
110
Multi AV Scanner detection
for dropped file
40->110
112
May check the online
IP address of the machine
40->112
114
Machine Learning detection
for dropped file
40->114
signatures18
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.