Threat name:
Raccoon RedLine SmokeLoader Tofsee
Alert
Classification:
troj.spyw.evad
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains very large array initializations
.NET source code references suspicious native API functions
Antivirus detection for dropped file
Benign windows process drops PE files
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Contains functionality to inject code into remote processes
Creates a thread in another existing process (thread injection)
Deletes itself after installation
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Drops executables to the windows directory (C:\Windows) and starts them
Found many strings related to Crypto-Wallets (likely being stolen)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Hides threads from debuggers
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Maps a DLL or memory area into another process
Modifies the windows firewall
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Performs DNS queries to domains with low reputation
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Sigma detected: Copying Sensitive Files with Credential Data
Sigma detected: Suspect Svchost Activity
Sigma detected: Suspicious Svchost Process
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Uses known network protocols on non-standard ports
Uses netsh to modify the Windows network and firewall settings
Yara detected Raccoon Stealer
Yara detected RedLine Stealer
Yara detected SmokeLoader
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
493916
Sample:
YjAp3izhE6.exe
Startdate:
30/09/2021
Architecture:
WINDOWS
Score:
100
82
91.219.236.162, 49874, 80
SERVERASTRA-ASHU
Hungary
2->82
84
t.me
149.154.167.99, 443, 49872
TELEGRAMRU
United Kingdom
2->84
86
4 other IPs or domains
2->86
132
Snort IDS alert for
network traffic (e.g.
based on Emerging Threat
rules)
2->132
134
System process connects
to network (likely due
to code injection or
exploit)
2->134
136
Multi AV Scanner detection
for submitted file
2->136
138
17 other signatures
2->138
11
YjAp3izhE6.exe
2->11
started
14
ejsifsd
2->14
started
16
svchost.exe
1
2->16
started
18
3 other processes
2->18
signatures3
process4
signatures5
164
Detected unpacking (changes
PE section rights)
11->164
166
Contains functionality
to inject code into
remote processes
11->166
168
Injects a PE file into
a foreign processes
11->168
20
YjAp3izhE6.exe
11->20
started
170
Multi AV Scanner detection
for dropped file
14->170
23
ejsifsd
14->23
started
process6
signatures7
140
Checks for kernel code
integrity (NtQuerySystemInformation(CodeIntegrityInformation))
20->140
142
Maps a DLL or memory
area into another process
20->142
144
Checks if the current
machine is a virtual
machine (disk enumeration)
20->144
25
explorer.exe
12
20->25
injected
146
Creates a thread in
another existing process
(thread injection)
23->146
process8
dnsIp9
88
193.56.146.41, 49833, 9080
LVLT-10753US
unknown
25->88
90
216.128.137.31, 80
AS-CHOOPAUS
United States
25->90
92
3 other IPs or domains
25->92
68
C:\Users\user\AppData\Roaming\ejsifsd, PE32
25->68
dropped
70
C:\Users\user\AppData\Local\Temp\FA5F.exe, PE32
25->70
dropped
72
C:\Users\user\AppData\Local\Temp\F34A.exe, PE32
25->72
dropped
74
4 other malicious files
25->74
dropped
172
System process connects
to network (likely due
to code injection or
exploit)
25->172
174
Benign windows process
drops PE files
25->174
176
Deletes itself after
installation
25->176
178
Hides that the sample
has been downloaded
from the Internet (zone.identifier)
25->178
30
BCBF.exe
15
6
25->30
started
35
F34A.exe
25->35
started
37
5DAD.exe
25->37
started
39
2 other processes
25->39
file10
signatures11
process12
dnsIp13
104
ipapi.co
104.26.8.44, 443, 49834, 49852
CLOUDFLARENETUS
United States
30->104
76
C:\Users\user\AppData\Roaming\BCBF.exe, PE32
30->76
dropped
106
Antivirus detection
for dropped file
30->106
108
Multi AV Scanner detection
for dropped file
30->108
110
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
30->110
128
2 other signatures
30->128
41
BCBF.exe
30->41
started
112
Detected unpacking (changes
PE section rights)
35->112
114
Machine Learning detection
for dropped file
35->114
116
Injects a PE file into
a foreign processes
35->116
45
F34A.exe
35->45
started
78
C:\Users\user\AppData\Local\...\vlllarxp.exe, PE32
37->78
dropped
118
Detected unpacking (overwrites
its own PE header)
37->118
120
Uses netsh to modify
the Windows network
and firewall settings
37->120
122
Modifies the windows
firewall
37->122
47
cmd.exe
37->47
started
50
cmd.exe
37->50
started
52
sc.exe
37->52
started
54
sc.exe
37->54
started
124
Query firmware table
information (likely
to detect VMs)
39->124
126
Tries to detect sandboxes
and other dynamic analysis
tools (window names)
39->126
130
2 other signatures
39->130
56
FA5F.exe
14
2
39->56
started
58
conhost.exe
39->58
started
60
conhost.exe
39->60
started
file14
signatures15
process16
dnsIp17
94
185.203.242.21, 49877, 80
ON-LINE-DATAServerlocation-NetherlandsDrontenNL
Ukraine
41->94
96
ipapi.co
41->96
98
100.99.0.0.in-addr.arpa
41->98
148
Antivirus detection
for dropped file
41->148
150
Multi AV Scanner detection
for dropped file
41->150
152
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
41->152
162
5 other signatures
41->162
154
Checks for kernel code
integrity (NtQuerySystemInformation(CodeIntegrityInformation))
45->154
156
Maps a DLL or memory
area into another process
45->156
158
Checks if the current
machine is a virtual
machine (disk enumeration)
45->158
160
Creates a thread in
another existing process
(thread injection)
45->160
80
C:\Windows\SysWOW64\...\vlllarxp.exe (copy), PE32
47->80
dropped
62
conhost.exe
47->62
started
64
conhost.exe
50->64
started
66
conhost.exe
52->66
started
100
188.72.208.174, 38430, 49875
WEBZILLANL
Netherlands
56->100
102
api.ip.sb
56->102
file18
signatures19
process20
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.