Threat name:
RedLine SmokeLoader Tofsee Vidar
Alert
Classification:
troj.spyw.evad
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code references suspicious native API functions
Antivirus detection for dropped file
Antivirus detection for URL or domain
Benign windows process drops PE files
Changes security center settings (notifications, updates, antivirus, firewall)
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Contains functionality to detect sleep reduction / modifications
Contains functionality to inject code into remote processes
Creates a thread in another existing process (thread injection)
Deletes itself after installation
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Found evasive API chain (may stop execution after checking computer name)
Found evasive API chain (may stop execution after checking locale)
Found evasive API chain (may stop execution after checking mutex)
Found evasive API chain (may stop execution after reading information in the PEB, e.g. number of processors)
Found many strings related to Crypto-Wallets (likely being stolen)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Maps a DLL or memory area into another process
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: Copying Sensitive Files with Credential Data
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Yara detected RedLine Stealer
Yara detected SmokeLoader
Yara detected Vidar stealer
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
553857
Sample:
6MmU91yK3F.exe
Startdate:
16/01/2022
Architecture:
WINDOWS
Score:
100
75
transfer.sh
2->75
77
host-data-coin-11.com
2->77
105
Snort IDS alert for
network traffic (e.g.
based on Emerging Threat
rules)
2->105
107
Multi AV Scanner detection
for domain / URL
2->107
109
Antivirus detection
for URL or domain
2->109
111
15 other signatures
2->111
11
6MmU91yK3F.exe
2->11
started
14
dsivjwe
2->14
started
16
svchost.exe
2->16
started
18
10 other processes
2->18
signatures3
process4
signatures5
121
Contains functionality
to inject code into
remote processes
11->121
123
Injects a PE file into
a foreign processes
11->123
20
6MmU91yK3F.exe
11->20
started
125
Machine Learning detection
for dropped file
14->125
23
dsivjwe
14->23
started
127
Changes security center
settings (notifications,
updates, antivirus,
firewall)
16->127
25
MpCmdRun.exe
16->25
started
process6
signatures7
113
Checks for kernel code
integrity (NtQuerySystemInformation(CodeIntegrityInformation))
20->113
115
Maps a DLL or memory
area into another process
20->115
117
Checks if the current
machine is a virtual
machine (disk enumeration)
20->117
27
explorer.exe
10
20->27
injected
119
Creates a thread in
another existing process
(thread injection)
23->119
32
conhost.exe
25->32
started
process8
dnsIp9
79
185.233.81.115, 443, 49790
SUPERSERVERSDATACENTERRU
Russian Federation
27->79
81
188.166.28.199, 80
DIGITALOCEAN-ASNUS
Netherlands
27->81
83
10 other IPs or domains
27->83
67
C:\Users\user\AppData\Roaming\dsivjwe, PE32
27->67
dropped
69
C:\Users\user\AppData\Local\Temp\FF6.exe, PE32
27->69
dropped
71
C:\Users\user\AppData\Local\Temp\F9CF.exe, PE32
27->71
dropped
73
9 other malicious files
27->73
dropped
129
System process connects
to network (likely due
to code injection or
exploit)
27->129
131
Benign windows process
drops PE files
27->131
133
Deletes itself after
installation
27->133
135
Hides that the sample
has been downloaded
from the Internet (zone.identifier)
27->135
34
566.exe
27->34
started
37
1892.exe
3
27->37
started
39
FF6.exe
2
27->39
started
42
3FB6.exe
27->42
started
file10
signatures11
process12
file13
87
Detected unpacking (changes
PE section rights)
34->87
89
Detected unpacking (overwrites
its own PE header)
34->89
91
Found evasive API chain
(may stop execution
after checking mutex)
34->91
103
4 other signatures
34->103
93
Antivirus detection
for dropped file
37->93
95
Multi AV Scanner detection
for dropped file
37->95
97
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
37->97
99
Queries sensitive disk
information (via WMI,
Win32_DiskDrive, often
done to detect virtual
machines)
37->99
44
1892.exe
37->44
started
65
C:\Users\user\AppData\Local\...\vctcqcvm.exe, PE32
39->65
dropped
101
Machine Learning detection
for dropped file
39->101
48
cmd.exe
39->48
started
51
cmd.exe
39->51
started
53
sc.exe
39->53
started
55
WerFault.exe
3
10
42->55
started
signatures14
process15
dnsIp16
85
92.255.111.23, 38134, 49882
CONTINENTAL_GROUP-ASRU
Russian Federation
44->85
137
Tries to harvest and
steal browser information
(history, passwords,
etc)
44->137
139
Tries to steal Crypto
Currency Wallets
44->139
63
C:\Windows\SysWOW64\...\vctcqcvm.exe (copy), PE32
48->63
dropped
57
conhost.exe
48->57
started
59
conhost.exe
51->59
started
61
conhost.exe
53->61
started
file17
signatures18
process19
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.