Analysis

  • max time kernel
    122s
  • max time network
    123s
  • platform
    windows7_x64
  • resource
    win7-20240220-en
  • resource tags

    arch:x64arch:x86image:win7-20240220-enlocale:en-usos:windows7-x64system
  • submitted
    24-06-2024 13:56

General

  • Target

    47278783745b4d089155c06c75a660fb.exe

  • Size

    505KB

  • MD5

    47278783745b4d089155c06c75a660fb

  • SHA1

    d79a6323b88953da2a794e76cb80c855f6bbedc9

  • SHA256

    66fcfbb25cb0e50b4cd85852ef21ddbf36e4c19a36cffef9e5f3e22c04b4290f

  • SHA512

    0d26598b717cac1b8de6432ed6c933b85b36da06cbaf2ddc06d52f7bb80dcb931850a18c6c87c02b173c024be60b4a9c83573c9368fea3ac482e2325f390c777

  • SSDEEP

    12288:zhMnv8pgJhX7ZspQ6Izq08jG5iBk8BJAzlHJkR:S7H7zq1jGUFBepU

Malware Config

Extracted

Family

redline

Botnet

cheat

C2

185.222.58.70:55615

Signatures

  • RedLine

    RedLine Stealer is a malware family written in C#, first appearing in early 2020.

  • RedLine payload 5 IoCs
  • SectopRAT

    SectopRAT is a remote access trojan first seen in November 2019.

  • SectopRAT payload 5 IoCs
  • Command and Scripting Interpreter: PowerShell 1 TTPs 2 IoCs

    Run Powershell to modify Windows Defender settings to add exclusions for file extensions, paths, and processes.

  • Reads user/profile data of web browsers 2 TTPs

    Infostealers often target stored browser data, which can include saved credentials etc.

  • Accesses cryptocurrency files/wallets, possible credential harvesting 2 TTPs
  • Checks installed software on the system 1 TTPs

    Looks up Uninstall key entries in the registry to enumerate software on the system.

  • Suspicious use of SetThreadContext 1 IoCs
  • Enumerates physical storage devices 1 TTPs

    Attempts to interact with connected storage/optical drive(s).

  • Modifies system certificate store 2 TTPs 6 IoCs
  • Scheduled Task/Job: Scheduled Task 1 TTPs 1 IoCs

    Schtasks is often used by malware for persistence or to perform post-infection execution.

  • Suspicious behavior: EnumeratesProcesses 8 IoCs
  • Suspicious use of AdjustPrivilegeToken 4 IoCs
  • Suspicious use of WriteProcessMemory 21 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\47278783745b4d089155c06c75a660fb.exe
    "C:\Users\Admin\AppData\Local\Temp\47278783745b4d089155c06c75a660fb.exe"
    1⤵
    • Suspicious use of SetThreadContext
    • Suspicious behavior: EnumeratesProcesses
    • Suspicious use of AdjustPrivilegeToken
    • Suspicious use of WriteProcessMemory
    PID:3056
    • C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
      "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\Admin\AppData\Local\Temp\47278783745b4d089155c06c75a660fb.exe"
      2⤵
      • Command and Scripting Interpreter: PowerShell
      • Suspicious behavior: EnumeratesProcesses
      • Suspicious use of AdjustPrivilegeToken
      PID:2576
    • C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
      "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\Admin\AppData\Roaming\zrmQDTlZlh.exe"
      2⤵
      • Command and Scripting Interpreter: PowerShell
      • Suspicious behavior: EnumeratesProcesses
      • Suspicious use of AdjustPrivilegeToken
      PID:2584
    • C:\Windows\SysWOW64\schtasks.exe
      "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\zrmQDTlZlh" /XML "C:\Users\Admin\AppData\Local\Temp\tmp474D.tmp"
      2⤵
      • Scheduled Task/Job: Scheduled Task
      PID:2720
    • C:\Users\Admin\AppData\Local\Temp\47278783745b4d089155c06c75a660fb.exe
      "C:\Users\Admin\AppData\Local\Temp\47278783745b4d089155c06c75a660fb.exe"
      2⤵
      • Modifies system certificate store
      • Suspicious behavior: EnumeratesProcesses
      • Suspicious use of AdjustPrivilegeToken
      PID:2148

Network

MITRE ATT&CK Matrix ATT&CK v13

Execution

Command and Scripting Interpreter

1
T1059

PowerShell

1
T1059.001

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Persistence

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Privilege Escalation

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Defense Evasion

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Credential Access

Unsecured Credentials

2
T1552

Credentials In Files

2
T1552.001

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Collection

Data from Local System

2
T1005

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
    Filesize

    70KB

    MD5

    49aebf8cbd62d92ac215b2923fb1b9f5

    SHA1

    1723be06719828dda65ad804298d0431f6aff976

    SHA256

    b33efcb95235b98b48508e019afa4b7655e80cf071defabd8b2123fc8b29307f

    SHA512

    bf86116b015fb56709516d686e168e7c9c68365136231cc51d0b6542ae95323a71d2c7acec84aad7dcecc2e410843f6d82a0a6d51b9acfc721a9c84fdd877b5b

  • C:\Users\Admin\AppData\Local\Temp\Cab6B53.tmp
    Filesize

    65KB

    MD5

    ac05d27423a85adc1622c714f2cb6184

    SHA1

    b0fe2b1abddb97837ea0195be70ab2ff14d43198

    SHA256

    c6456e12e5e53287a547af4103e0397cb9697e466cf75844312dc296d43d144d

    SHA512

    6d0ef9050e41fbae680e0e59dd0f90b6ac7fea5579ef5708b69d5da33a0ece7e8b16574b58b17b64a34cc34a4ffc22b4a62c1ece61f36c4a11a0665e0536b90d

  • C:\Users\Admin\AppData\Local\Temp\Tar6C44.tmp
    Filesize

    181KB

    MD5

    4ea6026cf93ec6338144661bf1202cd1

    SHA1

    a1dec9044f750ad887935a01430bf49322fbdcb7

    SHA256

    8efbc21559ef8b1bcf526800d8070baad42474ce7198e26fa771dbb41a76b1d8

    SHA512

    6c7e0980e39aacf4c3689802353f464a08cd17753bd210ee997e5f2a455deb4f287a9ef74d84579dbde49bc96213cd2b8b247723919c412ea980aa6e6bfe218b

  • C:\Users\Admin\AppData\Local\Temp\tmp474D.tmp
    Filesize

    1KB

    MD5

    c84ab447f674a23f7648eca3de41064f

    SHA1

    6abab2a1eec88a0a0a8abf88f36f8052f34acaef

    SHA256

    d75503373166c17f13e90266d675cdc770d24a93f6940a13fd1a8f9c0e7f35ea

    SHA512

    f7d9035e612e2f3796712acdb1442832a6a620a68dc6fc18ed24d144bb68b905df0061e7f13853379d38180cd0cd22810f3445aa15879394ae5de3500611b292

  • C:\Users\Admin\AppData\Local\Temp\tmp6EAD.tmp
    Filesize

    46KB

    MD5

    02d2c46697e3714e49f46b680b9a6b83

    SHA1

    84f98b56d49f01e9b6b76a4e21accf64fd319140

    SHA256

    522cad95d3fa6ebb3274709b8d09bbb1ca37389d0a924cd29e934a75aa04c6c9

    SHA512

    60348a145bfc71b1e07cb35fa79ab5ff472a3d0a557741ea2d39b3772bc395b86e261bd616f65307ae0d997294e49b5548d32f11e86ef3e2704959ca63da8aac

  • C:\Users\Admin\AppData\Local\Temp\tmp6EC3.tmp
    Filesize

    92KB

    MD5

    18e04095708297d6889a6962f81e8d8f

    SHA1

    9a25645db1da0217092c06579599b04982192124

    SHA256

    4ed16c019fe50bb4ab1c9dcedf0e52f93454b5dbaf18615d60761e7927b69fb7

    SHA512

    45ec57bddeeb8bca05babcf8da83bf9db630819b23076a1cf79f2e54b3e88e14cd7db650332554026ab5e8634061dd699f322bcba6683765063e67ac47ea1caf

  • C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7J39WBXJ86NCC7T7JQZK.temp
    Filesize

    7KB

    MD5

    753ed4934335d98b6c359029b8dfa2ea

    SHA1

    dcac2d73385ad354a219064c9ce9197629d37e93

    SHA256

    37da80201f5f02624189c2abe1f948e1adbce32cec5bf3d76d254388b9b12f6d

    SHA512

    fabdad45a7c40fe78aef25ac69cd36e46f775b25ec799c7b018b7098e53fae136ed6dd81b338dea926a8e7907e9abde0b5194235a96623bcc51e21b7a9b864a1

  • memory/2148-30-0x0000000000400000-0x000000000041E000-memory.dmp
    Filesize

    120KB

  • memory/2148-32-0x0000000000400000-0x000000000041E000-memory.dmp
    Filesize

    120KB

  • memory/2148-22-0x0000000000400000-0x000000000041E000-memory.dmp
    Filesize

    120KB

  • memory/2148-20-0x0000000000400000-0x000000000041E000-memory.dmp
    Filesize

    120KB

  • memory/2148-29-0x0000000000400000-0x000000000041E000-memory.dmp
    Filesize

    120KB

  • memory/2148-28-0x000000007EFDE000-0x000000007EFDF000-memory.dmp
    Filesize

    4KB

  • memory/2148-26-0x0000000000400000-0x000000000041E000-memory.dmp
    Filesize

    120KB

  • memory/2148-24-0x0000000000400000-0x000000000041E000-memory.dmp
    Filesize

    120KB

  • memory/3056-6-0x0000000000D10000-0x0000000000D1C000-memory.dmp
    Filesize

    48KB

  • memory/3056-7-0x0000000005070000-0x00000000050D0000-memory.dmp
    Filesize

    384KB

  • memory/3056-0-0x0000000074BDE000-0x0000000074BDF000-memory.dmp
    Filesize

    4KB

  • memory/3056-33-0x0000000074BD0000-0x00000000752BE000-memory.dmp
    Filesize

    6.9MB

  • memory/3056-5-0x0000000000D00000-0x0000000000D08000-memory.dmp
    Filesize

    32KB

  • memory/3056-4-0x0000000000510000-0x0000000000522000-memory.dmp
    Filesize

    72KB

  • memory/3056-3-0x0000000000F60000-0x0000000000FD6000-memory.dmp
    Filesize

    472KB

  • memory/3056-2-0x0000000074BD0000-0x00000000752BE000-memory.dmp
    Filesize

    6.9MB

  • memory/3056-1-0x00000000011B0000-0x0000000001230000-memory.dmp
    Filesize

    512KB