Windows
Analysis Report
Set-up.exe
Overview
General Information
Detection
ACR Stealer
Score: | 100 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Suricata IDS alerts for network traffic
Yara detected ACR Stealer
Allocates memory in foreign processes
Found direct / indirect Syscall (likely to bypass EDR)
Found many strings related to Crypto-Wallets (likely being stolen)
Joe Sandbox ML detected suspicious sample
Modifies the context of a thread in another process (thread injection)
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Tries to steal from password manager
Writes to foreign memory regions
AV process strings found (often used to terminate AV products)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to read the PEB
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
One or more processes crash
PE file contains sections with non-standard names
Sample file is different than original file name gathered from version info
Searches for user specific document files
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Yara detected Credential Stealer
Classification
- System is w10x64
Set-up.exe (PID: 7468 cmdline:
"C:\Users\ user\Deskt op\Set-up. exe" MD5: B21F13CF1A28FFC443CA52A022C78C3D) chrome.exe (PID: 1300 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" MD5: E81F54E6C1129887AEA47E7D092680BF) msedge.exe (PID: 6184 cmdline:
"C:\Progra m Files (x 86)\Micros oft\Edge\A pplication \msedge.ex e" MD5: 69222B8101B0601CC6663F8381E7E00F) chrome.exe (PID: 5760 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" MD5: E81F54E6C1129887AEA47E7D092680BF) WerFault.exe (PID: 5156 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 5 760 -s 144 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0) WerFault.exe (PID: 1936 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 5 760 -s 204 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0) msedge.exe (PID: 1380 cmdline:
"C:\Progra m Files (x 86)\Micros oft\Edge\A pplication \msedge.ex e" MD5: 69222B8101B0601CC6663F8381E7E00F) WerFault.exe (PID: 3680 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 1 380 -s 224 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0) WerFault.exe (PID: 1836 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 1 380 -s 92 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0) chrome.exe (PID: 2444 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" MD5: E81F54E6C1129887AEA47E7D092680BF) WerFault.exe (PID: 2836 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 2 444 -s 152 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0) WerFault.exe (PID: 2992 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 2 444 -s 92 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0) msedge.exe (PID: 3832 cmdline:
"C:\Progra m Files (x 86)\Micros oft\Edge\A pplication \msedge.ex e" MD5: 69222B8101B0601CC6663F8381E7E00F) WerFault.exe (PID: 3944 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 3 832 -s 228 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0) WerFault.exe (PID: 2568 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 3 832 -s 92 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0) chrome.exe (PID: 4544 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" MD5: E81F54E6C1129887AEA47E7D092680BF) WerFault.exe (PID: 5004 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 4 544 -s 144 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0) WerFault.exe (PID: 4848 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 4 544 -s 92 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0) msedge.exe (PID: 4988 cmdline:
"C:\Progra m Files (x 86)\Micros oft\Edge\A pplication \msedge.ex e" MD5: 69222B8101B0601CC6663F8381E7E00F) WerFault.exe (PID: 6500 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 4 988 -s 224 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0) WerFault.exe (PID: 2728 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 4 988 -s 92 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0)
elevation_service.exe (PID: 2956 cmdline:
"C:\Progra m Files (x 86)\Micros oft\Edge\A pplication \117.0.204 5.47\eleva tion_servi ce.exe" MD5: BF076931DBBF2CA64F5835A94A11DD46)
- cleanup
⊘No configs have been found
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_ACRStealer | Yara detected ACR Stealer | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security |
⊘No Sigma rule has matched
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-05-10T08:05:29.794242+0200 | 2052674 | 1 | A Network Trojan was detected | 192.168.2.5 | 49691 | 188.114.96.3 | 80 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | Neural Call Log Analysis: |
Source: | Code function: | 0_2_02682F00 |
Source: | Static PE information: |
Source: | Static PE information: |
Networking |
---|
Source: | Suricata IDS: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |