Loading ...

Play interactive tourEdit tour

Analysis Report http://verodin_backend.exe

Overview

General Information

Sample URL:http://verodin_backend.exe
Analysis ID:433021
Infos:

Most interesting Screenshot:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Tries to resolve domain names, but no domain seems valid (expired dropper behavior)

Classification

Process Tree

  • System is w10x64
  • cmd.exe (PID: 3352 cmdline: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P 'C:\Users\user\Desktop\download' --no-check-certificate --content-disposition --user-agent='Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko' 'http://verodin_backend.exe' > cmdline.out 2>&1 MD5: F3BDBE3BB6F734E357235F4D5898582D)
    • conhost.exe (PID: 800 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • wget.exe (PID: 400 cmdline: wget -t 2 -v -T 60 -P 'C:\Users\user\Desktop\download' --no-check-certificate --content-disposition --user-agent='Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko' 'http://verodin_backend.exe' MD5: 3DADB6E2ECE9C4B3E1E322E617658B60)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Signature Overview

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownDNS traffic detected: query: verodin_backend.exe replaycode: Name error (3)
Source: unknownDNS traffic detected: queries for: verodin_backend.exe
Source: wget.exe, 00000003.00000002.196874197.00000000001A0000.00000004.00000020.sdmpString found in binary or memory: http://verodin_backend.exe
Source: wget.exe, 00000003.00000002.197054459.00000000010C5000.00000004.00000040.sdmp, wget.exe, 00000003.00000002.196905964.00000000009CC000.00000004.00000001.sdmp, cmdline.out.3.drString found in binary or memory: http://verodin_backend.exe/
Source: wget.exe, 00000003.00000002.197049800.00000000010C0000.00000004.00000040.sdmpString found in binary or memory: http://verodin_backend.exe/nd.e
Source: classification engineClassification label: clean0.win@4/1@1/0
Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\Desktop\cmdline.outJump to behavior
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:800:120:WilError_01
Source: C:\Windows\SysWOW64\wget.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Windows\SysWOW64\wget.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
Source: C:\Windows\SysWOW64\wget.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
Source: unknownProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P 'C:\Users\user\Desktop\download' --no-check-certificate --content-disposition --user-agent='Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko' 'http://verodin_backend.exe' > cmdline.out 2>&1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -T 60 -P 'C:\Users\user\Desktop\download' --no-check-certificate --content-disposition --user-agent='Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko' 'http://verodin_backend.exe'
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -T 60 -P 'C:\Users\user\Desktop\download' --no-check-certificate --content-disposition --user-agent='Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko' 'http://verodin_backend.exe' Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\conhost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: wget.exe, 00000003.00000002.197517561.0000000002BB0000.00000002.00000001.sdmpBinary or memory string: A Virtual Machine could not be started because Hyper-V is not installed.
Source: wget.exe, 00000003.00000002.197517561.0000000002BB0000.00000002.00000001.sdmpBinary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service.
Source: wget.exe, 00000003.00000002.197517561.0000000002BB0000.00000002.00000001.sdmpBinary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported.
Source: wget.exe, 00000003.00000002.197517561.0000000002BB0000.00000002.00000001.sdmpBinary or memory string: An unknown internal message was received by the Hyper-V Compute Service.

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionProcess Injection1Masquerading1OS Credential DumpingSecurity Software Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumNon-Application Layer Protocol1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsProcess Injection1LSASS MemorySystem Information Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothApplication Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerRemote System Discovery1SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 433021 URL: http://verodin_backend.exe Startdate: 11/06/2021 Architecture: WINDOWS Score: 0 5 cmd.exe 2 2->5         started        process3 7 wget.exe 1 5->7         started        10 conhost.exe 5->10         started        dnsIp4 12 verodin_backend.exe 7->12

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
http://verodin_backend.exe0%Avira URL Cloudsafe

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

SourceDetectionScannerLabelLink
http://verodin_backend.exe/0%Avira URL Cloudsafe
http://verodin_backend.exe/nd.e0%Avira URL Cloudsafe

Domains and IPs

Contacted Domains

NameIPActiveMaliciousAntivirus DetectionReputation
verodin_backend.exe
unknown
unknownfalse
    unknown

    URLs from Memory and Binaries

    NameSourceMaliciousAntivirus DetectionReputation
    http://verodin_backend.exewget.exe, 00000003.00000002.196874197.00000000001A0000.00000004.00000020.sdmpfalse
      low
      http://verodin_backend.exe/wget.exe, 00000003.00000002.197054459.00000000010C5000.00000004.00000040.sdmp, wget.exe, 00000003.00000002.196905964.00000000009CC000.00000004.00000001.sdmp, cmdline.out.3.drfalse
      • Avira URL Cloud: safe
      low
      http://verodin_backend.exe/nd.ewget.exe, 00000003.00000002.197049800.00000000010C0000.00000004.00000040.sdmpfalse
      • Avira URL Cloud: safe
      low

      Contacted IPs

      No contacted IP infos

      General Information

      Joe Sandbox Version:32.0.0 Black Diamond
      Analysis ID:433021
      Start date:11.06.2021
      Start time:06:41:39
      Joe Sandbox Product:CloudBasic
      Overall analysis duration:0h 1m 50s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:urldownload.jbs
      Sample URL:http://verodin_backend.exe
      Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
      Number of analysed new started processes analysed:4
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • HDC enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:CLEAN
      Classification:clean0.win@4/1@1/0
      EGA Information:Failed
      HDC Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      Cookbook Comments:
      • Adjust boot time
      • Enable AMSI
      • Unable to download file
      Warnings:
      Show All
      • Exclude process from analysis (whitelisted): svchost.exe
      • Excluded IPs from analysis (whitelisted): 52.255.188.83, 104.43.139.144
      • Excluded domains from analysis (whitelisted): skypedataprdcoleus17.cloudapp.net, blobcollector.events.data.trafficmanager.net, skypedataprdcolcus16.cloudapp.net, watson.telemetry.microsoft.com
      • Not all processes where analyzed, report is missing behavior information

      Simulations

      Behavior and APIs

      No simulations

      Joe Sandbox View / Context

      IPs

      No context

      Domains

      No context

      ASN

      No context

      JA3 Fingerprints

      No context

      Dropped Files

      No context

      Created / dropped Files

      C:\Users\user\Desktop\cmdline.out
      Process:C:\Windows\SysWOW64\wget.exe
      File Type:ASCII text, with CRLF line terminators
      Category:modified
      Size (bytes):203
      Entropy (8bit):4.8362126956009055
      Encrypted:false
      SSDEEP:3:1tUOuBpP9ZgRJqXaKRGCLRPmMOrSGIPCOLK46ZmqLvdXnA+TAKKRBy:H/y7ijqXrjLlmcpGmsdXAs/Kry
      MD5:2B2EAB413545F64C2786DE288C761D55
      SHA1:3F590FDBA1EB631F6B7E0693A358A87729EC946D
      SHA-256:0E27493757A9CD2A506D6E5EC1B42096D8AFDD00A259A9A744A0120957CFAC67
      SHA-512:2CFE44C2D0A880235DFD8452F01BC4DA510B9080DFBFCCC3662899E021E15F218176DB2FF1961730981E94A28E4D256DAB47EDCB11346E55B27936F73E5BF36A
      Malicious:false
      Reputation:low
      Preview: --2021-06-11 06:42:24-- http://verodin_backend.exe/..Resolving verodin_backend.exe (verodin_backend.exe)... failed: No such host is known. ...wget: unable to resolve host address 'verodin_backend.exe'..

      Static File Info

      No static file info

      Network Behavior

      Network Port Distribution

      UDP Packets

      TimestampSource PortDest PortSource IPDest IP
      Jun 11, 2021 06:42:18.014142036 CEST6511053192.168.2.38.8.8.8
      Jun 11, 2021 06:42:18.076153994 CEST53651108.8.8.8192.168.2.3
      Jun 11, 2021 06:42:21.591480970 CEST5836153192.168.2.38.8.8.8
      Jun 11, 2021 06:42:21.649892092 CEST53583618.8.8.8192.168.2.3
      Jun 11, 2021 06:42:24.366087914 CEST6349253192.168.2.38.8.8.8
      Jun 11, 2021 06:42:24.421266079 CEST53634928.8.8.8192.168.2.3
      Jun 11, 2021 06:42:24.645869017 CEST6083153192.168.2.38.8.8.8
      Jun 11, 2021 06:42:24.709505081 CEST53608318.8.8.8192.168.2.3
      Jun 11, 2021 06:42:25.232471943 CEST6010053192.168.2.38.8.8.8
      Jun 11, 2021 06:42:25.285618067 CEST53601008.8.8.8192.168.2.3
      Jun 11, 2021 06:42:26.161859035 CEST5319553192.168.2.38.8.8.8
      Jun 11, 2021 06:42:26.222840071 CEST53531958.8.8.8192.168.2.3
      Jun 11, 2021 06:42:27.070625067 CEST5014153192.168.2.38.8.8.8
      Jun 11, 2021 06:42:27.121603012 CEST53501418.8.8.8192.168.2.3
      Jun 11, 2021 06:42:28.014219046 CEST5302353192.168.2.38.8.8.8
      Jun 11, 2021 06:42:28.067595005 CEST53530238.8.8.8192.168.2.3
      Jun 11, 2021 06:42:28.952725887 CEST4956353192.168.2.38.8.8.8
      Jun 11, 2021 06:42:29.003566027 CEST53495638.8.8.8192.168.2.3
      Jun 11, 2021 06:42:29.894565105 CEST5135253192.168.2.38.8.8.8
      Jun 11, 2021 06:42:29.953274965 CEST53513528.8.8.8192.168.2.3

      DNS Queries

      TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
      Jun 11, 2021 06:42:24.645869017 CEST192.168.2.38.8.8.80xfc24Standard query (0)verodin_backend.exeA (IP address)IN (0x0001)

      DNS Answers

      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
      Jun 11, 2021 06:42:24.709505081 CEST8.8.8.8192.168.2.30xfc24Name error (3)verodin_backend.exenonenoneA (IP address)IN (0x0001)

      Code Manipulations

      Statistics

      CPU Usage

      Click to jump to process

      Memory Usage

      Click to jump to process

      Behavior

      Click to jump to process

      System Behavior

      General

      Start time:06:42:22
      Start date:11/06/2021
      Path:C:\Windows\SysWOW64\cmd.exe
      Wow64 process (32bit):true
      Commandline:C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P 'C:\Users\user\Desktop\download' --no-check-certificate --content-disposition --user-agent='Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko' 'http://verodin_backend.exe' > cmdline.out 2>&1
      Imagebase:0xbd0000
      File size:232960 bytes
      MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low

      General

      Start time:06:42:23
      Start date:11/06/2021
      Path:C:\Windows\System32\conhost.exe
      Wow64 process (32bit):false
      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Imagebase:0x7ff6b2800000
      File size:625664 bytes
      MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low

      General

      Start time:06:42:24
      Start date:11/06/2021
      Path:C:\Windows\SysWOW64\wget.exe
      Wow64 process (32bit):true
      Commandline:wget -t 2 -v -T 60 -P 'C:\Users\user\Desktop\download' --no-check-certificate --content-disposition --user-agent='Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko' 'http://verodin_backend.exe'
      Imagebase:0x400000
      File size:3895184 bytes
      MD5 hash:3DADB6E2ECE9C4B3E1E322E617658B60
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low

      Disassembly

      Code Analysis

      Reset < >