Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
b8E3zd5AYc.exe

Overview

General Information

Sample Name:b8E3zd5AYc.exe
Analysis ID:715083
MD5:2072a0a726904aed8c39095f36efd296
SHA1:29754dea5a1fb0a2ff054279a3030d84579fad15
SHA256:9ae4d00a359aa5facd231470b9a92b0542c6f8afa6e981dce7b171a08f635287
Tags:exeRecordBreaker
Infos:

Detection

SmokeLoader
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Benign windows process drops PE files
Malicious sample detected (through community Yara rule)
Yara detected SmokeLoader
System process connects to network (likely due to code injection or exploit)
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Maps a DLL or memory area into another process
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Machine Learning detection for sample
Injects a PE file into a foreign processes
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Contains functionality to inject code into remote processes
Deletes itself after installation
Machine Learning detection for dropped file
C2 URLs / IPs found in malware configuration
Creates a thread in another existing process (thread injection)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Checks if the current machine is a virtual machine (disk enumeration)
Uses 32bit PE files
Yara signature match
Antivirus or Machine Learning detection for unpacked file
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query locales information (e.g. system language)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Internet Provider seen in connection with other malware
Detected potential crypto function
Sample execution stops while process was sleeping (likely an evasion)
Found evasive API chain (may stop execution after checking a module file name)
Contains functionality to call native functions
Contains functionality to dynamically determine API calls
PE file contains executable resources (Code or Archives)
IP address seen in connection with other malware
Creates a DirectInput object (often for capturing keystrokes)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Drops files with a non-matching file extension (content does not match file extension)
Drops PE files
Tries to load missing DLLs
Contains functionality to read the PEB
Uses a known web browser user agent for HTTP communication
Checks if the current process is being debugged
Creates a process in suspended mode (likely to inject code)

Classification

  • System is w10x64
  • b8E3zd5AYc.exe (PID: 5104 cmdline: C:\Users\user\Desktop\b8E3zd5AYc.exe MD5: 2072A0A726904AED8C39095F36EFD296)
    • b8E3zd5AYc.exe (PID: 5976 cmdline: C:\Users\user\Desktop\b8E3zd5AYc.exe MD5: 2072A0A726904AED8C39095F36EFD296)
      • explorer.exe (PID: 3324 cmdline: C:\Windows\Explorer.EXE MD5: AD5296B280E8F522A8A897C96BAB0E1D)
  • vwhdahh (PID: 2952 cmdline: C:\Users\user\AppData\Roaming\vwhdahh MD5: 2072A0A726904AED8C39095F36EFD296)
    • vwhdahh (PID: 6104 cmdline: C:\Users\user\AppData\Roaming\vwhdahh MD5: 2072A0A726904AED8C39095F36EFD296)
  • cleanup
{"C2 list": ["http://host-file-host6.com/", "http://host-host-file8.com/"]}
SourceRuleDescriptionAuthorStrings
00000005.00000002.426233930.00000000007B8000.00000040.00000020.00020000.00000000.sdmpWindows_Trojan_RedLineStealer_ed346e4cunknownunknown
  • 0x4984:$a: 55 8B EC 8B 45 14 56 57 8B 7D 08 33 F6 89 47 0C 39 75 10 76 15 8B
00000002.00000000.368476198.0000000002951000.00000020.80000000.00040000.00000000.sdmpJoeSecurity_SmokeLoader_2Yara detected SmokeLoaderJoe Security
    00000002.00000000.368476198.0000000002951000.00000020.80000000.00040000.00000000.sdmpWindows_Trojan_Smokeloader_4e31426eunknownunknown
    • 0x2f4:$a: 5B 81 EB 34 10 00 00 6A 30 58 64 8B 00 8B 40 0C 8B 40 1C 8B 40 08 89 85 C0
    00000001.00000002.386482803.00000000004F0000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_SmokeLoader_2Yara detected SmokeLoaderJoe Security
      00000001.00000002.386482803.00000000004F0000.00000004.00000800.00020000.00000000.sdmpWindows_Trojan_Smokeloader_4e31426eunknownunknown
      • 0x6f4:$a: 5B 81 EB 34 10 00 00 6A 30 58 64 8B 00 8B 40 0C 8B 40 1C 8B 40 08 89 85 C0
      Click to see the 7 entries
      SourceRuleDescriptionAuthorStrings
      6.0.vwhdahh.400000.5.unpackJoeSecurity_SmokeLoader_2Yara detected SmokeLoaderJoe Security
        1.2.b8E3zd5AYc.exe.400000.0.unpackJoeSecurity_SmokeLoader_2Yara detected SmokeLoaderJoe Security
          0.2.b8E3zd5AYc.exe.6e15a0.1.raw.unpackJoeSecurity_SmokeLoader_2Yara detected SmokeLoaderJoe Security
            6.0.vwhdahh.400000.6.unpackJoeSecurity_SmokeLoader_2Yara detected SmokeLoaderJoe Security
              6.2.vwhdahh.400000.0.unpackJoeSecurity_SmokeLoader_2Yara detected SmokeLoaderJoe Security
                Click to see the 2 entries
                No Sigma rule has matched
                No Snort rule has matched

                Click to jump to signature section

                Show All Signature Results

                AV Detection

                barindex
                Source: b8E3zd5AYc.exeReversingLabs: Detection: 43%
                Source: b8E3zd5AYc.exeVirustotal: Detection: 36%Perma Link
                Source: http://host-host-file8.com/URL Reputation: Label: malware
                Source: host-file-host6.comVirustotal: Detection: 21%Perma Link
                Source: host-host-file8.comVirustotal: Detection: 21%Perma Link
                Source: C:\Users\user\AppData\Roaming\vwhdahhReversingLabs: Detection: 43%
                Source: C:\Users\user\AppData\Roaming\vwhdahhVirustotal: Detection: 36%Perma Link
                Source: b8E3zd5AYc.exeJoe Sandbox ML: detected
                Source: C:\Users\user\AppData\Roaming\vwhdahhJoe Sandbox ML: detected
                Source: 6.0.vwhdahh.400000.2.unpackAvira: Label: TR/Patched.Gen
                Source: 6.0.vwhdahh.400000.3.unpackAvira: Label: TR/Patched.Gen
                Source: 6.0.vwhdahh.400000.0.unpackAvira: Label: TR/Patched.Gen
                Source: 6.0.vwhdahh.400000.1.unpackAvira: Label: TR/Patched.Gen
                Source: 00000001.00000002.386482803.00000000004F0000.00000004.00000800.00020000.00000000.sdmpMalware Configuration Extractor: SmokeLoader {"C2 list": ["http://host-file-host6.com/", "http://host-host-file8.com/"]}
                Source: b8E3zd5AYc.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
                Source: Binary string: VC:\ruvodejet xufututowik mehumexiz\ciz-legerawujewo\xahahes.pdbH source: b8E3zd5AYc.exe, vwhdahh.2.dr
                Source: Binary string: C:\ruvodejet xufututowik mehumexiz\ciz-legerawujewo\xahahes.pdb source: b8E3zd5AYc.exe, vwhdahh.2.dr

                Networking

                barindex
                Source: C:\Windows\explorer.exeDomain query: host-file-host6.com
                Source: C:\Windows\explorer.exeDomain query: host-host-file8.com
                Source: Malware configuration extractorURLs: http://host-file-host6.com/
                Source: Malware configuration extractorURLs: http://host-host-file8.com/
                Source: Joe Sandbox ViewASN Name: GULFSTREAMUA GULFSTREAMUA
                Source: Joe Sandbox ViewIP Address: 176.124.192.17 176.124.192.17
                Source: global trafficHTTP traffic detected: POST / HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://turbbv.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 195Host: host-file-host6.com
                Source: explorer.exe, 00000002.00000000.349059881.000000000091F000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000002.00000000.367736313.000000000091F000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000002.00000000.317150379.000000000091F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.autoitscript.com/autoit3/J
                Source: unknownHTTP traffic detected: POST / HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://turbbv.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 195Host: host-file-host6.com
                Source: unknownDNS traffic detected: queries for: host-file-host6.com

                Key, Mouse, Clipboard, Microphone and Screen Capturing

                barindex