Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
P2SMn3jloH.exe

Overview

General Information

Sample Name:P2SMn3jloH.exe
Analysis ID:736951
MD5:0779f7b34e9079944427b8260b49c205
SHA1:31f2cf1dc970fdfaf51b9aab2c9e0b9715fb53ec
SHA256:5c7ff5f2993bdb60d15a567dfaef41dcd30875d6629f2775acdb190e01dcef87
Tags:exeSnakeKeylogger
Infos:

Detection

SmokeLoader
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Benign windows process drops PE files
Malicious sample detected (through community Yara rule)
Yara detected SmokeLoader
System process connects to network (likely due to code injection or exploit)
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Maps a DLL or memory area into another process
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Machine Learning detection for sample
Injects a PE file into a foreign processes
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Contains functionality to inject code into remote processes
Deletes itself after installation
Machine Learning detection for dropped file
C2 URLs / IPs found in malware configuration
Creates a thread in another existing process (thread injection)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Checks if the current machine is a virtual machine (disk enumeration)
Uses 32bit PE files
Yara signature match
Antivirus or Machine Learning detection for unpacked file
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query locales information (e.g. system language)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Internet Provider seen in connection with other malware
Detected potential crypto function
Found potential string decryption / allocating functions
Sample execution stops while process was sleeping (likely an evasion)
Found evasive API chain (may stop execution after checking a module file name)
Contains functionality to call native functions
Contains functionality to dynamically determine API calls
PE file contains executable resources (Code or Archives)
IP address seen in connection with other malware
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Drops files with a non-matching file extension (content does not match file extension)
Drops PE files
Tries to load missing DLLs
Contains functionality to read the PEB
Uses a known web browser user agent for HTTP communication
Checks if the current process is being debugged
Found evaded block containing many API calls
Creates a process in suspended mode (likely to inject code)

Classification

  • System is w10x64
  • P2SMn3jloH.exe (PID: 4020 cmdline: C:\Users\user\Desktop\P2SMn3jloH.exe MD5: 0779F7B34E9079944427B8260B49C205)
    • P2SMn3jloH.exe (PID: 3420 cmdline: C:\Users\user\Desktop\P2SMn3jloH.exe MD5: 0779F7B34E9079944427B8260B49C205)
      • explorer.exe (PID: 3452 cmdline: C:\Windows\Explorer.EXE MD5: AD5296B280E8F522A8A897C96BAB0E1D)
  • utisvaa (PID: 1280 cmdline: C:\Users\user\AppData\Roaming\utisvaa MD5: 0779F7B34E9079944427B8260B49C205)
    • utisvaa (PID: 5332 cmdline: C:\Users\user\AppData\Roaming\utisvaa MD5: 0779F7B34E9079944427B8260B49C205)
  • cleanup
{"C2 list": ["http://host-file-host6.com/", "http://host-host-file8.com/"]}
SourceRuleDescriptionAuthorStrings
0000000D.00000002.409013280.0000000001F51000.00000004.10000000.00040000.00000000.sdmpJoeSecurity_SmokeLoader_2Yara detected SmokeLoaderJoe Security
    0000000D.00000002.409013280.0000000001F51000.00000004.10000000.00040000.00000000.sdmpWindows_Trojan_Smokeloader_4e31426eunknownunknown
    • 0x2f4:$a: 5B 81 EB 34 10 00 00 6A 30 58 64 8B 00 8B 40 0C 8B 40 1C 8B 40 08 89 85 C0
    0000000C.00000002.395157811.00000000006D8000.00000040.00000020.00020000.00000000.sdmpWindows_Trojan_RedLineStealer_ed346e4cunknownunknown
    • 0x5218:$a: 55 8B EC 8B 45 14 56 57 8B 7D 08 33 F6 89 47 0C 39 75 10 76 15 8B
    00000001.00000002.350515025.0000000001F51000.00000004.10000000.00040000.00000000.sdmpJoeSecurity_SmokeLoader_2Yara detected SmokeLoaderJoe Security
      00000001.00000002.350515025.0000000001F51000.00000004.10000000.00040000.00000000.sdmpWindows_Trojan_Smokeloader_4e31426eunknownunknown
      • 0x2f4:$a: 5B 81 EB 34 10 00 00 6A 30 58 64 8B 00 8B 40 0C 8B 40 1C 8B 40 08 89 85 C0
      Click to see the 7 entries
      SourceRuleDescriptionAuthorStrings
      0.2.P2SMn3jloH.exe.21b15a0.1.raw.unpackJoeSecurity_SmokeLoader_2Yara detected SmokeLoaderJoe Security
        1.2.P2SMn3jloH.exe.400000.0.unpackJoeSecurity_SmokeLoader_2Yara detected SmokeLoaderJoe Security
          13.0.utisvaa.400000.6.unpackJoeSecurity_SmokeLoader_2Yara detected SmokeLoaderJoe Security
            13.0.utisvaa.400000.4.unpackJoeSecurity_SmokeLoader_2Yara detected SmokeLoaderJoe Security
              13.0.utisvaa.400000.5.unpackJoeSecurity_SmokeLoader_2Yara detected SmokeLoaderJoe Security
                Click to see the 2 entries
                No Sigma rule has matched
                No Snort rule has matched

                Click to jump to signature section

                Show All Signature Results

                AV Detection

                barindex
                Source: P2SMn3jloH.exeReversingLabs: Detection: 46%
                Source: P2SMn3jloH.exeVirustotal: Detection: 34%Perma Link
                Source: http://host-host-file8.com/URL Reputation: Label: malware
                Source: host-file-host6.comVirustotal: Detection: 17%Perma Link
                Source: host-host-file8.comVirustotal: Detection: 16%Perma Link
                Source: C:\Users\user\AppData\Roaming\utisvaaReversingLabs: Detection: 46%
                Source: C:\Users\user\AppData\Roaming\utisvaaVirustotal: Detection: 34%Perma Link
                Source: P2SMn3jloH.exeJoe Sandbox ML: detected
                Source: C:\Users\user\AppData\Roaming\utisvaaJoe Sandbox ML: detected
                Source: 13.0.utisvaa.400000.2.unpackAvira: Label: TR/Crypt.ZPACK.Gen
                Source: 13.0.utisvaa.400000.1.unpackAvira: Label: TR/Crypt.ZPACK.Gen
                Source: 13.0.utisvaa.400000.0.unpackAvira: Label: TR/Crypt.ZPACK.Gen
                Source: 13.0.utisvaa.400000.3.unpackAvira: Label: TR/Crypt.ZPACK.Gen
                Source: 00000001.00000002.350312010.0000000000420000.00000004.00000800.00020000.00000000.sdmpMalware Configuration Extractor: SmokeLoader {"C2 list": ["http://host-file-host6.com/", "http://host-host-file8.com/"]}
                Source: P2SMn3jloH.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
                Source: Binary string: C:\jexagiyad51\fuzuniguxoloyi55\nohacagepak\zevoluril\suy.pdb source: P2SMn3jloH.exe, utisvaa.2.dr
                Source: Binary string: (C:\jexagiyad51\fuzuniguxoloyi55\nohacagepak\zevoluril\suy.pdb@ source: P2SMn3jloH.exe, utisvaa.2.dr

                Networking

                barindex
                Source: C:\Windows\explorer.exeDomain query: host-file-host6.com
                Source: C:\Windows\explorer.exeDomain query: host-host-file8.com
                Source: Malware configuration extractorURLs: http://host-file-host6.com/
                Source: Malware configuration extractorURLs: http://host-host-file8.com/
                Source: Joe Sandbox ViewASN Name: RISS-ASRU RISS-ASRU
                Source: Joe Sandbox ViewIP Address: 87.251.79.60 87.251.79.60
                Source: global trafficHTTP traffic detected: POST / HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://dcihclar.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 229Host: host-file-host6.com
                Source: unknownHTTP traffic detected: POST / HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://dcihclar.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 229Host: host-file-host6.com
                Source: unknownDNS traffic detected: queries for: host-file-host6.com

                Key, Mouse, Clipboard, Microphone and Screen Capturing

                barindex
                Source: Yara matchFile source: 0.2.P2SMn3jloH.exe.21b15a0.1.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 1.2.P2SMn3jloH.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 13.0.utisvaa.400000.6.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 13.0.utisvaa.400000.4.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 13.0.utisvaa.400000.5.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 13.2.utisvaa.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 12.2.utisvaa.21a15a0.1.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 0000000D.00000002.409013280.0000000001F51000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000001.00000002.350515025.0000000001F51000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000001.00000002.350312010.0000000000420000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 0000000D.00000002.408977758.0000000001F30000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000002.00000000.338679207.00000000057B1000.00000020.80000000.00040000.00000000.sdmp, type: MEMORY

                System Summary

                barindex
                Source: 0000000D.00000002.409013280.0000000001F51000.00000004.10000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
                Source: 0000000C.00000002.395157811.00000000006D8000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
                Source: 00000001.00000002.350515025.0000000001F51000.00000004.10000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
                Source: 00000001.00000002.350312010.0000000000420000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
                Source: 0000000D.00000002.408977758.0000000001F30000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
                Source: 00000002.00000000.338679207.00000000057B1000.00000020.80000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
                Source: 00000000.00000002.254069978.00000000005E9000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
                Source: P2SMn3jloH.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
                Source: 0000000D.00000002.409013280.0000000001F51000.00000004.10000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
                Source: 0000000C.00000002.395157811.00000000006D8000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
                Source: 00000001.00000002.350515025.0000000001F51000.00000004.10000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
                Source: 00000001.00000002.350312010.0000000000420000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
                Source: 0000000D.00000002.408977758.0000000001F30000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
                Source: 00000002.00000000.338679207.00000000057B1000.00000020.80000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
                Source: 00000000.00000002.254069978.00000000005E9000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
                Source: C:\Users\user\Desktop\P2SMn3jloH.exeCode function: 0_2_0041A8B00_2_0041A8B0
                Source: C:\Users\user\Desktop\P2SMn3jloH.exeCode function: 0_2_0040E9700_2_0040E970
                Source: C:\Users\user\Desktop\P2SMn3jloH.exeCode function: 0_2_004199180_2_00419918
                Source: C:\Users\user\Desktop\P2SMn3jloH.exeCode function: 0_2_004139A70_2_004139A7
                Source: C:\Users\user\Desktop\P2SMn3jloH.exeCode function: 0_2_004142500_2_00414250
                Source: C:\Users\user\Desktop\P2SMn3jloH.exeCode function: 0_2_00414A7C0_2_00414A7C
                Source: C:\Users\user\Desktop\P2SMn3jloH.exeCode function: 0_2_004192200_2_00419220
                Source: C:\Users\user\Desktop\P2SMn3jloH.exeCode function: 0_2_00418CDC0_2_00418CDC
                Source: C:\Users\user\Desktop\P2SMn3jloH.exeCode function: 0_2_0041B4810_2_0041B481
                Source: C:\Users\user\Desktop\P2SMn3jloH.exeCode function: 0_2_0041465C0_2_0041465C
                Source: C:\Users\user\Desktop\P2SMn3jloH.exeCode function: 0_2_00413E7C0_2_00413E7C
                Source: C:\Users\user\Desktop\P2SMn3jloH.exeCode function: 0_2_004187980_2_00418798
                Source: C:\Users\user\Desktop\P2SMn3jloH.exeCode function: String function: 0040EF38 appears 38 times
                Source: C:\Users\user\Desktop\P2SMn3jloH.exeCode function: 0_2_021B0110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,SetThreadContext,ResumeThread,ExitProcess,0_2_021B0110
                Source: C:\Users\user\Desktop\P2SMn3jloH.exeCode function: 1_2_0040180C Sleep,NtTerminateProcess,1_2_0040180C
                Source: C:\Users\user\Desktop\P2SMn3jloH.exeCode function: 1_2_00401818 Sleep,NtTerminateProcess,1_2_00401818
                Source: C:\Users\user\Desktop\P2SMn3jloH.exeCode function: 1_2_00401822 Sleep,NtTerminateProcess,1_2_00401822
                Source: C:\Users\user\Desktop\P2SMn3jloH.exeCode function: 1_2_00401826 Sleep,NtTerminateProcess,1_2_00401826
                Source: C:\Users\user\Desktop\P2SMn3jloH.exeCode function: 1_2_00401834 Sleep,NtTerminateProcess,1_2_00401834
                Source: C:\Users\user\AppData\Roaming\utisvaaCode function: 12_2_021A0110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,SetThreadContext,ResumeThread,ExitProcess,12_2_021A0110
                Source: C:\Users\user\AppData\Roaming\utisvaaCode function: 13_2_0040180C Sleep,NtTerminateProcess,13_2_0040180C
                Source: C:\Users\user\AppData\Roaming\utisvaaCode fu