• No results found

MALICIOUS DYNAMIC ANALYSIS REPORT # X-Ray Vision for Malware / 31. Injector. Classifications: Mal/Generic-S Mal/HTMLGen-A

N/A
N/A
Protected

Academic year: 2022

Share "MALICIOUS DYNAMIC ANALYSIS REPORT # X-Ray Vision for Malware / 31. Injector. Classifications: Mal/Generic-S Mal/HTMLGen-A"

Copied!
31
0
0

Loading.... (view fulltext now)

Full text

(1)

MALICIOUS

Classifications: Injector

Threat Names:

Mal/Generic-S Mal/HTMLGen-A Generic.Exploit.Shellcode.RDI.2.848912F9 Gen:Variant.Strictor.46025

Verdict Reason: -

Sample Type Windows Exe (x86-32)

File Name 0d2805a84af62c765ac706960cd2a4a1.exe

ID #1077621

MD5 592cbf02a35ee0358194b33c483be874

SHA1 ae04e74a104cd6d2d00331111f0f2596c86eeb2e

SHA256 2c12f9be67bf31375db1b0578920fa37b415ec1a2df56cc1f3dacd9985f60100

File Size 339.00 KB

Report Created 2021-10-26 16:21 (UTC+2)

Target Environment win10_64_th2_en_mso2016 | exe

(2)

OVERVIEW

VMRay Threat Identifiers (17 rules, 47 matches)

Score Category Operation Count Classification

4/5 Defense Evasion Obscures a file's origin 2 -

(Process #2) 0d2805a84af62c765ac706960cd2a4a1.exe tries to delete zone identifier of file "C:\ProgramData\images.exe".

(Process #11) images.exe tries to delete zone identifier of file "C:\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe".

4/5 Injection Writes into the memory of another process 1 Injector

(Process #7) images.exe modifies memory of (process #8) cmd.exe.

4/5 Injection Modifies control flow of another process 1 Injector

(Process #7) images.exe creates thread in (process #8) cmd.exe.

4/5 Antivirus Malicious content was detected by heuristic scan 4 -

Built-in AV detected a memory dump of (process #2) 0d2805a84af62c765ac706960cd2a4a1.exe as "Generic.Exploit.Shellcode.RDI.2.848912F9".

Built-in AV detected a memory dump of (process #2) 0d2805a84af62c765ac706960cd2a4a1.exe as "Gen:Variant.Strictor.46025".

Built-in AV detected a memory dump of (process #7) images.exe as "Generic.Exploit.Shellcode.RDI.2.848912F9".

Built-in AV detected a memory dump of (process #11) images.exe as "Generic.Exploit.Shellcode.RDI.2.848912F9".

4/5 Reputation Known malicious file 1 -

Reputation analysis labels the sample itself as "Mal/Generic-S".

4/5 Reputation Resolves known malicious domain 1 -

Reputation analysis labels the resolved domain "nan.ydns.eu" as "Mal/HTMLGen-A".

2/5 Injection Writes into the memory of a process started from a created or modified executable 3 -

(Process #1) 0d2805a84af62c765ac706960cd2a4a1.exe modifies memory of (process #2) 0d2805a84af62c765ac706960cd2a4a1.exe.

(Process #4) images.exe modifies memory of (process #7) images.exe.

(Process #10) images.exe modifies memory of (process #11) images.exe.

2/5 Injection Modifies control flow of a process started from a created or modified executable 3 -

(Process #1) 0d2805a84af62c765ac706960cd2a4a1.exe alters context of (process #2) 0d2805a84af62c765ac706960cd2a4a1.exe.

(Process #4) images.exe alters context of (process #7) images.exe.

(Process #10) images.exe alters context of (process #11) images.exe.

1/5 Privilege Escalation Enables process privilege 3 -

(Process #1) 0d2805a84af62c765ac706960cd2a4a1.exe enables process privilege "SeDebugPrivilege".

(Process #4) images.exe enables process privilege "SeDebugPrivilege".

(Process #10) images.exe enables process privilege "SeDebugPrivilege".

1/5 Hide Tracks Creates process with hidden window 8 -

X-Ray Vision for Malware - www.vmray.com 2 / 31

(3)

Score Category Operation Count Classification

(Process #1) 0d2805a84af62c765ac706960cd2a4a1.exe starts (process #2) 0d2805a84af62c765ac706960cd2a4a1.exe with a hidden window.

(Process #2) 0d2805a84af62c765ac706960cd2a4a1.exe starts (process #3) cmd.exe with a hidden window.

(Process #2) 0d2805a84af62c765ac706960cd2a4a1.exe starts (process #4) images.exe with a hidden window.

(Process #4) images.exe starts (process #7) images.exe with a hidden window.

(Process #7) images.exe starts (process #8) cmd.exe with a hidden window.

(Process #10) images.exe starts (process #11) images.exe with a hidden window.

(Process #11) images.exe starts (process #12) cmd.exe with a hidden window.

(Process #11) images.exe starts (process #13) images.exe with a hidden window.

1/5 Discovery Enumerates running processes 3 -

(Process #1) 0d2805a84af62c765ac706960cd2a4a1.exe enumerates running processes.

(Process #4) images.exe enumerates running processes.

(Process #10) images.exe enumerates running processes.

1/5 Obfuscation Reads from memory of another process 3 -

(Process #1) 0d2805a84af62c765ac706960cd2a4a1.exe reads from (process #2) 0d2805a84af62c765ac706960cd2a4a1.exe.

(Process #4) images.exe reads from (process #7) images.exe.

(Process #10) images.exe reads from (process #11) images.exe.

1/5 Obfuscation Creates a page with write and execute permissions 4 -

(Process #1) 0d2805a84af62c765ac706960cd2a4a1.exe allocates a page in a foreign process with "PAGE_EXECUTE_READWRITE" permissions, often used to dynamically unpack code.

(Process #4) images.exe allocates a page in a foreign process with "PAGE_EXECUTE_READWRITE" permissions, often used to dynamically unpack code.

(Process #7) images.exe allocates a page in a foreign process with "PAGE_EXECUTE_READWRITE" permissions, often used to dynamically unpack code.

(Process #10) images.exe allocates a page in a foreign process with "PAGE_EXECUTE_READWRITE" permissions, often used to dynamically unpack code.

1/5 Anti Analysis Tries to detect analyzer sandbox 1 -

(Process #2) 0d2805a84af62c765ac706960cd2a4a1.exe is possibly trying to detect analyzer sandbox by checking for patched sleep.

1/5 System Modification Modifies application directory 3 -

(Process #2) 0d2805a84af62c765ac706960cd2a4a1.exe modifies "c:\program files\microsoft dn1".

(Process #7) images.exe modifies "c:\program files\microsoft dn1".

(Process #11) images.exe modifies "c:\program files\microsoft dn1".

1/5 Network Connection Performs DNS request 1 -

(Process #7) images.exe resolves host name "nan.ydns.eu" to IP "-".

1/5 Execution Executes itself 5 -

(Process #1) 0d2805a84af62c765ac706960cd2a4a1.exe executes a copy of the sample at C:\Users\RDhJ0CNFevzX\Desktop\0d2805a84af62c765ac706960cd2a4a1.exe.

(Process #2) 0d2805a84af62c765ac706960cd2a4a1.exe executes a copy of the sample at C:\Users\RDhJ0CNFevzX\Desktop\0d2805a84af62c765ac706960cd2a4a1.exe.

(Process #4) images.exe executes a copy of the sample at C:\Users\RDhJ0CNFevzX\Desktop\0d2805a84af62c765ac706960cd2a4a1.exe.

(Process #10) images.exe executes a copy of the sample at C:\Users\RDhJ0CNFevzX\Desktop\0d2805a84af62c765ac706960cd2a4a1.exe.

(Process #11) images.exe executes a copy of the sample at C:\Users\RDhJ0CNFevzX\Desktop\0d2805a84af62c765ac706960cd2a4a1.exe.

(4)

Mitre ATT&CK Matrix

Initial Access Execution Persistence Privilege Escalation

Defense Evasion

Credential

Access Discovery Lateral

Movement Collection Command

and Control Exfiltration Impact

#T1143 Hidden Window

#T1057 Process Discovery

#T1045 Software Packing

#T1497 Virtualization/

Sandbox Evasion

#T1497 Virtualization/

Sandbox Evasion

#T1124 System Time

Discovery

#T1096 NTFS File Attributes

X-Ray Vision for Malware - www.vmray.com 4 / 31

(5)

Sample Information

Analysis Information

ID #1077621

MD5 592cbf02a35ee0358194b33c483be874

SHA1 ae04e74a104cd6d2d00331111f0f2596c86eeb2e

SHA256 2c12f9be67bf31375db1b0578920fa37b415ec1a2df56cc1f3dacd9985f60100

SSDeep 6144:BQIxNYrJYEfv9Ykr7DVLq1YV+8TzAB/KOnTSE0K8LvfDEQXWUtin2H+:yrZfeec1Yf/AwOn3094Kb3+

ImpHash f34d5f2d4577ed6d9ceec516c1f5a744

File Name 0d2805a84af62c765ac706960cd2a4a1.exe

File Size 339.00 KB

Sample Type Windows Exe (x86-32)

Has Macros

Creation Time 2021-10-26 16:21 (UTC+2)

Analysis Duration 00:04:00

Termination Reason Timeout

Number of Monitored Processes 12

Execution Successful False

Reputation Enabled

WHOIS Enabled

Built-in AV Enabled

Built-in AV Applied On Sample Files, PCAP File, Downloaded Files, Dropped Files, Modified Files, Memory Dumps, Embedded Files

Number of AV Matches 40

YARA Enabled

YARA Applied On Sample Files, PCAP File, Downloaded Files, Dropped Files, Modified Files, Memory Dumps, Embedded Files

Number of YARA Matches 0

(6)

X-Ray Vision for Malware - www.vmray.com 6 / 31

(7)

Screenshots truncated

(8)

NETWORK

General

DNS

HTTP/S

DNS Requests

Type Hostname Response Code Resolved IPs CNames Verdict

0 bytes total sent

0 bytes total received 0 ports

1 contacted IP addresses

0 URLs extracted 0 files downloaded

0 malicious hosts detected

1 DNS requests for 1 domains 1 nameservers contacted

0 total requests returned errors

0 URLs contacted, 0 servers

0 sessions, 0 bytes sent, 0 bytes received

A nan.ydns.eu NoError 195.133.40.125 NA

X-Ray Vision for Malware - www.vmray.com 8 / 31

(9)

BEHAVIOR

Process Graph

Sample Start #1

0d2805a84af62c765ac706960cd2a4a1.exe #2

0d2805a84af62c765ac706960cd2a4a1.exe Modify Memory

Modify Control Flow Child Process

#3 cmd.exe Child Process

#4 images.exe Child Process

#6 reg.exe Child Process

#7 images.exe Modify Memory

Modify Control Flow Child Process

#8 cmd.exe Modify Memory

Create Remote Thread Child Process

Reboot #1 #10

images.exe

#11 images.exe Modify Memory

Modify Control Flow Child Process

#12 cmd.exe Child Process

#13 images.exe Child Process

#15 reg.exe Child Process

(10)

Process #1: 0d2805a84af62c765ac706960cd2a4a1.exe

Dropped Files (1)

File Name File Size SHA256 YARA Match

Host Behavior

Type Count

ID 1

File Name c:\users\rdhj0cnfevzx\desktop\0d2805a84af62c765ac706960cd2a4a1.exe Command Line "C:\Users\RDhJ0CNFevzX\Desktop\0d2805a84af62c765ac706960cd2a4a1.exe"

Initial Working Directory C:\Users\RDhJ0CNFevzX\Desktop\

Monitor Start Time Start Time: 51003, Reason: Analysis Target Unmonitor End Time End Time: 115609, Reason: Terminated

Monitor duration 64.61s

Return Code 0

PID 5032

Parent PID 1636

Bitness 32 Bit

C:

\Users\RDhJ0CNFevzX\AppData\Local\Temp\0d2805a84af62c765ac

706960cd2a4a1.exe 339.00 KB 2c12f9be67bf31375db1b0578920fa37b415ec1a2df56cc1f3dacd9985f60

100

File 5

User 1

Process 111

Module 57

- 3

System 111

- 9

X-Ray Vision for Malware - www.vmray.com 10 / 31

(11)

Process #2: 0d2805a84af62c765ac706960cd2a4a1.exe

Injection Information (8)

Injection Type Source Process Source / Target TID Address / Name Size Success Count

Dropped Files (1)

File Name File Size SHA256 YARA Match

Host Behavior

Type Count

ID 2

File Name c:\users\rdhj0cnfevzx\appdata\local\temp\0d2805a84af62c765ac706960cd2a4a1.exe Command Line C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\0d2805a84af62c765ac706960cd2a4a1.exe

Initial Working Directory C:\Users\RDhJ0CNFevzX\Desktop\

Monitor Start Time Start Time: 104515, Reason: Child Process Unmonitor End Time End Time: 125847, Reason: Terminated

Monitor duration 21.33s

Return Code 0

PID 3528

Parent PID 5032

Bitness 32 Bit

Modify Memory

#1: c:

\users\rdhj0cnfevzx\desktop

\0d2805a84af62c765ac7069 60cd2a4a1.exe

0x13a0 0x400000(4194304) 0x400 1

Modify Memory

#1: c:

\users\rdhj0cnfevzx\desktop

\0d2805a84af62c765ac7069 60cd2a4a1.exe

0x13a0 0x401000(4198400) 0x15200 1

Modify Memory

#1: c:

\users\rdhj0cnfevzx\desktop

\0d2805a84af62c765ac7069 60cd2a4a1.exe

0x13a0 0x417000(4288512) 0x5000 1

Modify Memory

#1: c:

\users\rdhj0cnfevzx\desktop

\0d2805a84af62c765ac7069 60cd2a4a1.exe

0x13a0 0x41c000(4308992) 0xa800 1

Modify Memory

#1: c:

\users\rdhj0cnfevzx\desktop

\0d2805a84af62c765ac7069 60cd2a4a1.exe

0x13a0 0x55b000(5615616) 0x1200 1

Modify Memory

#1: c:

\users\rdhj0cnfevzx\desktop

\0d2805a84af62c765ac7069 60cd2a4a1.exe

0x13a0 0x55d000(5623808) 0x200 1

Modify Memory

#1: c:

\users\rdhj0cnfevzx\desktop

\0d2805a84af62c765ac7069 60cd2a4a1.exe

0x13a0 0x245008(2379784) 0x4 1

Modify Control Flow

#1: c:

\users\rdhj0cnfevzx\desktop

\0d2805a84af62c765ac7069 60cd2a4a1.exe

0x13a0 / 0x600 - 1

C:\ProgramData\images.exe 339.00 KB 2c12f9be67bf31375db1b0578920fa37b415ec1a2df56cc1f3dacd9985f60

100

Mutex 14

COM 1

(12)

Type Count

System 142

- 8

Module 18

File 8

Registry 7

Process 2

X-Ray Vision for Malware - www.vmray.com 12 / 31

(13)

Process #3: cmd.exe

Host Behavior

Type Count

ID 3

File Name c:\windows\syswow64\cmd.exe

Command Line cmd.exe /c REG ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /f /v Load /t REG_SZ /d "C:\ProgramData\images.exe"

Initial Working Directory C:\Users\RDhJ0CNFevzX\Desktop\

Monitor Start Time Start Time: 121592, Reason: Child Process Unmonitor End Time End Time: 140075, Reason: Terminated

Monitor duration 18.48s

Return Code 0

PID 3136

Parent PID 3528

Bitness 32 Bit

Module 8

Registry 17

File 17

Environment 19

System 1

Process 1

(14)

Process #4: images.exe

Dropped Files (1)

File Name File Size SHA256 YARA Match

Host Behavior

Type Count

ID 4

File Name c:\programdata\images.exe

Command Line "C:\ProgramData\images.exe"

Initial Working Directory C:\Users\RDhJ0CNFevzX\Desktop\

Monitor Start Time Start Time: 121953, Reason: Child Process Unmonitor End Time End Time: 159891, Reason: Terminated

Monitor duration 37.94s

Return Code 0

PID 2908

Parent PID 3528

Bitness 32 Bit

C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\images.exe 339.00 KB 2c12f9be67bf31375db1b0578920fa37b415ec1a2df56cc1f3dacd9985f60 100

File 5

User 1

Process 108

Module 56

- 3

System 108

- 9

X-Ray Vision for Malware - www.vmray.com 14 / 31

(15)

Process #6: reg.exe

Host Behavior

Type Count

ID 6

File Name c:\windows\syswow64\reg.exe

Command Line REG ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /f /v Load /t REG_SZ /d "C:\ProgramData\images.exe"

Initial Working Directory C:\Users\RDhJ0CNFevzX\Desktop\

Monitor Start Time Start Time: 138732, Reason: Child Process Unmonitor End Time End Time: 140051, Reason: Terminated

Monitor duration 1.32s

Return Code 0

PID 1256

Parent PID 3136

Bitness 32 Bit

Module 1

Registry 4

File 6

(16)

Process #7: images.exe

Injection Information (8)

Injection Type Source Process Source / Target TID Address / Name Size Success Count

Host Behavior

Type Count

ID 7

File Name c:\users\rdhj0cnfevzx\appdata\local\temp\images.exe Command Line C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\images.exe

Initial Working Directory C:\Users\RDhJ0CNFevzX\Desktop\

Monitor Start Time Start Time: 157628, Reason: Child Process Unmonitor End Time End Time: 169969, Reason: Terminated

Monitor duration 12.34s

Return Code 1073807364

PID 3168

Parent PID 2908

Bitness 32 Bit

Modify Memory #4: c:

\programdata\images.exe 0x960 0x400000(4194304) 0x400 1

Modify Memory #4: c:

\programdata\images.exe 0x960 0x401000(4198400) 0x15200 1

Modify Memory #4: c:

\programdata\images.exe 0x960 0x417000(4288512) 0x5000 1

Modify Memory #4: c:

\programdata\images.exe 0x960 0x41c000(4308992) 0xa800 1

Modify Memory #4: c:

\programdata\images.exe 0x960 0x55b000(5615616) 0x1200 1

Modify Memory #4: c:

\programdata\images.exe 0x960 0x55d000(5623808) 0x200 1

Modify Memory #4: c:

\programdata\images.exe 0x960 0x37f008(3665928) 0x4 1

Modify Control Flow #4: c:

\programdata\images.exe 0x960 / 0x6a0 - 1

Mutex 8

COM 1

System 144

- 8

Module 19

File 5

Registry 6

Process 2

- 5

- 1

X-Ray Vision for Malware - www.vmray.com 16 / 31

(17)

Network Behavior

Type Count

DNS 1

(18)

Process #8: cmd.exe

Injection Information (3)

Injection Type Source Process Source / Target TID Address / Name Size Success Count

Host Behavior

Type Count

ID 8

File Name c:\windows\syswow64\cmd.exe

Command Line "C:\Windows\System32\cmd.exe"

Initial Working Directory C:\Users\RDhJ0CNFevzX\Desktop\

Monitor Start Time Start Time: 163834, Reason: Child Process Unmonitor End Time End Time: 170277, Reason: Terminated

Monitor duration 6.44s

Return Code 1073807364

PID 3672

Parent PID 3168

Bitness 32 Bit

Modify Memory #7: c:

\users\rdhj0cnfevzx\appdata

\local\temp\images.exe 0x6a0 0x1f0000(2031616) 0x800 1

Modify Memory #7: c:

\users\rdhj0cnfevzx\appdata

\local\temp\images.exe 0x6a0 0x440000(4456448) 0x103 1

Create Remote Thread #7: c:

\users\rdhj0cnfevzx\appdata

\local\temp\images.exe 0x6a0 0x1f010e(2031886) - 1

Module 11

Registry 17

File 62

Environment 12

System 3

X-Ray Vision for Malware - www.vmray.com 18 / 31

(19)

Process #10: images.exe

Host Behavior

Type Count

ID 10

File Name c:\programdata\images.exe

Command Line "C:\ProgramData\images.exe"

Initial Working Directory C:\Windows\

Monitor Start Time Start Time: 244271, Reason: Autostart Unmonitor End Time End Time: 276885, Reason: Terminated

Monitor duration 32.61s

Return Code 0

PID 3272

Parent PID 1528

Bitness 32 Bit

File 5

User 1

Process 36

Module 56

- 3

System 36

- 9

(20)

Process #11: images.exe

Injection Information (8)

Injection Type Source Process Source / Target TID Address / Name Size Success Count

Dropped Files (1)

File Name File Size SHA256 YARA Match

Host Behavior

Type Count

ID 11

File Name c:\users\rdhj0cnfevzx\appdata\local\temp\images.exe Command Line C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\images.exe

Initial Working Directory C:\Windows\

Monitor Start Time Start Time: 274317, Reason: Child Process Unmonitor End Time End Time: 279450, Reason: Terminated

Monitor duration 5.13s

Return Code 0

PID 3612

Parent PID 3272

Bitness 32 Bit

Modify Memory #10: c:

\programdata\images.exe 0xccc 0x400000(4194304) 0x400 1

Modify Memory #10: c:

\programdata\images.exe 0xccc 0x401000(4198400) 0x15200 1

Modify Memory #10: c:

\programdata\images.exe 0xccc 0x417000(4288512) 0x5000 1

Modify Memory #10: c:

\programdata\images.exe 0xccc 0x41c000(4308992) 0xa800 1

Modify Memory #10: c:

\programdata\images.exe 0xccc 0x55b000(5615616) 0x1200 1

Modify Memory #10: c:

\programdata\images.exe 0xccc 0x55d000(5623808) 0x200 1

Modify Memory #10: c:

\programdata\images.exe 0xccc 0x36e008(3596296) 0x4 1

Modify Control Flow #10: c:

\programdata\images.exe 0xccc / 0xe20 - 1

C:\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe 339.00 KB 2c12f9be67bf31375db1b0578920fa37b415ec1a2df56cc1f3dacd9985f60 100

Mutex 14

COM 1

System 142

- 8

Module 18

File 8

Registry 7

Process 2

X-Ray Vision for Malware - www.vmray.com 20 / 31

(21)

Process #12: cmd.exe

Host Behavior

Type Count

ID 12

File Name c:\windows\syswow64\cmd.exe

Command Line cmd.exe /c REG ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /f /v Load /t REG_SZ /d "C:

\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe"

Initial Working Directory C:\Windows\

Monitor Start Time Start Time: 276888, Reason: Child Process Unmonitor End Time End Time: 279760, Reason: Terminated

Monitor duration 2.87s

Return Code 0

PID 3644

Parent PID 3612

Bitness 32 Bit

Module 8

Registry 17

File 15

Environment 19

System 1

Process 1

(22)

Process #13: images.exe

Host Behavior

Type Count

ID 13

File Name c:\users\rdhj0cnfevzx\appdata\roaming\images.exe Command Line "C:\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe"

Initial Working Directory C:\Windows\

Monitor Start Time Start Time: 276924, Reason: Child Process Unmonitor End Time End Time: 298617, Reason: Terminated by Timeout

Monitor duration 21.69s

Return Code Unknown

PID 3652

Parent PID 3612

Bitness 32 Bit

File 1

X-Ray Vision for Malware - www.vmray.com 22 / 31

(23)

Process #15: reg.exe

Host Behavior

Type Count

ID 15

File Name c:\windows\syswow64\reg.exe

Command Line REG ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /f /v Load /t REG_SZ /d "C:

\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe"

Initial Working Directory C:\Windows\

Monitor Start Time Start Time: 278464, Reason: Child Process Unmonitor End Time End Time: 279333, Reason: Terminated

Monitor duration 0.87s

Return Code 0

PID 3696

Parent PID 3644

Bitness 32 Bit

Module 1

Registry 4

File 6

(24)

ARTIFACTS

File

SHA256 File Names Category File Size MIME Type Operations Verdict

Filename

File Name Category Operations Verdict

2c12f9be67bf31375db1b057 8920fa37b415ec1a2df56cc1f 3dacd9985f60100

C:

\Users\RDhJ0CNFevzX\AppData\Ro aming\images.exe, C:

\ProgramData\images.exe, C:

\Users\RDhJ0CNFevzX\Desktop\0d2 805a84af62c765ac7069... ...C:

\Users\RDhJ0CNFevzX\AppData\Loc al\Temp\images.exe, C:

\Users\RDhJ0CNFevzX\AppData\Loc al\Temp\0d2805a84af62c765ac706960 cd2a4a1.exe

Sample File 339.00 KB application/

vnd.microsoft.portable-

executable Read, Create, Access, Write MALICIOUS

C:

\Users\RDhJ0CNFevzX\Desktop\0d2805a84af62c765ac706960cd2a4

a1.exe.config Accessed File Access CLEAN

C:

\Users\RDhJ0CNFevzX\Desktop\0d2805a84af62c765ac706960cd2a4

a1.exe Sample File Access CLEAN

C:\Windows\SYSTEM32\ntdll.dll Accessed File Access CLEAN

C:\Windows\SYSTEM32\MSCOREE.DLL Accessed File Access CLEAN

C:\Windows\SYSTEM32\KERNEL32.dll Accessed File Access CLEAN

C:\Windows\SYSTEM32\KERNELBASE.dll Accessed File Access CLEAN

C:\Windows\system32\apphelp.dll Accessed File Access CLEAN

C:\Windows\SYSTEM32\ADVAPI32.dll Accessed File Access CLEAN

C:\Windows\SYSTEM32\msvcrt.dll Accessed File Access CLEAN

C:\Windows\SYSTEM32\sechost.dll Accessed File Access CLEAN

C:\Windows\SYSTEM32\RPCRT4.dll Accessed File Access CLEAN

C:\Windows\SYSTEM32\SspiCli.dll Accessed File Access CLEAN

C:\Windows\SYSTEM32\CRYPTBASE.dll Accessed File Access CLEAN

C:\Windows\SYSTEM32\bcryptPrimitives.dll Accessed File Access CLEAN

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll Accessed File Access CLEAN

C:\Windows\SYSTEM32\SHLWAPI.dll Accessed File Access CLEAN

C:\Windows\SYSTEM32\combase.dll Accessed File Access CLEAN

C:\Windows\SYSTEM32\GDI32.dll Accessed File Access CLEAN

C:\Windows\SYSTEM32\USER32.dll Accessed File Access CLEAN

C:\Windows\SYSTEM32\IMM32.DLL Accessed File Access CLEAN

C:\Windows\SYSTEM32\kernel.appcore.dll Accessed File Access CLEAN

C:\Windows\SYSTEM32\VERSION.dll Accessed File Access CLEAN

C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll Accessed File Access CLEAN

C:\Windows\SYSTEM32\MSVCR120_CLR0400.dll Accessed File Access CLEAN

C:

\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\8062d42

7acd64e37f4fded7b00f4a869\mscorlib.ni.dll Accessed File Access CLEAN

X-Ray Vision for Malware - www.vmray.com 24 / 31

(25)

File Name Category Operations Verdict

Domain

Domain IP Address Country Protocols Verdict

IP

IP Address Domains Country Protocols Verdict

Registry

Registry Key Operations Parent Process Name Verdict

C:\Windows\SYSTEM32\ole32.dll Accessed File Access CLEAN

C:\Windows\system32\uxtheme.dll Accessed File Access CLEAN

C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll Accessed File Access CLEAN

C:\Windows\SYSTEM32\OLEAUT32.dll Accessed File Access CLEAN

C:

\Windows\assembly\NativeImages_v4.0.30319_32\System\cc4e5d11

0dd318e8b7d61a9ed184ab74\System.ni.dll Accessed File Access CLEAN

C:\Windows\SYSTEM32\psapi.dll Accessed File Access CLEAN

C:\Windows\Microsoft.NET\Framework\v4.0.30319\Itself.exe Accessed File Access CLEAN

C:

\Users\RDhJ0CNFevzX\AppData\Local\Temp\0d2805a84af62c765ac

706960cd2a4a1.exe Sample File Read, Create, Access, Write CLEAN

C:\Program Files\Microsoft DN1 Accessed File Create, Access CLEAN

C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft Vision\ Accessed File Create, Access CLEAN

C:\ProgramData Accessed File Create, Access CLEAN

C:\ProgramData\images.exe Sample File Create, Access, Write CLEAN

C:\ProgramData\images.exe:Zone.Identifier Accessed File Delete, Access CLEAN

C:\Windows\SysWOW64\cmd.exe Accessed File Access CLEAN

C:\Users\RDhJ0CNFevzX\Desktop Accessed File Access CLEAN

C:\ProgramData\images.exe.config Accessed File Access CLEAN

C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\images.exe Sample File Read, Create, Access, Write CLEAN

C:\Users\RDhJ0CNFevzX\AppData\Roaming Accessed File Create, Access CLEAN

C:\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe Sample File Create, Access, Write CLEAN

C:

\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe:Zone.Identifi

er Accessed File Delete, Access CLEAN

C:\Windows Accessed File Access CLEAN

C:\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe.config Accessed File Access CLEAN

nan.ydns.eu 195.133.40.125 - DNS MALICIOUS

192.168.0.1 - - DNS, UDP CLEAN

195.133.40.125 nan.ydns.eu Czech Rep. DNS CLEAN

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVer

sion\Internet Settings create, access 0d2805a84af62c765ac706960cd2a4a1.exe, images.exe CLEAN

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVer

sion\Internet Settings\MaxConnectionsPer1_0Server write, access 0d2805a84af62c765ac706960cd2a4a1.exe, images.exe CLEAN

(26)

Registry Key Operations Parent Process Name Verdict

Process

Process Name Commandline Verdict

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVer

sion\Internet Settings\MaxConnectionsPerServer write, access 0d2805a84af62c765ac706960cd2a4a1.exe, images.exe CLEAN

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVer

sion\Explorer\1VDK9FWJ7BWX4Q78 create, access 0d2805a84af62c765ac706960cd2a4a1.exe, images.exe CLEAN

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVer

sion\Explorer\1VDK9FWJ7BWX4Q78\inst read, write, access 0d2805a84af62c765ac706960cd2a4a1.exe, images.exe CLEAN

HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Sy

stem access cmd.exe CLEAN

HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor access cmd.exe CLEAN

HKEY_LOCAL_MACHINE\Software\Microsoft\Command

Processor\DisableUNCCheck read, access cmd.exe CLEAN

HKEY_LOCAL_MACHINE\Software\Microsoft\Command

Processor\EnableExtensions read, access cmd.exe CLEAN

HKEY_LOCAL_MACHINE\Software\Microsoft\Command

Processor\DelayedExpansion read, access cmd.exe CLEAN

HKEY_LOCAL_MACHINE\Software\Microsoft\Command

Processor\DefaultColor read, access cmd.exe CLEAN

HKEY_LOCAL_MACHINE\Software\Microsoft\Command

Processor\CompletionChar read, access cmd.exe CLEAN

HKEY_LOCAL_MACHINE\Software\Microsoft\Command

Processor\PathCompletionChar read, access cmd.exe CLEAN

HKEY_LOCAL_MACHINE\Software\Microsoft\Command

Processor\AutoRun read, access cmd.exe CLEAN

HKEY_CURRENT_USER\Software\Microsoft\Command Processor access cmd.exe CLEAN

HKEY_CURRENT_USER\Software\Microsoft\Command

Processor\DisableUNCCheck read, access cmd.exe CLEAN

HKEY_CURRENT_USER\Software\Microsoft\Command

Processor\EnableExtensions read, access cmd.exe CLEAN

HKEY_CURRENT_USER\Software\Microsoft\Command

Processor\DelayedExpansion read, access cmd.exe CLEAN

HKEY_CURRENT_USER\Software\Microsoft\Command

Processor\DefaultColor read, access cmd.exe CLEAN

HKEY_CURRENT_USER\Software\Microsoft\Command

Processor\CompletionChar read, access cmd.exe CLEAN

HKEY_CURRENT_USER\Software\Microsoft\Command

Processor\PathCompletionChar read, access cmd.exe CLEAN

HKEY_CURRENT_USER\Software\Microsoft\Command

Processor\AutoRun read, access cmd.exe CLEAN

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVer

sion\Policies\System access reg.exe CLEAN

HKEY_CURRENT_USER\Software\Microsoft\Windows

NT\CurrentVersion\Windows create, access reg.exe CLEAN

HKEY_CURRENT_USER\Software\Microsoft\Windows

NT\CurrentVersion\Windows\Load read, write, access reg.exe CLEAN

0d2805a84af62c765ac706960cd2a4a1.exe "C:\Users\RDhJ0CNFevzX\Desktop\0d2805a84af62c765ac706960cd2a4a1.exe" MALICIOUS

images.exe "C:\ProgramData\images.exe" MALICIOUS

images.exe "C:\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe" MALICIOUS

0d2805a84af62c765ac706960cd2a4a1.exe C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\0d2805a84af62c765ac706960cd2a4a1.exe SUSPICIOUS

images.exe C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\images.exe SUSPICIOUS

images.exe "C:\ProgramData\images.exe" SUSPICIOUS

X-Ray Vision for Malware - www.vmray.com 26 / 31

(27)

Process Name Commandline Verdict cmd.exe cmd.exe /c REG ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /f /v Load

/t REG_SZ /d "C:\ProgramData\images.exe" CLEAN

reg.exe REG ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /f /v Load /t REG_SZ

/d "C:\ProgramData\images.exe" CLEAN

cmd.exe "C:\Windows\System32\cmd.exe" CLEAN

cmd.exe cmd.exe /c REG ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /f /v Load

/t REG_SZ /d "C:\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe" CLEAN

reg.exe REG ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /f /v Load /t REG_SZ

/d "C:\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe" CLEAN

(28)

YARA / AV

Antivirus (40)

File Type Threat Name File Name Verdict

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Gen:Variant.Strictor.46025 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

X-Ray Vision for Malware - www.vmray.com 28 / 31

(29)

File Type Threat Name File Name Verdict

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS

(30)

ENVIRONMENT

Virtual Machine Information

Platform Information

Anti Virus Information

Software Information

System Information

Name win10_64_th2_en_mso2016

Description win10_64_th2_en_mso2016

Architecture x86 64-bit

Operating System Windows 10 Threshold 2

Kernel Version 10.0.10586.0 (0de6dc23-8e19-4bb7-8608-d54b1e6fa379)

Network Scheme Name Local Gateway

Network Config Name Local Gateway

Platform Version 4.3.0

Dynamic Engine Version 4.3.0 / 09/20/2021 03:59

Static Engine Version 4.3.0.0 / 2021-09-20 03:00:12

AV Exceptions Version 4.3.1.6 / 2021-09-21 13:25:28 Link Detonation Heuristics Version 4.3.1.6 / 2021-09-21 13:25:28

Signature Trust Store Version 4.3.1.6 / 2021-09-21 13:25:28

VMRay Threat Identifiers Version 4.3.1.16 / 2021-10-20 13:20:51 YARA Built-in Ruleset Version 4.3.1.11

Built-in AV Version AVCORE v2.2 Linux/x86_64 11.0.1.19 (March 15, 2021) Built-in AV Database Update Release

Date 2021-10-26 11:48:59+00:00

Built-in AV Database Records 11041076

Adobe Acrobat Reader Version Not installed

Microsoft Office 2016

Microsoft Office Version 16.0.4266.1003

Hangul Office Not installed

Hangul Office Version Not installed

Internet Explorer Version 11.0.10586.0

Chrome Version Not installed

Firefox Version Not installed

Flash Version Not installed

Java Version Not installed

Sample Directory C:\Users\RDhJ0CNFevzX\Desktop

Computer Name XC64ZB

User Domain XC64ZB

X-Ray Vision for Malware - www.vmray.com 30 / 31

(31)

User Name RDhJ0CNFevzX

User Profile C:\Users\RDhJ0CNFevzX

Temp Directory C:\Users\RDHJ0C~1\AppData\Local\Temp

System Root C:\Windows

References

Related documents