Sample name: | ZmWSzgevgt.exerenamed because original name is a hash value |
Original sample name: | 4f2d5d155fe7497f9ab429cae34c5ebbdd711b0256b3bae83d9038cf1526c724.exe |
Analysis ID: | 1354609 |
MD5: | 2deaf2be4672bf6457e136d78a7a3940 |
SHA1: | f8460d05dbdb1c171818510c9685847d00468349 |
SHA256: | 4f2d5d155fe7497f9ab429cae34c5ebbdd711b0256b3bae83d9038cf1526c724 |
Tags: | exe |
Infos: | |
NetSupport RAT, LummaC Stealer
Score: | 64 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Yara detected LummaC Stealer
Binary is likely a compiled AutoIt script file
Contains functionality to detect sleep reduction / modifications
Creates an undocumented autostart registry key
Obfuscated command line found
Performs DNS queries to domains with low reputation
Query firmware table information (likely to detect VMs)
Uses known network protocols on non-standard ports
Yara detected Generic Downloader
Adds / modifies Windows certificates
Binary contains a suspicious time stamp
Checks for available system drives (often done to infect USB drives)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Connects to many different domains
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to dynamically determine API calls
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to query network adapater information
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Deletes files inside the Windows folder
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Downloads executable code via HTTP
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Drops PE files to the windows directory (C:\Windows)
Drops files with a non-matching file extension (content does not match file extension)
Enables debug privileges
Enables security privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
HTML body contains low number of good links
HTML title does not match URL
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May check if the current machine is a sandbox (GetTickCount - Sleep)
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive Operating System Information (via WMI, Win32_ComputerSystem, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Stores large binary data to the registry
Tries to load missing DLLs
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Uses insecure TLS / SSL version for HTTPS connection
Uses reg.exe to modify the Windows registry
Uses taskkill to terminate processes
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara detected Keylogger Generic
Yara detected NetSupport remote tool
- System is w10x64
- ZmWSzgevgt.exe (PID: 6184 cmdline:
C:\Users\u ser\Deskto p\ZmWSzgev gt.exe MD5: 2DEAF2BE4672BF6457E136D78A7A3940) - ZmWSzgevgt.tmp (PID: 5240 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\is-P5S F5.tmp\ZmW Szgevgt.tm p" /SL5="$ 20408,8325 12,832512, C:\Users\u ser\Deskto p\ZmWSzgev gt.exe" MD5: BE0E74DC6AC70C5B8CC74C42B6999A70) - setup.exe (PID: 5800 cmdline:
C:\Users\u ser\AppDat a\Local\Te mp\is-0270 L.tmp\setu p.exe MD5: 8657D8F7608F1E03726F5B0256869C66) - setup.tmp (PID: 1992 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\is-UKD SG.tmp\set up.tmp" /S L5="$1047E ,4289520,8 32512,C:\U sers\user\ AppData\Lo cal\Temp\i s-0270L.tm p\setup.ex e" MD5: C039C014580F43E5B8162552F3CAF067) - a0.exe (PID: 2724 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\is-53U S7.tmp\a0. exe" /VERY SILENT /PA SSWORD=NtI RVUpMK9ZD3 0Nf98220 - token mtn1 co3fo4gs5v wq -subid 2598 MD5: 5AFE9D5A2BCC39B1E0573A77EFBE82B7) - a0.tmp (PID: 3172 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\is-8LR UI.tmp\a0. tmp" /SL5= "$204E6,10 235147,832 512,C:\Use rs\user\Ap pData\Loca l\Temp\is- 53US7.tmp\ a0.exe" /V ERYSILENT /PASSWORD= NtIRVUpMK9 ZD30Nf9822 0 -token m tn1co3fo4g s5vwq -sub id 2598 MD5: AD96645518D5ABDD4F96B007E799F61E) - cmd.exe (PID: 1472 cmdline:
"cmd.exe" /c expand C:\Users\u ser\AppDat a\Local\Te mp\is-TMJS M.tmp\{app }\aglwjhm. cab -F:* % ProgramDat a% MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 5640 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - expand.exe (PID: 5696 cmdline:
expand C:\ Users\user \AppData\L ocal\Temp\ is-TMJSM.t mp\{app}\a glwjhm.cab -F:* C:\P rogramData MD5: 544B0DBFF3F393BCE8BB9D815F532D51) - cmd.exe (PID: 6036 cmdline:
"cmd.exe" /c reg add "HKEY_CUR RENT_USER\ Environmen t" /v User InitMprLog onScript / t REG_EXPA ND_SZ /d " %ProgramDa ta%\regid. 1993-06.co m.microsof t\wmiprvse .exe" /f MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 4368 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - reg.exe (PID: 5020 cmdline:
reg add "H KEY_CURREN T_USER\Env ironment" /v UserIni tMprLogonS cript /t R EG_EXPAND_ SZ /d "C:\ ProgramDat a\regid.19 93-06.com. microsoft\ wmiprvse.e xe" /f MD5: CDD462E86EC0F20DE2A1D781928B1B0C) - wmiprvse.exe (PID: 6024 cmdline:
C:\Program Data\regid .1993-06.c om.microso ft\wmiprvs e.exe MD5: 261D6E9D4571D1938CB54A2AE1B1821D) - cmd.exe (PID: 1964 cmdline:
"cmd.exe" /c start h ttps://axs boe-campai gn.com/pix el?pmhzmq= fhoohvpn6e 7i^&c=5306 757^&pl=0x 03^&pb=1^& px=2598 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 5728 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - chrome.exe (PID: 5556 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// axsboe-cam paign.com/ pixel?pmhz mq=fhoohvp n6e7i&c=53 06757&pl=0 x03&pb=1&p x=2598 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 2972 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2132 --fi eld-trial- handle=194 4,i,729332 6498590966 015,157242 2170191744 7522,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - a1.exe (PID: 7588 cmdline:
C:\Users\u ser\AppDat a\Local\Te mp\is-53US 7.tmp\a1.e xe" /qn CA MPAIGN="25 98 MD5: FA24733F5A6A6F44D0E65D7D98B84AA6) - msiexec.exe (PID: 6192 cmdline:
C:\Windows \system32\ msiexec.ex e" /i "C:\ Users\user \AppData\R oaming\AW Manager\Wi ndows Mana ger 1.0.0\ install\97 FDF62\Wind ows Manage r - Postba ck Johan.m si" /qn CA MPAIGN=259 8 AI_SETUP EXEPATH=C: \Users\use r\AppData\ Local\Temp \is-53US7. tmp\a1.exe SETUPEXED IR=C:\User s\user\App Data\Local \Temp\is-5 3US7.tmp\ EXE_CMD_LI NE="/exeno updates /f orcecleanu p /wintime 170186937 4 /qn CAMP AIGN=""259 8"" " CAMP AIGN="2598 MD5: 9D09DC1EDA745A5F87553048E57620CF)
- msiexec.exe (PID: 7932 cmdline:
C:\Windows \system32\ msiexec.ex e /V MD5: E5DA170027542E25EDE42FC54C929077) - msiexec.exe (PID: 8052 cmdline:
C:\Windows \syswow64\ MsiExec.ex e -Embeddi ng 7B2098D E867FDA1FB AC9E94E8D3 11FE9 C MD5: 9D09DC1EDA745A5F87553048E57620CF) - msiexec.exe (PID: 6972 cmdline:
C:\Windows \syswow64\ MsiExec.ex e -Embeddi ng CB3F137 362C364F2A 010C44D44B 9B692 MD5: 9D09DC1EDA745A5F87553048E57620CF) - taskkill.exe (PID: 7756 cmdline:
"C:\Window s\SysWOW64 \taskkill. exe" /im A dvancedWin dowsManage r* /f MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD) - conhost.exe (PID: 7780 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - msiexec.exe (PID: 7400 cmdline:
C:\Windows \syswow64\ MsiExec.ex e -Embeddi ng A0F7B99 CF6F596956 15DF13CC64 61763 E Gl obal\MSI00 00 MD5: 9D09DC1EDA745A5F87553048E57620CF) - msiexec.exe (PID: 7824 cmdline:
C:\Windows \syswow64\ MsiExec.ex e -Embeddi ng 9A41533 8A0E06E3AA 66F7530B5F E606F C MD5: 9D09DC1EDA745A5F87553048E57620CF) - msiexec.exe (PID: 8128 cmdline:
C:\Windows \syswow64\ MsiExec.ex e -Embeddi ng 50B63A9 4597415634 C568616DD5 51356 E Gl obal\MSI00 00 MD5: 9D09DC1EDA745A5F87553048E57620CF) - taskkill.exe (PID: 7560 cmdline:
"C:\Window s\SysWOW64 \taskkill. exe" /im A dvancedWin dowsManage r* /f MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD) - conhost.exe (PID: 8160 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - taskkill.exe (PID: 4012 cmdline:
"C:\Window s\SysWOW64 \taskkill. exe" /im A dvancedWin dowsManage r* /f MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD) - conhost.exe (PID: 7312 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - taskkill.exe (PID: 7360 cmdline:
"C:\Window s\SysWOW64 \taskkill. exe" /im A dvancedWin dowsManage r* /f MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD) - conhost.exe (PID: 7504 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- Windows Updater.exe (PID: 5572 cmdline:
"C:\Progra m Files (x 86)\AW Man ager\Windo ws Manager \Windows U pdater.exe " /silenta ll -nofreq check -nog ui MD5: F95007206C6B2407FB69748EF7C93612) - Windows Updater.exe (PID: 6304 cmdline:
C:\Windows \TEMP\ce2d 31339cfff4 1b4b6db9e3 2e93218c\W indows Upd ater.exe" /install s ilentall " C:\Windows \TEMP\ce2d 31339cfff4 1b4b6db9e3 2e93218c\W indows Upd ater.ini MD5: F95007206C6B2407FB69748EF7C93612) - v113.exe (PID: 7476 cmdline:
"C:\Progra mData\AW M anager\Win dows Manag er\updates \v113\v113 .exe" MD5: 8CAD036C5CFED94D5319A060C488E38F) - msiexec.exe (PID: 2928 cmdline:
"C:\Window s\system32 \msiexec.e xe" /i "C: \AppData\R oaming\Adv ancedWindo wsManager\ Windows In staller 5. 0.3\instal l\7EB1504\ System Upd ater.msi" AI_SETUPEX EPATH="C:\ ProgramDat a\AW Manag er\Windows Manager\u pdates\v11 3\v113.exe " SETUPEXE DIR="C:\Pr ogramData\ AW Manager \Windows M anager\upd ates\v113\ " EXE_CMD_ LINE="/exe noupdates /forceclea nup /winti me 1701869 374 " MD5: 9D09DC1EDA745A5F87553048E57620CF)
- AdvancedWindowsManager.exe (PID: 5808 cmdline:
"C:\Progra m Files (x 86)\AW Man ager\Windo ws Manager \AdvancedW indowsMana ger.exe" - v 110 -t 8 080 MD5: 26F21ED76944ED83382851D9F2453B0E)
- AdvancedWindowsManager.exe (PID: 7908 cmdline:
"C:\Progra m Files (x 86)\AW Man ager\Windo ws Manager \AdvancedW indowsMana ger.exe" - v 111 -t 8 080 MD5: 26F21ED76944ED83382851D9F2453B0E) - conhost.exe (PID: 5908 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- AdvancedWindowsManager.exe (PID: 4052 cmdline:
"C:\Progra m Files (x 86)\AW Man ager\Windo ws Manager \AdvancedW indowsMana ger.exe" - v 110 -t 8 080 MD5: 26F21ED76944ED83382851D9F2453B0E) - conhost.exe (PID: 5588 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- AdvancedWindowsManager.exe (PID: 4372 cmdline:
"C:\Progra m Files (x 86)\AW Man ager\Windo ws Manager \AdvancedW indowsMana ger.exe" - v 112 -t 8 080 MD5: 26F21ED76944ED83382851D9F2453B0E) - conhost.exe (PID: 4796 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- AdvancedWindowsManager.exe (PID: 7592 cmdline:
"C:\Progra m Files (x 86)\AW Man ager\Windo ws Manager \AdvancedW indowsMana ger.exe" - v 111 -t 8 080 MD5: 26F21ED76944ED83382851D9F2453B0E) - conhost.exe (PID: 360 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- AdvancedWindowsManager.exe (PID: 3936 cmdline:
"C:\Progra m Files (x 86)\AW Man ager\Windo ws Manager \AdvancedW indowsMana ger.exe" - v 114 -t 8 080 MD5: 26F21ED76944ED83382851D9F2453B0E) - conhost.exe (PID: 1048 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- AdvancedWindowsManager.exe (PID: 4832 cmdline:
"C:\Progra m Files (x 86)\AW Man ager\Windo ws Manager \AdvancedW indowsMana ger.exe" - v 113 -t 8 080 MD5: 26F21ED76944ED83382851D9F2453B0E) - conhost.exe (PID: 5508 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- AdvancedWindowsManager.exe (PID: 5000 cmdline:
"C:\Progra m Files (x 86)\AW Man ager\Windo ws Manager \AdvancedW indowsMana ger.exe" - v 115 -t 8 080 MD5: 26F21ED76944ED83382851D9F2453B0E) - conhost.exe (PID: 4012 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- AdvancedWindowsManager.exe (PID: 6308 cmdline:
"C:\Progra m Files (x 86)\AW Man ager\Windo ws Manager \AdvancedW indowsMana ger.exe" - v 112 -t 8 080 MD5: 26F21ED76944ED83382851D9F2453B0E) - conhost.exe (PID: 7412 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- AdvancedWindowsManager.exe (PID: 3012 cmdline:
"C:\Progra m Files (x 86)\AW Man ager\Windo ws Manager \AdvancedW indowsMana ger.exe" - v 113 -t 8 080 MD5: 26F21ED76944ED83382851D9F2453B0E)
Source | Rule | Description | Author | Strings |
JoeSecurity_LummaCStealer_3 | Yara detected LummaC Stealer | Joe Security |
Source | Rule | Description | Author | Strings |
JoeSecurity_NetSupport | Yara detected NetSupport remote tool | Joe Security | ||
JoeSecurity_NetSupport | Yara detected NetSupport remote tool | Joe Security | ||
JoeSecurity_NetSupport | Yara detected NetSupport remote tool | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
JoeSecurity_NetSupport | Yara detected NetSupport remote tool | Joe Security | ||
Source | Rule | Description | Author | Strings |
JoeSecurity_NetSupport | Yara detected NetSupport remote tool | Joe Security | ||
JoeSecurity_NetSupport | Yara detected NetSupport remote tool | Joe Security | ||
JoeSecurity_NetSupport | Yara detected NetSupport remote tool | Joe Security | ||
JoeSecurity_NetSupport | Yara detected NetSupport remote tool | Joe Security | ||
JoeSecurity_NetSupport | Yara detected NetSupport remote tool | Joe Security | ||
Source | Rule | Description | Author | Strings |
JoeSecurity_NetSupport | Yara detected NetSupport remote tool | Joe Security | ||
JoeSecurity_NetSupport | Yara detected NetSupport remote tool | Joe Security | ||
JoeSecurity_Keylogger_Generic | Yara detected Keylogger Generic | Joe Security | ||
JoeSecurity_NetSupport | Yara detected NetSupport remote tool | Joe Security | ||
JoeSecurity_NetSupport | Yara detected NetSupport remote tool | Joe Security | ||
Timestamp: | 12/06/23-14:36:21.023223 |
SID: | 2046045 |
Source Port: | 50296 |
Destination Port: | 81 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 12/06/23-14:36:51.222959 |
SID: | 2046045 |
Source Port: | 50339 |
Destination Port: | 81 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 12/06/23-14:35:36.356295 |
SID: | 2048094 |
Source Port: | 50240 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 12/06/23-14:36:47.245112 |
SID: | 2046045 |
Source Port: | 50333 |
Destination Port: | 81 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
AV Detection |
Source: | Avira: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | Avira: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | Code function: | 31_2_004F2740 | |
Source: | Code function: | 31_2_004F2600 | |
Source: | Code function: | 31_2_004F2B40 | |
Source: | Code function: | 31_2_004F2C30 | |
Source: | Code function: | 31_2_004F2C90 | |
Source: | Code function: | 31_2_004F2CB0 | |
Source: | Code function: | 31_2_004F2D20 | |
Source: | Code function: | 31_2_004F2ED0 | |
Source: | Code function: | 31_2_004FAED0 | |
Source: | Code function: | 31_2_004FB1A0 | |
Source: | Code function: | 31_2_004FB520 | |
Source: | Code function: | 31_2_004FB6A0 |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: |
Source: | Window detected: |