Edit tour
Windows
Analysis Report
file.exe
Overview
General Information
Detection
XRed
Score: | 74 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Antivirus detection for dropped file
Found malware configuration
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected XRed
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Document contains an embedded VBA macro with suspicious strings
Document contains an embedded VBA with functions possibly related to ADO stream file operations
Document contains an embedded VBA with functions possibly related to HTTP operations
Document contains an embedded VBA with functions possibly related to WSH operations (process, registry, environment, or keystrokes)
Drops PE files to the document folder of the user
Infects executable files (exe, dll, sys, html)
Machine Learning detection for dropped file
Machine Learning detection for sample
Uses dynamic DNS services
AV process strings found (often used to terminate AV products)
Checks for available system drives (often done to infect USB drives)
Checks if the current process is being debugged
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to dynamically determine API calls
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Creates or modifies windows services
Deletes files inside the Windows folder
Detected potential crypto function
Document contains an embedded VBA macro which executes code when the document is opened / closed
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Drops PE files to the windows directory (C:\Windows)
Drops files with a non-matching file extension (content does not match file extension)
Found dropped PE file which has not been started or loaded
Found evaded block containing many API calls
Found evasive API chain checking for process token information
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May infect USB drives
May sleep (evasive loops) to hinder dynamic analysis
Modifies existing windows services
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
One or more processes crash
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
PE file does not import any functions
Queries the installation date of Windows
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: Wow6432Node CurrentVersion Autorun Keys Modification
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Uses the system / local time for branch decision (may execute only at specific dates)
Classification
- System is w10x64
- file.exe (PID: 7868 cmdline:
"C:\Users\ user\Deskt op\file.ex e" MD5: 7274B0B15C4E6D5BBE8DB5AA93C65A12) - ._cache_file.exe (PID: 7980 cmdline:
"C:\Users\ user\Deskt op\._cache _file.exe" MD5: DE34B1C517E0463602624BBC8294C08D) - ._cache_file.exe (PID: 8028 cmdline:
"C:\Window s\Temp\{F5 2E087A-53A 6-4D4D-BEA E-A40DD36C 6E5E}\.cr\ ._cache_fi le.exe" -b urn.clean. room="C:\U sers\user\ Desktop\._ cache_file .exe" -bur n.filehand le.attache d=524 -bur n.filehand le.self=64 0 MD5: 2F9D2B6CE54F9095695B53D1AA217C7B) - VC_redist.x86.exe (PID: 6632 cmdline:
"C:\Window s\Temp\{B0 8E6DC2-76D 4-458D-A6E 2-7E824AE2 40D4}\.be\ VC_redist. x86.exe" - q -burn.el evated Bur nPipe.{4EC B3904-0384 -4F60-9326 -256C50426 7D7} {9931 72C8-4368- 4578-BD0A- D6EA507F91 CB} 8028 MD5: 2F9D2B6CE54F9095695B53D1AA217C7B) - Synaptics.exe (PID: 8096 cmdline:
"C:\Progra mData\Syna ptics\Syna ptics.exe" InjUpdate MD5: B753207B14C635F29B2ABF64F603570A) - WerFault.exe (PID: 5616 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 8 096 -s 464 8 MD5: C31336C1EFC2CCB44B4326EA793040F2)
- EXCEL.EXE (PID: 8140 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \Root\Offi ce16\EXCEL .EXE" /aut omation -E mbedding MD5: 4A871771235598812032C822E6F68F19)
- Synaptics.exe (PID: 1900 cmdline:
"C:\Progra mData\Syna ptics\Syna ptics.exe" MD5: B753207B14C635F29B2ABF64F603570A)
- SrTasks.exe (PID: 6008 cmdline:
C:\Windows \system32\ srtasks.ex e ExecuteS copeRestor ePoint /Wa itForResto rePoint:1 MD5: 2694D2D28C368B921686FE567BD319EB) - conhost.exe (PID: 5912 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- msiexec.exe (PID: 4196 cmdline:
C:\Windows \system32\ msiexec.ex e /V MD5: E5DA170027542E25EDE42FC54C929077)
- VC_redist.x86.exe (PID: 4868 cmdline:
"C:\Progra mData\Pack age Cache\ {65e650ff- 30be-469d- b63a-418d7 1ea1765}\V C_redist.x 86.exe" /b urn.runonc e MD5: 2F9D2B6CE54F9095695B53D1AA217C7B) - VC_redist.x86.exe (PID: 6412 cmdline:
"C:\Progra mData\Pack age Cache\ {65e650ff- 30be-469d- b63a-418d7 1ea1765}\V C_redist.x 86.exe" MD5: 2F9D2B6CE54F9095695B53D1AA217C7B) - VC_redist.x86.exe (PID: 4496 cmdline:
"C:\Progra mData\Pack age Cache\ {65e650ff- 30be-469d- b63a-418d7 1ea1765}\V C_redist.x 86.exe" -b urn.clean. room="C:\P rogramData \Package C ache\{65e6 50ff-30be- 469d-b63a- 418d71ea17 65}\VC_red ist.x86.ex e" -burn.f ilehandle. attached=5 32 -burn.f ilehandle. self=540 MD5: 2F9D2B6CE54F9095695B53D1AA217C7B)
- cleanup
{"C2 url": "xred.mooo.com", "Email": "xredline1@gmail.com", "Payload urls": ["http://freedns.afraid.org/api/?action=getdyndns&sha=a30fa98efc092684e8d1c5cff797bcc613562978", "https://docs.google.com/uc?id=0BxsMXGfPIZfSVlVsOGlEVGxuZVk&export=download", "https://www.dropbox.com/s/n1w4p8gc6jzo0sg/SUpdate.ini?dl=1", "http://xred.site50.net/syn/SUpdate.ini", "https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download", "https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1", "http://xred.site50.net/syn/Synaptics.rar", "https://docs.google.com/uc?id=0BxsMXGfPIZfSTmlVYkxhSDg5TzQ&export=download", "https://www.dropbox.com/s/fzj752whr3ontsm/SSLLibrary.dll?dl=1", "http://xred.site50.net/syn/SSLLibrary.dll"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XRed | Yara detected XRed | Joe Security | ||
JoeSecurity_DelphiSystemParamCount | Detected Delphi use of System.ParamCount() | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XRed | Yara detected XRed | Joe Security | ||
JoeSecurity_DelphiSystemParamCount | Detected Delphi use of System.ParamCount() | Joe Security | ||
JoeSecurity_XRed | Yara detected XRed | Joe Security | ||
JoeSecurity_DelphiSystemParamCount | Detected Delphi use of System.ParamCount() | Joe Security | ||
JoeSecurity_XRed | Yara detected XRed | Joe Security | ||
Click to see the 1 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XRed | Yara detected XRed | Joe Security | ||
JoeSecurity_XRed | Yara detected XRed | Joe Security | ||
JoeSecurity_DelphiSystemParamCount | Detected Delphi use of System.ParamCount() | Joe Security | ||
JoeSecurity_XRed | Yara detected XRed | Joe Security | ||
JoeSecurity_XRed | Yara detected XRed | Joe Security |
System Summary |
---|
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-02T20:29:49.306824+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.10 | 49766 | 172.217.18.14 | 443 | TCP |
2025-01-02T20:29:49.335267+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.10 | 49767 | 172.217.18.14 | 443 | TCP |
2025-01-02T20:29:50.362124+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.10 | 49781 | 172.217.18.14 | 443 | TCP |
2025-01-02T20:29:50.433921+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.10 | 49778 | 172.217.18.14 | 443 | TCP |
2025-01-02T20:29:51.425915+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.10 | 49789 | 172.217.18.14 | 443 | TCP |
2025-01-02T20:29:51.514259+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.10 | 49793 | 172.217.18.14 | 443 | TCP |
2025-01-02T20:29:53.390542+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.10 | 49801 | 172.217.18.14 | 443 | TCP |
2025-01-02T20:30:00.471957+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.10 | 49831 | 172.217.18.14 | 443 | TCP |
2025-01-02T20:30:00.480979+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.10 | 49829 | 172.217.18.14 | 443 | TCP |
2025-01-02T20:30:01.615907+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.10 | 49845 | 172.217.18.14 | 443 | TCP |
2025-01-02T20:30:01.708048+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.10 | 49844 | 172.217.18.14 | 443 | TCP |
2025-01-02T20:30:02.641788+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.10 | 49853 | 172.217.18.14 | 443 | TCP |
2025-01-02T20:30:02.740833+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.10 | 49856 | 172.217.18.14 | 443 | TCP |
2025-01-02T20:30:03.978908+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.10 | 49865 | 172.217.18.14 | 443 | TCP |
2025-01-02T20:30:03.989273+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.10 | 49863 | 172.217.18.14 | 443 | TCP |
2025-01-02T20:30:05.175798+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.10 | 49884 | 172.217.18.14 | 443 | TCP |
2025-01-02T20:30:05.176404+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.10 | 49883 | 172.217.18.14 | 443 | TCP |
2025-01-02T20:30:06.278855+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.10 | 49890 | 172.217.18.14 | 443 | TCP |
2025-01-02T20:30:06.286346+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.10 | 49891 | 172.217.18.14 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-02T20:29:49.704664+0100 | 2832617 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49776 | 69.42.215.252 | 80 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: | ||
Source: | Avira: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Code function: | 6_2_00FF9EB7 | |
Source: | Code function: | 6_2_0101F961 | |
Source: | Code function: | 6_2_00FF9C99 | |
Source: | Code function: | 7_2_00199EB7 | |
Source: | Code function: | 7_2_001BF961 | |
Source: | Code function: | 7_2_00199C99 | |
Source: | Code function: | 12_2_007FF961 | |
Source: | Code function: | 12_2_007D9C99 | |
Source: | Code function: | 12_2_007D9EB7 | |
Source: | Code function: | 25_2_00A0F961 | |
Source: | Code function: | 25_2_009E9C99 | |
Source: | Code function: | 25_2_009E9EB7 |
Source: | Static PE information: |
Source: | Window detected: |