Edit tour
Windows
Analysis Report
$RLFVMMG.exe
Overview
General Information
Detection
Score: | 84 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Multi AV Scanner detection for submitted file
Antivirus detection for URL or domain
Multi AV Scanner detection for dropped file
Uses cmd line tools excessively to alter registry or file data
Modifies Chrome's extension installation force list
Obfuscated command line found
Found potential ransomware demand text
Uses schtasks.exe or at.exe to add and modify task schedules
Uses 32bit PE files
Contains functionality to check if a debugger is running (IsDebuggerPresent)
May sleep (evasive loops) to hinder dynamic analysis
PE file contains sections with non-standard names
Detected potential crypto function
Found potential string decryption / allocating functions
Sample execution stops while process was sleeping (likely an evasion)
Found dropped PE file which has not been started or loaded
PE file contains executable resources (Code or Archives)
IP address seen in connection with other malware
Enables debug privileges
Sample file is different than original file name gathered from version info
Drops PE files
Uses reg.exe to modify the Windows registry
Uses taskkill to terminate processes
PE / OLE file has an invalid certificate
Found large amount of non-executed APIs
Installs a Chrome extension
Creates a process in suspended mode (likely to inject code)
Classification
- System is w10x64
- $RLFVMMG.exe (PID: 5308 cmdline:
C:\Users\u ser\Deskto p\$RLFVMMG .exe MD5: A7A5C04005C17D1FA983F835CFFBD183) - $RLFVMMG.tmp (PID: 5376 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\is-4FQ L9.tmp\$RL FVMMG.tmp" /SL5="$50 378,857904 ,780800,C: \Users\use r\Desktop\ $RLFVMMG.e xe" MD5: A93A63A9E371AF57AE7FF4D3D1A8068C) - $RLFVMMG.exe (PID: 2468 cmdline:
"C:\Users\ user\Deskt op\$RLFVMM G.exe" /SI LENT MD5: A7A5C04005C17D1FA983F835CFFBD183) - $RLFVMMG.tmp (PID: 1228 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\is-Q42 F8.tmp\$RL FVMMG.tmp" /SL5="$60 038,857904 ,780800,C: \Users\use r\Desktop\ $RLFVMMG.e xe" /SILEN T MD5: A93A63A9E371AF57AE7FF4D3D1A8068C) - EdgeInstall.exe (PID: 1312 cmdline:
"C:\Users\ user\AppDa ta\Local\M icroApp\Ed geInstall. exe" insta ll MD5: BC44C3F3B1E233CCF83E964193F4CC0D) - cmd.exe (PID: 1236 cmdline:
C:\Windows \system32\ cmd.exe" / C ""C:\Use rs\user\Ap pData\Loca l\MicroApp \edge.bat" install MD5: 4E2ACF4F8A396486AB4268C94A6A245F) - conhost.exe (PID: 5464 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496) - cmd.exe (PID: 4688 cmdline:
C:\Windows \system32\ cmd.exe" / C ""C:\Use rs\user\Ap pData\Loca l\MicroApp \reg.bat" install MD5: 4E2ACF4F8A396486AB4268C94A6A245F) - conhost.exe (PID: 2416 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496) - ChromeInstall.exe (PID: 5984 cmdline:
"C:\Users\ user\AppDa ta\Local\S erviceApp\ ChromeInst all.exe" i nstall MD5: CFBB52F1BD761012D807812DB9566A8B) - cmd.exe (PID: 1464 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Local \ServiceAp p\chrome.b at" " MD5: 4E2ACF4F8A396486AB4268C94A6A245F) - conhost.exe (PID: 6140 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496) - schtasks.exe (PID: 3292 cmdline:
schtasks.e xe /Create /XML "C:\ Users\user \AppData\L ocal\Servi ceApp\reg. xml" /tn C hromeUpdat e MD5: 838D346D1D28F00783B7A6C6BD03A0DA) - cmd.exe (PID: 5128 cmdline:
C:\Windows \system32\ cmd.exe" / C ""C:\Use rs\user\Ap pData\Loca l\ServiceA pp\chrome. bat" insta ll MD5: 4E2ACF4F8A396486AB4268C94A6A245F) - conhost.exe (PID: 1332 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496) - schtasks.exe (PID: 1700 cmdline:
schtasks.e xe /Create /XML "C:\ Users\user \AppData\L ocal\Servi ceApp\reg. xml" /tn C hromeUpdat e MD5: 838D346D1D28F00783B7A6C6BD03A0DA) - cmd.exe (PID: 5996 cmdline:
C:\Windows \system32\ cmd.exe" / C ""C:\Use rs\user\Ap pData\Loca l\ServiceA pp\reg.bat " install MD5: 4E2ACF4F8A396486AB4268C94A6A245F) - conhost.exe (PID: 1004 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496) - schtasks.exe (PID: 5444 cmdline:
schtasks.e xe /Create /XML "C:\ Users\user \AppData\L ocal\Servi ceApp\reg. xml" /tn C hromeUpdat e MD5: 838D346D1D28F00783B7A6C6BD03A0DA) - chrome.exe (PID: 4748 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// getfiles.w iki/welcom e.php MD5: 0FEC2748F363150DC54C1CAFFB1A9408) - chrome.exe (PID: 4616 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-G B --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =1876 --fi eld-trial- handle=176 4,i,151681 9875000492 3395,29323 7332646725 9029,13107 2 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationTarge tPredictio n /prefetc h:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
- ChromeInstall.exe (PID: 5208 cmdline:
C:\Users\u ser\AppDat a\Local\Se rviceApp\C hromeInsta ll.exe MD5: CFBB52F1BD761012D807812DB9566A8B) - cmd.exe (PID: 6516 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Local \ServiceAp p\chrome.b at" " MD5: 4E2ACF4F8A396486AB4268C94A6A245F) - conhost.exe (PID: 6564 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496) - reg.exe (PID: 6648 cmdline:
REG DELETE HKLM\SOFT WARE\Polic ies\Google \Chrome /f MD5: E3DACF0B31841FA02064B4457D44B357) - reg.exe (PID: 6696 cmdline:
REG DELETE HKLM\SOFT WARE\Googl e\Chrome\E xtensions\ macjkjgiee oakdlmmfef gmldohgddp kj /f MD5: E3DACF0B31841FA02064B4457D44B357) - reg.exe (PID: 6724 cmdline:
REG DELETE HKLM\SOFT WARE\WOW64 32Node\Goo gle\Chrome \Extension s\macjkjgi eeoakdlmmf efgmldohgd dpkj /f MD5: E3DACF0B31841FA02064B4457D44B357) - reg.exe (PID: 6852 cmdline:
REG ADD "H KLM\SOFTWA RE\Policie s\Google\C hrome\Exte nsionInsta llAllowlis t" /v "3" /t REG_SZ /d macjkjg ieeoakdlmm fefgmldohg ddpkj /f MD5: E3DACF0B31841FA02064B4457D44B357) - reg.exe (PID: 7100 cmdline:
REG ADD "H KLM\SOFTWA RE\Google\ Chrome\Ext ensions\ma cjkjgieeoa kdlmmfefgm ldohgddpkj " /v "path " /t REG_S Z /d "C:\U sers\user\ AppData\Lo cal\Servic eApp\apps- helper\app s.crx" /f MD5: E3DACF0B31841FA02064B4457D44B357) - reg.exe (PID: 7120 cmdline:
REG ADD "H KLM\SOFTWA RE\Google\ Chrome\Ext ensions\ma cjkjgieeoa kdlmmfefgm ldohgddpkj " /v "vers ion" /t RE G_SZ /d 1. 0 /f MD5: E3DACF0B31841FA02064B4457D44B357) - reg.exe (PID: 7132 cmdline:
REG ADD "H KLM\SOFTWA RE\WOW6432 Node\Polic ies\Google \Chrome\Ex tensionIns tallAllowl ist" /v "3 " /t REG_S Z /d macjk jgieeoakdl mmfefgmldo hgddpkj /f MD5: E3DACF0B31841FA02064B4457D44B357) - reg.exe (PID: 7148 cmdline:
REG ADD "H KLM\SOFTWA RE\WOW6432 Node\Googl e\Chrome\E xtensions\ macjkjgiee oakdlmmfef gmldohgddp kj" /v "pa th" /t REG _SZ /d "C: \Users\use r\AppData\ Local\Serv iceApp\app s-helper\a pps.crx" / f MD5: E3DACF0B31841FA02064B4457D44B357) - reg.exe (PID: 7164 cmdline:
REG ADD "H KLM\SOFTWA RE\WOW6432 Node\Googl e\Chrome\E xtensions\ macjkjgiee oakdlmmfef gmldohgddp kj" /v "ve rsion" /t REG_SZ /d 1.0 /f MD5: E3DACF0B31841FA02064B4457D44B357) - taskkill.exe (PID: 4700 cmdline:
taskkill / F /IM chro me.exe /T MD5: 530C6A6CBA137EAA7021CEF9B234E8D4) - chrome.exe (PID: 4836 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --pr ofile-dire ctory="Def ault" --no -startup-w indow --lo ad-extensi on="C:\Use rs\user\Ap pData\Loca l\ServiceA pp\apps-he lper" --hi de-crash-r estore-bub ble MD5: 0FEC2748F363150DC54C1CAFFB1A9408) - chrome.exe (PID: 6972 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-G B --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =1964 --fi eld-trial- handle=170 4,i,101324 6721325091 6559,14044 5970981533 58203,1310 72 /prefet ch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408) - timeout.exe (PID: 6836 cmdline:
timeout 5 MD5: EB9A65078396FB5D4E3813BB9198CB18) - reg.exe (PID: 6572 cmdline:
REG ADD "H KLM\SOFTWA RE\Policie s\Google\C hrome\Exte nsionInsta llForcelis t" /v "3" /t REG_SZ /d macjkjg ieeoakdlmm fefgmldohg ddpkj /f MD5: E3DACF0B31841FA02064B4457D44B357) - reg.exe (PID: 7000 cmdline:
REG ADD "H KLM\SOFTWA RE\WOW6432 Node\Polic ies\Google \Chrome\Ex tensionIns tallForcel ist" /v "3 " /t REG_S Z /d macjk jgieeoakdl mmfefgmldo hgddpkj /f MD5: E3DACF0B31841FA02064B4457D44B357) - timeout.exe (PID: 7004 cmdline:
timeout 5 MD5: EB9A65078396FB5D4E3813BB9198CB18) - taskkill.exe (PID: 7020 cmdline:
taskkill / F /IM chro me.exe /T MD5: 530C6A6CBA137EAA7021CEF9B234E8D4) - chrome.exe (PID: 2412 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --pro file-direc tory="Defa ult MD5: 0FEC2748F363150DC54C1CAFFB1A9408) - chrome.exe (PID: 5552 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-G B --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =1796 --fi eld-trial- handle=178 8,i,119172 2918601395 4701,12445 5255987683 7676,13107 2 /prefetc h:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
- ChromeInstall.exe (PID: 6712 cmdline:
C:\Users\u ser\AppDat a\Local\Se rviceApp\C hromeInsta ll.exe MD5: CFBB52F1BD761012D807812DB9566A8B)
- ChromeInstall.exe (PID: 3576 cmdline:
C:\Users\u ser\AppDat a\Local\Se rviceApp\C hromeInsta ll.exe MD5: CFBB52F1BD761012D807812DB9566A8B)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
⊘No Snort rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Avira URL Cloud: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: |
Source: | Static PE information: |
Source: | Code function: |