Report - setup_pass.7z

PrivateLoader Escalate priviledges PWS KeyLogger AntiDebug AntiVM
ScreenShot
Created 2023.09.06 14:03 Machine s1_win7_x6402
Filename setup_pass.7z
Type 7-zip archive data, version 0.4
AI Score Not founds Behavior Score
5.0
ZERO API file : malware
VT API (file)
md5 1860765426cb420e321b2511a3c2652d
sha256 834853673e1e591db871c7219900aa38081ac22502c43d93d884f2a640afc772
ssdeep 196608:Fwf+yFSvNqMN4XqlxxInjA20Vzd558TLeHEl:OgOi+n3E5Kpl
imphash
impfuzzy
  Network IP location

Signature (13cnts)

Level Description
watch Communicates with host for which no DNS query was performed
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks for the Locally Unique Identifier on the system for a suspicious privilege
notice Communication to multiple IPs on high port numbers possibly indicative of a peer-to-peer (P2P) or non-standard command and control protocol
notice Creates executable files on the filesystem
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice Looks up the external IP address
notice Performs some HTTP requests
notice Resolves a suspicious Top Level Domain (TLD)
notice Sends data using the HTTP POST Method
notice Yara rule detected in process memory
info Checks amount of memory in system
info Checks if process is being debugged by a debugger

Rules (11cnts)

Level Name Description Collection
notice Escalate_priviledges Escalate priviledges memory
notice Generic_PWS_Memory_Zero PWS Memory memory
notice KeyLogger Run a KeyLogger memory
info anti_dbg Checks if being debugged memory
info DebuggerCheck__GlobalFlags (no description) memory
info DebuggerCheck__QueryInfo (no description) memory
info DebuggerHiding__Active (no description) memory
info DebuggerHiding__Thread (no description) memory
info disable_dep Bypass DEP memory
info SEH__vectored (no description) memory
info ThreadControl__Context (no description) memory

Network (115cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://45.15.156.229/api/firegate.php RU CJSC Kolomna-Sviaz TV 45.15.156.229 36052 mailcious
http://hugersi.com/dl/6523.exe RU Petersburg Internet Network ltd. 91.215.85.147 32660 malware
http://45.15.156.229/api/tracemap.php RU CJSC Kolomna-Sviaz TV 45.15.156.229 33783 mailcious
http://94.142.138.131/api/firecom.php RU Ihor Hosting LLC 94.142.138.131 36179 mailcious
http://45.9.74.80/ummaa.exe Unknown 45.9.74.80 36186 malware
http://194.169.175.232/autorun.exe Unknown 194.169.175.232 malware
http://94.142.138.113/api/firegate.php RU Ihor Hosting LLC 94.142.138.113 36152 mailcious
http://77.91.68.238/info/fotos894.exe RU Foton Telecom CJSC 77.91.68.238 36160 malware
http://94.156.253.187/download/Services.exe BG Technofy Ltd. 94.156.253.187 malware
http://87.121.221.58/g.exe Unknown 87.121.221.58 35764 malware
http://94.156.253.187/download/WWW14_n.exe BG Technofy Ltd. 94.156.253.187 36185 malware
http://apps.identrust.com/roots/dstrootcax3.p7c US Akamai International B.V. 23.67.53.17 clean
http://94.142.138.131/api/tracemap.php RU Ihor Hosting LLC 94.142.138.131 28311 mailcious
http://193.42.32.118/api/tracemap.php Unknown 193.42.32.118 36180 mailcious
http://www.maxmind.com/geoip/v2.1/city/me US CLOUDFLARENET 104.18.146.235 clean
http://230809204625331.nes.dtf99.top/f/fikim0809331.exe BG Belcloud LTD 94.156.35.76 36062 malware
http://45.9.74.80/super.exe Unknown 45.9.74.80 36063 malware
http://ralphkors.top/calc2.exe RU Continental Ltd. 89.223.65.127 malware
http://myfilebest.com/order/set17.exe US CLOUDFLARENET 172.67.183.191 36161 malware
http://94.142.138.113/api/tracemap.php RU Ihor Hosting LLC 94.142.138.113 28877 mailcious
https://vk.com/doc44017378_668841700?hash=B7naXG9fPpueUKaZxzbzFzqgThiLopd9A232GVSoLbD&dl=VDCn0RuU4RRcIuzpA6hHZu4JCvVt7UCUAmWFRORbSKs&api=1&no_preview=1 RU VKontakte Ltd 87.240.132.67 mailcious
https://db-ip.com/demo/home.php?s=175.208.134.152 US CLOUDFLARENET 104.26.5.15 clean
https://vk.com/doc44017378_668685574?hash=2Z9kWDMxHv9Bg52ieOFMjjyZlIe2LzZhpXJtbJfi2jD&dl=MckLSTrLnFqxzbDQcQsY8zw8KxvNLWnEyU8AMbhyK6s&api=1&no_preview=1#WW1 RU VKontakte Ltd 87.240.132.67 mailcious
https://vk.com/doc44017378_668916923?hash=sOYzznQFdvahBVyVjkbZnzPi3TCGlZg6RM6IHhJTZtL&dl=WPCbPohX0oULQzTqTTGTJNQWxrKyDARUvPHJcYJtGbP&api=1&no_preview=1#qq RU VKontakte Ltd 87.240.132.67 clean
https://sun6-21.userapi.com/c909628/u44017378/docs/d11/1a3013098cbf/WWW1.bmp?extra=xgcuwlyssMW5fhehD936AqhRSGL9n6WAhvJJzjwcFZ3WMiE8xWxO3qKhr9_8jnDUTj1l3e5eKgd9DPl2hGHNRQsMstXoksgW-4kZoEzSOKif1Txq8PmSgC4s2KKLAdrZ-IWl7XcwtYoplwO1 RU VKontakte Ltd 95.142.206.1 clean
https://vk.com/doc791620691_663065029?hash=Efubo9FQtw3Bdj42XJVcJwymfIH3PazMKz8g5wJ0dZX&dl=G44TCNRSGA3DSMI:1682787066:QgrgzF33wDt9bwmmOgWCYTv61J7HwhLVZOXGaEdWiKP&api=1&no_preview=1#stats RU VKontakte Ltd 87.240.132.67 mailcious
https://vk.com/doc44017378_668903345?hash=Zaetqx11oeFBdkWDjedCOItoPTbkAjFxDdmH7zuyJRo&dl=y4MBsDhjAnxnZdtJN2fzh9BSudm5oc4mHzNl4ImM7J0&api=1&no_preview=1#1 RU VKontakte Ltd 87.240.132.67 clean
https://preconcert.pw/setup294.exe US CLOUDFLARENET 104.21.84.222 36162 malware
https://vk.com/doc44017378_668916984?hash=z1dD7zDOKf4ZPQJxQGiBgAjggkhOTKzwGcbzPqETlMz&dl=qmY4pwWN7rzbugtcn7O1yC8XQAj2CqQOYWt2YS9MT9s&api=1&no_preview=1#9f RU VKontakte Ltd 87.240.132.67 clean
https://sun6-20.userapi.com/c909228/u44017378/docs/d21/7ad101a96b02/RisePro_0_5_eM6kP0V0t0TJM31LPkFZ.bmp?extra=XXZOHqfnMq17vouPpzTFs3JuQrmoHXmTSMlflvAzh2GLImsRHfMz9eBd4CuMjz8ELbdw9smSs0DnbidzeGfroV0r-b9IgDwMl_TlfFZuryV19PDmHTTp_h0wGXPgYU4pHWQ3GNoEpMFPQLfl RU VKontakte Ltd 95.142.206.0 clean
https://sun6-23.userapi.com/c240331/u44017378/docs/d40/efd676633f21/test2.bmp?extra=7Tl2Y-CX-JxiRCYulouwERP3ItXHBJDXxyoPj0iVEHSIa9hZ7xvFnG2fGentCZSFBhCQxO-UxYGoZHq-WfhVsGNzMCnfmCbfx4QRc17JBaevHEahprxnIt83DzE8XokOPOHZg2UjY8lhxjkL RU VKontakte Ltd 95.142.206.3 clean
https://db-ip.com/ US CLOUDFLARENET 104.26.4.15 clean
https://sun6-23.userapi.com/c909218/u44017378/docs/d31/28287d82e701/3.bmp?extra=Eia0Z52O_QfMzxBphvQv2mAhSnbUD5gztBKz2S-85eW2DofIDB-aCKBuZ393oBZW0tDYKH9h7atpaV_aJBQybspAkUHNC-pEe72vNCg8Kk1iD_XA5Um1USzPPozdvJvAOg3vHT-D_AIed8L2 RU VKontakte Ltd 95.142.206.3 clean
https://dzen.ru/?yredirect=true RU Invest Mobile LLC 62.217.160.2 clean
https://sun6-20.userapi.com/c909618/u44017378/docs/d36/4045d7e5e2af/PL_Client.bmp?extra=41RYXiYdonWnWPYwQIzl_E40YzLt9e-a585sYDB48TJ1guOgXM82khcH113VcyDUy1qRwuEub4FUsSEnl5OfhF82khtCO4eGvfgR1-OEX6MePbBwA6qux-eLDXjut3NIGwniEJcDMP8LnpSO RU VKontakte Ltd 95.142.206.0 clean
https://sun6-21.userapi.com/c235131/u44017378/docs/d58/b5d7bd164765/tmvwr.bmp?extra=MOoJ_YAgLF-1um3Me5WawUQVtSpNdXdk4O4HjEHIoEJYoGofA_i-K7joq0CWxFxZ_12PJ_jQLkx1WwKPGJ02adtFNG4_nnXRhcuoM-7EcVqjywc84kVq559VzCTblgn2fgMn9BIrYrs9lDH_ RU VKontakte Ltd 95.142.206.1 clean
https://vk.com/doc746114504_647280747?hash=cvDFKP5q0CQEjBCbeoeHvPNrWE0xbMxZEmrkIeNKcET&dl=G42DMMJRGQ2TANA:1661413520:uZNj68vRUvQaydRD8wpAK8zluN0I7otw5AHbA1ZlN9T&api=1&no_preview=1 RU VKontakte Ltd 87.240.132.78 mailcious
https://vk.com/doc44017378_668777192?hash=bErtt2Itw8CZPTouyuXblBKb3pLfVImQzvGWnZ4CyVs&dl=vm2AArvcYQaQAETnMlmPKTg0CoqMAAqRh2fogvAYbWP&api=1&no_preview=1#tmwvr RU VKontakte Ltd 87.240.132.78 mailcious
https://vk.com/doc44017378_668790441?hash=ZAKf3wtiDekEKOwL5zOUpKlhs3NsBThU4THBbA9UjZ0&dl=tGcv3oqIrQKDSR0z8GXJxfn9P4s1HZm2ci3UQevYE7w&api=1&no_preview=1#test2 RU VKontakte Ltd 87.240.132.67 mailcious
https://vk.com/doc44017378_668805679?hash=Pq8nRu8IL2bYqDVs2GPjMvpAFMOm04kusdFGQmRlGY0&dl=ns6C3Wug8h8cGKJrvWC9ONCmtSXnbVIqzmpprkB3Voz&api=1&no_preview=1#rise RU VKontakte Ltd 87.240.132.67 mailcious
https://sso.passport.yandex.ru/push?uuid=1c2cbbd3-3e8d-405c-9ea3-cfda8d7fc41e&retpath=https%3A%2F%2Fdzen.ru%2F%3Fyredirect%3Dtrue RU YANDEX LLC 213.180.204.24 clean
https://sun6-23.userapi.com/c909618/u44017378/docs/d58/7bf5e3bbbea6/Synapse.bmp?extra=mzMMk3WSUR9nXjlWZ6cDWS8uZXnpeH5HFoj4k-neSMlSwedoZanNxQoG3h1Fl180ZYqPy_dIeBEOfQRiGTKUc2qv1mDlwQ6hq_BjfKmI04Adw-GHS1o0utmIeVwn4vFkEZ17GUfHoBCOUPhw RU VKontakte Ltd 95.142.206.3 clean
https://vk.com/doc791620691_663065029?hash=Efubo9FQtw3Bdj42XJVcJwymfIH3PazMKz8g5wJ0dZX&dl=G44TCNRSGA3DSMI:1682787066:QgrgzF33wDt9bwmmOgWCYTv61J7HwhLVZOXGaEdWiKP&api=1&no_preview=1#test RU VKontakte Ltd 87.240.132.67 mailcious
https://sun6-22.userapi.com/c240331/u44017378/docs/d38/3cdd8ad7ce1f/crypted.bmp?extra=oWgEqzAKAoeJqXlNWcq1L2Twro57C2oqwpXLM14hc75rg4Axr9nzDq7o6meuTh0Y7BWbfc7d9cnupYGV36dyCqvgfEdnTEO8YF_-s6Jw3JzLfmxX6fhV9rtqGT0yzb_52y_5s8JLbtSZ8cII RU VKontakte Ltd 95.142.206.2 clean
https://sun6-23.userapi.com/c240331/u44017378/docs/d3/12830610f737/ResortedMetaphrase.bmp?extra=sJUz3R5N8E8T2U3-Oy6z6Gn4gPEMsBChQOzEqvJr5tl3sIwCWpIO_HTic5PfalDQbPCyxepzGd0O1Iq1W9y2aLpy91N7vAjZoAHfJCxaGS8jPoJgoJhoYvMfs3Q9JUjLDkS7cpeHQl7ZgZOs RU VKontakte Ltd 95.142.206.3 clean
https://api.db-ip.com/v2/p31e4d59ee6ad1a0b5cc80695a873e43a8fbca06/self US CLOUDFLARENET 172.67.75.166 clean
https://vk.com/doc44017378_668679037?hash=6lxdrm9NUkSryZCfzYZn4zR2sOTXzaKgfQIcVCaPnvX&dl=FLqYTpktPSSWsXhtSyyzRawRyuZZexn7WIKXiXEZBv4&api=1&no_preview=1 RU VKontakte Ltd 87.240.132.67 mailcious
db-ip.com US CLOUDFLARENET 104.26.5.15 clean
sun6-23.userapi.com RU VKontakte Ltd 95.142.206.3 clean
ipinfo.io US GOOGLE 34.117.59.81 clean
agsnv.com US Digital Energy Technologies Ltd. 181.214.31.34 malware
dzen.ru RU Invest Mobile LLC 62.217.160.2 clean
preconcert.pw US CLOUDFLARENET 104.21.84.222 malware
iplogger.org DE Hetzner Online GmbH 148.251.234.83 mailcious
telegram.org GB Telegram Messenger Inc 149.154.167.99 clean
twitter.com US TWITTER 104.244.42.129 clean
myfilebest.com US CLOUDFLARENET 104.21.56.98 malware
cdn.discordapp.com Unknown 162.159.133.233 malware
sun6-20.userapi.com RU VKontakte Ltd 95.142.206.0 mailcious
api.db-ip.com US CLOUDFLARENET 104.26.5.15 clean
sun6-21.userapi.com RU VKontakte Ltd 95.142.206.1 mailcious
sso.passport.yandex.ru RU YANDEX LLC 213.180.204.24 clean
bitbucket.org US ATLASSIAN PTY LTD 104.192.141.1 malware
ralphkors.top RU Continental Ltd. 89.223.65.127 malware
230809204625331.nes.dtf99.top BG Belcloud LTD 94.156.35.76 malware
yandex.ru RU YANDEX LLC 77.88.55.88 clean
api.myip.com US CLOUDFLARENET 172.67.75.163 clean
hugersi.com RU Petersburg Internet Network ltd. 91.215.85.147 malware
ironhost.io US CLOUDFLARENET 104.21.57.237 clean
sun6-22.userapi.com RU VKontakte Ltd 95.142.206.2 clean
www.maxmind.com US CLOUDFLARENET 104.18.145.235 clean
vk.com RU VKontakte Ltd 87.240.137.164 mailcious
iplis.ru DE Hetzner Online GmbH 148.251.234.93 mailcious
51.89.253.22 FR OVH SAS 51.89.253.22 clean
148.251.234.93 DE Hetzner Online GmbH 148.251.234.93 mailcious
194.169.175.128 Unknown 194.169.175.128 mailcious
104.18.145.235 US CLOUDFLARENET 104.18.145.235 clean
181.214.31.34 US Digital Energy Technologies Ltd. 181.214.31.34 malware
104.192.141.1 US ATLASSIAN PTY LTD 104.192.141.1 mailcious
91.215.85.147 RU Petersburg Internet Network ltd. 91.215.85.147 malware
77.91.68.238 RU Foton Telecom CJSC 77.91.68.238 malware
89.223.65.127 RU Continental Ltd. 89.223.65.127 malware
62.217.160.2 RU Invest Mobile LLC 62.217.160.2 clean
104.26.5.15 US CLOUDFLARENET 104.26.5.15 clean
179.43.158.2 CH Private Layer INC 179.43.158.2 clean
5.255.255.77 RU YANDEX LLC 5.255.255.77 clean
149.154.167.99 GB Telegram Messenger Inc 149.154.167.99 mailcious
193.42.32.118 Unknown 193.42.32.118 mailcious
172.67.75.166 US CLOUDFLARENET 172.67.75.166 clean
172.67.193.129 US CLOUDFLARENET 172.67.193.129 clean
104.21.56.98 US CLOUDFLARENET 104.21.56.98 clean
121.254.136.18 KR LG DACOM Corporation 121.254.136.18 clean
87.240.132.67 RU VKontakte Ltd 87.240.132.67 mailcious
34.117.59.81 US GOOGLE 34.117.59.81 clean
94.156.253.187 BG Technofy Ltd. 94.156.253.187 malware
148.251.234.83 DE Hetzner Online GmbH 148.251.234.83 clean
213.180.204.24 RU YANDEX LLC 213.180.204.24 clean
104.21.84.222 US CLOUDFLARENET 104.21.84.222 malware
45.9.74.80 Unknown 45.9.74.80 malware
194.169.175.232 Unknown 194.169.175.232 malware
176.123.9.142 MD Alexhost Srl 176.123.9.142 mailcious
94.142.138.113 RU Ihor Hosting LLC 94.142.138.113 mailcious
185.225.73.32 DE Mayak Smart Services Ltd. 185.225.73.32 mailcious
87.240.132.78 RU VKontakte Ltd 87.240.132.78 mailcious
162.159.129.233 Unknown 162.159.129.233 malware
45.15.156.229 RU CJSC Kolomna-Sviaz TV 45.15.156.229 mailcious
172.67.75.163 US CLOUDFLARENET 172.67.75.163 clean
104.26.4.15 US CLOUDFLARENET 104.26.4.15 clean
95.142.206.3 RU VKontakte Ltd 95.142.206.3 clean
95.142.206.2 RU VKontakte Ltd 95.142.206.2 clean
95.142.206.1 RU VKontakte Ltd 95.142.206.1 mailcious
95.142.206.0 RU VKontakte Ltd 95.142.206.0 mailcious
104.244.42.193 US TWITTER 104.244.42.193 suspicious
87.121.221.58 Unknown 87.121.221.58 malware
94.142.138.131 RU Ihor Hosting LLC 94.142.138.131 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure