Report - ndena.exe

Azorult .NET framework ftp Client info stealer email stealer Win Trojan agentTesla browser Google Chrome User Data Download management
ScreenShot
    Created 2021.03.19 18:28 Machine s1_win7_x6401
    Filename ndena.exe
    Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
    AI Score
    8
    Behavior Score
    10.8
    ZERO API file : malware
    VT API (file) 18 detected (malicious, high confidence, Unsafe, Save, Malcode, gdn30, Score, Wacatac, ZemsilF, 2m0@ay64jjj, Kryptik, AAAV, Static AI, Suspicious PE, susgen, AABO, QVM03)
    md5 d4b31689b01301f90ce578d418a74231
    sha256 4c83b9a705090f3edd4f8f1322ec609b7a04d59d03b390681c3708c61341eb1a
    ssdeep 24576:lZPkSFqd8QVpOV0XkStbjFzcbVnGk3O9PyhoBfgTk:lZMSwd7pOSUN5Gk+hEoBfgT
    imphash f34d5f2d4577ed6d9ceec516c1f5a744
    impfuzzy 3:rGsLdAIEK:tf
      No network connection information

    Signature (23cnts)

    Level Description
    danger Executed a process and injected code into it
    watch A process attempted to delay the analysis task.
    watch Allocates execute permission to another process indicative of possible code injection
    watch Code injection by writing an executable or DLL to the memory of another process
    watch File has been identified by 18 AntiVirus engines on VirusTotal as malicious
    watch Found URLs in memory pointing to an IP address rather than a domain (potentially indicative of Command & Control traffic)
    watch Found URLs related to Tor in process memory dump (e.g. onion services
    watch Looks for the Windows Idle Time to determine the uptime
    watch Potential code injection by writing to the memory of another process
    watch Resumed a suspended thread in a remote process potentially indicative of process injection
    watch Used NtSetContextThread to modify a thread in a remote process indicative of process injection
    notice Allocates read-write-execute memory (usually to unpack itself)
    notice Checks for the Locally Unique Identifier on the system for a suspicious privilege
    notice One or more potentially interesting buffers were extracted
    notice Potentially malicious URLs were found in the process memory dump
    notice Terminates another process
    notice The binary likely contains encrypted or compressed data indicative of a packer
    notice Yara rule detected in process memory
    info Checks amount of memory in system
    info Checks if process is being debugged by a debugger
    info One or more processes crashed
    info Queries for the computername
    info Uses Windows APIs to generate a cryptographic key

    Rules (69cnts)

    Level Name Description Collection
    warning infoStealer_browser_Zero browser info stealer memory
    warning infoStealer_DownloadManagement_Zero Download management info stealer memory
    warning infoStealer_emailClients_Zero email clients info stealer memory
    warning infoStealer_ftpClients_Zero ftp clients info stealer memory
    watch Chrome_User_Data_Check_Zero Google Chrome User Data Check memory
    notice Str_Win32_Http_API Match Windows Http API call memory
    notice Str_Win32_Internet_API Match Windows Inet API call memory
    info anti_dbg Checks if being debugged memory
    info antisb_threatExpert Anti-Sandbox checks for ThreatExpert memory
    info Check_Dlls (no description) memory
    info Check_Qemu_Description (no description) memory
    info Check_Qemu_DeviceMap (no description) memory
    info Check_VBox_Description (no description) memory
    info Check_VBox_DeviceMap (no description) memory
    info Check_VBox_Guest_Additions (no description) memory
    info Check_VBox_VideoDrivers (no description) memory
    info Check_VmTools (no description) memory
    info Check_VMWare_DeviceMap (no description) memory
    info DebuggerCheck__GlobalFlags (no description) memory
    info DebuggerCheck__QueryInfo (no description) memory
    info DebuggerCheck__RemoteAPI (no description) memory
    info DebuggerException__ConsoleCtrl (no description) memory
    info DebuggerException__SetConsoleCtrl (no description) memory
    info DebuggerHiding__Active (no description) memory
    info DebuggerHiding__Thread (no description) memory
    info disable_dep Bypass DEP memory
    info IsPE32 (no description) binaries (upload)
    info PE_Header_Zero PE File Signature Zero binaries (upload)
    info SEH__vectored (no description) memory
    info ThreadControl__Context (no description) memory
    info vmdetect_misc Following Rule is referenced from AlienVault's Yara rule repository.This rule contains additional processes and driver names. memory
    info win_hook Affect hook table memory
    info WMI_VM_Detect Detection of Virtual Appliances through the use of WMI for use of evasion. memory
    info create_com_service Create a COM server memory
    info create_service Create a windows service memory
    info cred_ff Steal Firefox credential memory
    info cred_local Steal credential memory
    info dyndns Dynamic DNS memory
    info escalate_priv Escalade priviledges memory
    info inject_thread Code injection with CreateRemoteThread in a remote process memory
    info IsNET_EXE (no description) binaries (upload)
    info IsPacked Entropy Check binaries (upload)
    info IsWindowsGUI (no description) binaries (upload)
    info keylogger Run a keylogger memory
    info migrate_apc APC queue tasks migration memory
    info network_dga Communication using dga memory
    info network_dns Communications use DNS memory
    info network_dropper File downloader/dropper memory
    info network_ftp Communications over FTP memory
    info network_http Communications over HTTP memory
    info network_p2p_win Communications over P2P network memory
    info network_smtp_dotNet Communications smtp memory
    info network_tcp_listen Listen for incoming communication memory
    info network_tcp_socket Communications over RAW socket memory
    info network_udp_sock Communications over UDP network memory
    info rat_vnc Remote Administration toolkit VNC memory
    info screenshot Take screenshot memory
    info sniff_audio Record Audio memory
    info spreading_file Malware can spread east-west file memory
    info spreading_share Malware can spread east-west using share drive memory
    info Str_Win32_Wininet_Library Match Windows Inet API library declaration memory
    info Str_Win32_Winsock2_Library Match Winsock 2 API library declaration memory
    info Win32_Trojan_PWS_Azorult_Net_1_Zero Win32 Trojan PWS .NET Azorult binaries (upload)
    info win_files_operation Affect private profile memory
    info win_mutex Create or check mutex memory
    info win_private_profile Affect private profile memory
    info win_registry Affect system registries memory
    info win_token Affect system token memory
    info Win_Trojan_agentTesla_Zero Win.Trojan.agentTesla memory

    Network (0cnts) ?

    Request CC ASN Co IP4 Rule ? ZERO ?

    Suricata ids

    PE API

    IAT(Import Address Table) Library

    mscoree.dll
     0x402000 _CorExeMain

    EAT(Export Address Table) is none



    Similarity measure (PE file only) - Checking for service failure