Hostile 100% datamaliciousorder Download

Trojan.Danger_Trojan.GenericKD.72853156_372_1.vir

Trojan with C2, injection, packing

BMP screenshot capture with network exfiltrationScreenshot capture with network exfiltration
SHA-256323301749d4f444c6b4a1aa4e0178ea8c1bd2fedf06f446e6d9f79a3bbeeb53e

Evidence

Large high-entropy overlay 0x0–0xb0
0x04d5a4ad2bbd328af40eac1ca27170988MZJ...(.@...'...
0x102dc58dc2411b6cea28efd9e7c8765ee7-...A.l.(....v^.
0x2076ae1b3f85d05137433bf902dc2d4b24v..?..Q7C;...-K$
⋯9 more rows
TerminateProcess API name in binary strings 0x40eed–0x411dd
⋯3 more rows
0x40f1d0000004b45524e454c33322e444c4c00...KERNEL32.DLL.
0x40f2d41544c2e444c4c0047444933322e646cATL.DLL.GDI32.dl
0x40f3d6c00676469706c75732e646c6c004d53l.gdiplus.dll.MS
0x40f4d494d4733322e646c6c004d5356435254IMG32.dll.MSVCRT
0x40f5d2e646c6c006f6c6533322e646c6c004f.dll.ole32.dll.O
0x40f6d4c4541555433322e646c6c005348454cLEAUT32.dll.SHEL
0x40f7d4c33322e646c6c0053484c574150492eL32.dll.SHLWAPI.
0x40f8d646c6c005553455233322e646c6c0057dll.USER32.dll.W
0x40f9d494e494e45542e646c6c0000004d756cININET.dll...Mul
0x40fad746942797465546f5769646543686172tiByteToWideChar
0x40fbd0000005769646543686172546f4d756c...WideCharToMul
0x40fcd7469427974650000004d756c44697600tiByte...MulDiv.
0x40fdd00476c6f62616c556e6c6f636b000052.GlobalUnlock..R
0x40fed746c4d6f76654d656d6f727900000047tlMoveMemory...G
0x40ffd6c6f62616c467265650000476c6f6261lobalFree..Globa
0x4100d6c4c6f636b0000476c6f62616c416c6clLock..GlobalAll
0x4101d6f6300000043616e63656c5761697461oc...CancelWaita
0x4102d626c6554696d65720000005365745761bleTimer...SetWa
0x4103d697461626c6554696d65720000437265itableTimer..Cre
0x4104d6174655761697461626c6554696d6572ateWaitableTimer
0x4105d4100005465726d696e61746550726f63A..TerminateProc
0x4106d65737300004f70656e50726f63657373ess..OpenProcess
0x4107d0000004d6f64756c6533324669727374...Module32First
0x4108d000000436c6f736548616e646c650000...CloseHandle..
0x4109d0050726f6365737333324e6578740000.Process32Next..
0x410ad0050726f636573733332466972737400.Process32First.
0x410bd00437265617465546f6f6c68656c7033.CreateToolhelp3
0x410cd32536e617073686f7400004765744d6f2Snapshot..GetMo
0x410dd64756c6546696c654e616d6541000047duleFileNameA..G
⋯9 more rows
0x4117d65745469636b436f756e740000577269etTickCount..Wri
0x4118d746546696c65000000476574456e7669teFile...GetEnvi
0x4119d726f6e6d656e745661726961626c6541ronmentVariableA
0x411ad00000043726561746546696c65410000...CreateFileA..
⋯3 more rows
InternetCloseHandle API name 0x41cbc–0x41dec
⋯3 more rows
0x41cec6c7469706c654f626a65637473000000ltipleObjects...
0x41cfc487474705175657279496e666f410000HttpQueryInfoA..
0x41d0c496e7465726e65745265616446696c65InternetReadFile
0x41d1c00004874747053656e64526571756573..HttpSendReques
0x41d2c74410000487474704f70656e52657175tA..HttpOpenRequ
0x41d3c657374410000496e7465726e6574436festA..InternetCo
0x41d4c6e6e656374410000496e7465726e6574nnectA..Internet
0x41d5c436c6f736548616e646c65000000496eCloseHandle...In
0x41d6c7465726e65744f70656e410000000000ternetOpenA.....
0x41d7c00000000000000000000000000000000................
⋯7 more rows
GUI import cluster BeginPaint 0x41fc0–0x422b0
⋯3 more rows
0x41ff000000000000000000000000000000000................
0x4200000000000000000000000000000000000................
0x4201000000000000000000000000000000000................
0x4202000000000000000000000000000000000................
0x4203000000000000000000000000000000000................
0x4204000000000000000000000000000000000................
0x4205000000000000000000000000000000000................
0x4206000000000000000000000000000000000................
0x4207000000000000000000000000000000000................
0x4208000000000000000000000000000000000................
0x4209000000000000000000000000000000000................
0x420a000000000000000000000000000000000................
0x420b000000000000000000000000000000000................
0x420c000000000000000000000000000000000................
0x420d000000000000000000000000000000000................
0x420e000000000000000000000000000000000................
0x420f000000000000000000000000000000000................
0x4210000000000000000000000000000000000................
0x4211000000000000000000000000000000000................
0x4212000000000000000000000000000000000................
0x4213000000000000000000000000000000000................
0x4214000000000000000000000000000000000................
0x4215000000000000000000000000000000000................
0x4216000000000000000000000000000000000................
0x4217000000000000000000000000000000000................
0x4218000000000000000000000000000000000................
0x4219000000000000000000000000000000000................
0x421a000000000000000000000000000000000................
0x421b000000000000000000000000000000000................
0x421c000000000000000000000000000000000................
⋯7 more rows
0x42240514170702e65786500515150726f7465QApp.exe.QQProte
0x4225063742e6578650001000000000000002ect.exe..........
0x422606578650053797371616d717176617171exe.Sysqamqqvaqq
0x42270642e6578650053797371616d005c0001d.exe.Sysqam.\..
0x42280000000000100005c53797374656d526f.......\SystemRo
0x422906f740053797374656d526f6f74005c3fot.SystemRoot.\?
0x422a03f5c006f70656e00000000000088c3c0?\.open.........
0x422b0ccdad1b6515100684a744a764c724c77....QQ.hJtJvLrLw
References an HTTP Content-Type header 0x509f1–0x50cb1
⋯7 more rows
0x50a6184aa5c7eda7fac31082f71cb18bfffd9..\~...1./q.....
0x50a71504f53540047455400557365722d4167POST.GET.User-Ag
0x50a81656e743a000d0a004d6f7a696c6c612fent:....Mozilla/
0x50a91342e302028636f6d70617469626c653b4.0 (compatible;
0x50aa1204d53494520392e303b2057696e646f MSIE 9.0; Windo
0x50ab17773204e5420362e313b203132354c41ws NT 6.1; 125LA
0x50ac13b202e4e455420434c5220322e302e35; .NET CLR 2.0.5
0x50ad1303732373b202e4e455420434c5220330727; .NET CLR 3
0x50ae12e302e30343530362e3634383b202e4e.0.04506.648; .N
0x50af1455420434c5220332e352e3231303232ET CLR 3.5.21022
0x50b012900687474703d006874747073004854).http=.https.HT
0x50b1154502f312e3100526566657265723a00TP/1.1.Referer:.
0x50b21526566657265723a20000d0a52656665Referer: ...Refe
⋯3 more rows
0x50b6163636570742d4c616e67756167653a20ccept-Language:
0x50b717a682d636e00436f6e74656e742d5479zh-cn.Content-Ty
0x50b8170653a000d0a436f6e74656e742d5479pe:...Content-Ty
0x50b9170653a206170706c69636174696f6e2fpe: application/
0x50ba1782d7777772d666f726d2d75726c656ex-www-form-urlen
0x50bb1636f646564000d0a436f6f6b69653a20coded...Cookie:
0x50bc1004c6f636174696f6e3a005365742d43.Location:.Set-C
⋯15 more rows
TerminateProcess API name in binary strings Trojan.Danger_Trojan.GenericKD.72853156_372_1.vir · 0x40eed–0x411dd
⋯3 more rows
0x40f1d0000004b45524e454c33322e444c4c00...KERNEL32.DLL.
0x40f2d41544c2e444c4c0047444933322e646cATL.DLL.GDI32.dl
0x40f3d6c00676469706c75732e646c6c004d53l.gdiplus.dll.MS
0x40f4d494d4733322e646c6c004d5356435254IMG32.dll.MSVCRT
0x40f5d2e646c6c006f6c6533322e646c6c004f.dll.ole32.dll.O
0x40f6d4c4541555433322e646c6c005348454cLEAUT32.dll.SHEL
0x40f7d4c33322e646c6c0053484c574150492eL32.dll.SHLWAPI.
0x40f8d646c6c005553455233322e646c6c0057dll.USER32.dll.W
0x40f9d494e494e45542e646c6c0000004d756cININET.dll...Mul
0x40fad746942797465546f5769646543686172tiByteToWideChar
0x40fbd0000005769646543686172546f4d756c...WideCharToMul
0x40fcd7469427974650000004d756c44697600tiByte...MulDiv.
0x40fdd00476c6f62616c556e6c6f636b000052.GlobalUnlock..R
0x40fed746c4d6f76654d656d6f727900000047tlMoveMemory...G
0x40ffd6c6f62616c467265650000476c6f6261lobalFree..Globa
0x4100d6c4c6f636b0000476c6f62616c416c6clLock..GlobalAll
0x4101d6f6300000043616e63656c5761697461oc...CancelWaita
0x4102d626c6554696d65720000005365745761bleTimer...SetWa
0x4103d697461626c6554696d65720000437265itableTimer..Cre
0x4104d6174655761697461626c6554696d6572ateWaitableTimer
0x4105d4100005465726d696e61746550726f63A..TerminateProc
0x4106d65737300004f70656e50726f63657373ess..OpenProcess
0x4107d0000004d6f64756c6533324669727374...Module32First
0x4108d000000436c6f736548616e646c650000...CloseHandle..
0x4109d0050726f6365737333324e6578740000.Process32Next..
0x410ad0050726f636573733332466972737400.Process32First.
0x410bd00437265617465546f6f6c68656c7033.CreateToolhelp3
0x410cd32536e617073686f7400004765744d6f2Snapshot..GetMo
0x410dd64756c6546696c654e616d6541000047duleFileNameA..G
⋯9 more rows
0x4117d65745469636b436f756e740000577269etTickCount..Wri
0x4118d746546696c65000000476574456e7669teFile...GetEnvi
0x4119d726f6e6d656e745661726961626c6541ronmentVariableA
0x411ad00000043726561746546696c65410000...CreateFileA..
⋯3 more rows
InternetCloseHandle API name Trojan.Danger_Trojan.GenericKD.72853156_372_1.vir · 0x41cbc–0x41dec
⋯3 more rows
0x41cec6c7469706c654f626a65637473000000ltipleObjects...
0x41cfc487474705175657279496e666f410000HttpQueryInfoA..
0x41d0c496e7465726e65745265616446696c65InternetReadFile
0x41d1c00004874747053656e64526571756573..HttpSendReques
0x41d2c74410000487474704f70656e52657175tA..HttpOpenRequ
0x41d3c657374410000496e7465726e6574436festA..InternetCo
0x41d4c6e6e656374410000496e7465726e6574nnectA..Internet
0x41d5c436c6f736548616e646c65000000496eCloseHandle...In
0x41d6c7465726e65744f70656e410000000000ternetOpenA.....
0x41d7c00000000000000000000000000000000................
⋯7 more rows
GUI import cluster BeginPaint Trojan.Danger_Trojan.GenericKD.72853156_372_1.vir · 0x41fc0–0x422b0
⋯3 more rows
0x41ff000000000000000000000000000000000................
0x4200000000000000000000000000000000000................
0x4201000000000000000000000000000000000................
0x4202000000000000000000000000000000000................
0x4203000000000000000000000000000000000................
0x4204000000000000000000000000000000000................
0x4205000000000000000000000000000000000................
0x4206000000000000000000000000000000000................
0x4207000000000000000000000000000000000................
0x4208000000000000000000000000000000000................
0x4209000000000000000000000000000000000................
0x420a000000000000000000000000000000000................
0x420b000000000000000000000000000000000................
0x420c000000000000000000000000000000000................
0x420d000000000000000000000000000000000................
0x420e000000000000000000000000000000000................
0x420f000000000000000000000000000000000................
0x4210000000000000000000000000000000000................
0x4211000000000000000000000000000000000................
0x4212000000000000000000000000000000000................
0x4213000000000000000000000000000000000................
0x4214000000000000000000000000000000000................
0x4215000000000000000000000000000000000................
0x4216000000000000000000000000000000000................
0x4217000000000000000000000000000000000................
0x4218000000000000000000000000000000000................
0x4219000000000000000000000000000000000................
0x421a000000000000000000000000000000000................
0x421b000000000000000000000000000000000................
0x421c000000000000000000000000000000000................
⋯7 more rows
0x42240514170702e65786500515150726f7465QApp.exe.QQProte
0x4225063742e6578650001000000000000002ect.exe..........
0x422606578650053797371616d717176617171exe.Sysqamqqvaqq
0x42270642e6578650053797371616d005c0001d.exe.Sysqam.\..
0x42280000000000100005c53797374656d526f.......\SystemRo
0x422906f740053797374656d526f6f74005c3fot.SystemRoot.\?
0x422a03f5c006f70656e00000000000088c3c0?\.open.........
0x422b0ccdad1b6515100684a744a764c724c77....QQ.hJtJvLrLw
References an HTTP Content-Type header Trojan.Danger_Trojan.GenericKD.72853156_372_1.vir · 0x509f1–0x50cb1
⋯7 more rows
0x50a6184aa5c7eda7fac31082f71cb18bfffd9..\~...1./q.....
0x50a71504f53540047455400557365722d4167POST.GET.User-Ag
0x50a81656e743a000d0a004d6f7a696c6c612fent:....Mozilla/
0x50a91342e302028636f6d70617469626c653b4.0 (compatible;
0x50aa1204d53494520392e303b2057696e646f MSIE 9.0; Windo
0x50ab17773204e5420362e313b203132354c41ws NT 6.1; 125LA
0x50ac13b202e4e455420434c5220322e302e35; .NET CLR 2.0.5
0x50ad1303732373b202e4e455420434c5220330727; .NET CLR 3
0x50ae12e302e30343530362e3634383b202e4e.0.04506.648; .N
0x50af1455420434c5220332e352e3231303232ET CLR 3.5.21022
0x50b012900687474703d006874747073004854).http=.https.HT
0x50b1154502f312e3100526566657265723a00TP/1.1.Referer:.
0x50b21526566657265723a20000d0a52656665Referer: ...Refe
⋯3 more rows
0x50b6163636570742d4c616e67756167653a20ccept-Language:
0x50b717a682d636e00436f6e74656e742d5479zh-cn.Content-Ty
0x50b8170653a000d0a436f6e74656e742d5479pe:...Content-Ty
0x50b9170653a206170706c69636174696f6e2fpe: application/
0x50ba1782d7777772d666f726d2d75726c656ex-www-form-urlen
0x50bb1636f646564000d0a436f6f6b69653a20coded...Cookie:
0x50bc1004c6f636174696f6e3a005365742d43.Location:.Set-C
⋯15 more rows
Packed binary with WinInet and dynamic loading embedded:pe@0x86b28 · 0x0–0xd0
0x04d5a90000300000004000000ffff0000MZ..............
0x10b8000000000000004000000000000000........@.......
0x2000000000000000000000000000000000................
⋯11 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.