File name:

SecuriteInfo.com.Trojan.Win32.VMProtect.11906

Full analysis: https://app.any.run/tasks/735d034b-2056-44c9-88c2-9a59261ac143
Verdict: Malicious activity
Threats:

Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.

Analysis date: September 10, 2022, 14:02:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
rat
redline
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

CFA34647EAB02295BA2BE704C17AF700

SHA1:

9011573060BFDA6F3E677B67BE64A2D723210D79

SHA256:

D671AD5AE7F3211B7582407339BF7BAC0A6C861E400749F8A612D86088746EA7

SSDEEP:

98304:jXFQ1lFTB/OXsm1F+CXn9iGlxD+DLvnEOpGB7k8D:j49O7v93sGqzEvBD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials from Web Browsers

      • SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exe (PID: 3388)
    • REDLINE detected by memory dumps

      • SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exe (PID: 3388)
    • REDLINE was detected

      • SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exe (PID: 3388)
    • Connects to CnC server

      • SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exe (PID: 3388)
    • Actions looks like stealing of personal data

      • SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exe (PID: 3388)
  • SUSPICIOUS

    • Checks supported languages

      • SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exe (PID: 3388)
    • Reads the computer name

      • SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exe (PID: 3388)
    • Reads the cookies of Google Chrome

      • SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exe (PID: 3388)
    • Reads Environment values

      • SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exe (PID: 3388)
    • Reads the cookies of Mozilla Firefox

      • SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exe (PID: 3388)
    • Searches for installed software

      • SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exe (PID: 3388)
  • INFO

    • Reads settings of System Certificates

      • SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exe (PID: 3388)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (38.3)
.exe | Win32 Executable (generic) (26.2)
.exe | Win16/32 Executable Delphi generic (12)
.exe | Generic Win/DOS Executable (11.6)
.exe | DOS Executable Generic (11.6)

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 2012-Jul-13 22:47:16
Detected languages:
  • English - United States
CompanyName: chebrowser
FileDescription: Revolutionary anti-detect browser for multiple accounts
FileVersion: 0.3.0.0
InternalName: nw_exe
LegalCopyright: -
OriginalFilename: nw.exe
ProductName: chebrowser
ProductVersion: 0.3.0.0
CompanyShortName: nwjs.io
ProductShortName: nwjs
LastChange: 62f83a7521ae1f32e563795732dff0c9da1b660d-refs/heads/master@{#812354}

DOS Header

e_magic: MZ
e_cblp: 144
e_cp: 3
e_crlc: -
e_cparhdr: 4
e_minalloc: -
e_maxalloc: 65535
e_ss: -
e_sp: 184
e_csum: -
e_ip: -
e_cs: -
e_ovno: -
e_oemid: -
e_oeminfo: -
e_lfanew: 128

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
NumberofSections: 6
TimeDateStamp: 2012-Jul-13 22:47:16
PointerToSymbolTable: -
NumberOfSymbols: -
SizeOfOptionalHeader: 224
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LARGE_ADDRESS_AWARE
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
4096
104216
104448
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.7535
.rdata
110592
28084
28160
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
6.63272
.data
139264
12480
5632
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
3.26259
#% )(\xc6\x92\xe2
155648
3094294
3094528
IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
7.81145
#% )(\xc6\x92\xe2 (#2)
3252224
1936688
1936896
IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
7.68269
.rsrc
5189632
33068
33280
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.13525

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.0272
4264
UNKNOWN
UNKNOWN
RT_ICON
2
4.85395
9640
UNKNOWN
UNKNOWN
RT_ICON
3
4.98358
16936
UNKNOWN
UNKNOWN
RT_ICON
MAINICON
2.51589
48
UNKNOWN
UNKNOWN
RT_GROUP_ICON
1 (#2)
3.42816
1008
UNKNOWN
UNKNOWN
RT_VERSION
1 (#3)
5.17015
752
UNKNOWN
UNKNOWN
RT_MANIFEST

Imports

KERNEL32.dll
KERNEL32.dll (#2)
KERNEL32.dll (#3)
OLEAUT32.dll
USER32.dll
USER32.dll (#2)
WTSAPI32.dll
ole32.dll
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #REDLINE securiteinfo.com.trojan.win32.vmprotect.11906.exe

Process information

PID
CMD
Path
Indicators
Parent process
3388"C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exe" C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exe
Explorer.EXE
User:
admin
Company:
chebrowser
Integrity Level:
MEDIUM
Description:
Revolutionary anti-detect browser for multiple accounts
Exit code:
0
Version:
0.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\securiteinfo.com.trojan.win32.vmprotect.11906.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
Total events
4 136
Read events
4 110
Write events
26
Delete events
0

Modification events

(PID) Process:(3388) SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SecuriteInfo_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3388) SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SecuriteInfo_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3388) SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SecuriteInfo_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(3388) SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SecuriteInfo_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(3388) SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SecuriteInfo_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(3388) SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SecuriteInfo_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(3388) SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SecuriteInfo_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3388) SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SecuriteInfo_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3388) SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SecuriteInfo_RASMANCS
Operation:writeName:FileTracingMask
Value:
(PID) Process:(3388) SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SecuriteInfo_RASMANCS
Operation:writeName:ConsoleTracingMask
Value:
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
2
Threats
27

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3388
SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exe
80.76.51.84:81
ns4.livelogs.xyz
malicious
3388
SecuriteInfo.com.Trojan.Win32.VMProtect.11906.exe
104.26.13.31:443
api.ip.sb
Cloudflare Inc
US
suspicious

DNS requests

Domain
IP
Reputation
ns4.livelogs.xyz
  • 80.76.51.84
malicious
api.ip.sb
  • 104.26.13.31
  • 172.67.75.172
  • 104.26.12.31
whitelisted

Threats

Found threats are available for the paid subscriptions
27 ETPRO signatures available at the full report
No debug info