Ursnif is a banking Trojan that usually infects corporate victims. It is based on an old malware but was substantially updated over the years and became quite powerful. Today Ursnif is one of the most widely spread banking Trojans in the world.
MALICIOUS | SUSPICIOUS | INFO |
---|---|---|
Changes the autorun value in the registry
|
Starts CMD.EXE for commands execution
|
No info indicators. |
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
UPX0 | 0x00001000 | 0x092C2000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 0 |
UPX1 | 0x092C3000 | 0x0007C000 | 0x0007BE00 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 7.57801 |
.rsrc | 0x0933F000 | 0x00002000 | 0x00001800 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 4.78674 |
No resources.
No exports.
Click at the process to see the details.
Image |
---|
c:\windows\explorer.exe |
c:\windows\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\explorerframe.dll |
c:\windows\system32\duser.dll |
c:\windows\system32\dui70.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\uxtheme.dll |
c:\windows\system32\powrprof.dll |
c:\windows\system32\setupapi.dll |
c:\windows\system32\cfgmgr32.dll |
c:\windows\system32\devobj.dll |
c:\windows\system32\dwmapi.dll |
c:\windows\system32\slc.dll |
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll |
c:\windows\system32\secur32.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\propsys.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\windowscodecs.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\apphelp.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\ehstorshell.dll |
c:\windows\system32\cscui.dll |
c:\windows\system32\cscdll.dll |
c:\windows\system32\cscapi.dll |
c:\windows\system32\ntshrui.dll |
c:\windows\system32\srvcli.dll |
c:\windows\system32\iconcodecservice.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\system32\rpcrtremote.dll |
c:\windows\system32\sndvolsso.dll |
c:\windows\system32\hid.dll |
c:\windows\system32\mmdevapi.dll |
c:\windows\system32\timedate.cpl |
c:\windows\system32\atl.dll |
c:\windows\system32\winbrand.dll |
c:\windows\system32\actxprxy.dll |
c:\windows\system32\ntmarta.dll |
c:\windows\system32\wldap32.dll |
c:\windows\system32\shdocvw.dll |
c:\windows\system32\linkinfo.dll |
c:\windows\system32\userenv.dll |
c:\windows\system32\shacct.dll |
c:\windows\system32\samlib.dll |
c:\windows\system32\samcli.dll |
c:\windows\system32\netutils.dll |
c:\windows\system32\msftedit.dll |
c:\windows\system32\msls31.dll |
c:\program files\common files\microsoft shared\ink\tiptsf.dll |
c:\windows\system32\authui.dll |
c:\windows\system32\cryptui.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\gameux.dll |
c:\windows\system32\xmllite.dll |
c:\windows\system32\wer.dll |
c:\windows\system32\msiltcfg.dll |
c:\windows\system32\version.dll |
c:\windows\system32\msi.dll |
c:\windows\system32\winsta.dll |
c:\windows\system32\psapi.dll |
c:\windows\system32\networkexplorer.dll |
c:\windows\system32\winmm.dll |
c:\windows\system32\wdmaud.drv |
c:\windows\system32\ksuser.dll |
c:\windows\system32\avrt.dll |
c:\windows\system32\audioses.dll |
c:\windows\system32\msacm32.drv |
c:\windows\system32\msacm32.dll |
c:\windows\system32\midimap.dll |
c:\windows\system32\stobject.dll |
c:\windows\system32\batmeter.dll |
c:\windows\system32\wtsapi32.dll |
c:\windows\system32\es.dll |
c:\windows\system32\prnfldr.dll |
c:\windows\system32\winspool.drv |
c:\windows\system32\dxp.dll |
c:\windows\system32\urlmon.dll |
c:\windows\system32\wininet.dll |
c:\windows\system32\iertutil.dll |
c:\windows\system32\syncreg.dll |
c:\windows\ehome\ehsso.dll |
c:\windows\system32\netshell.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\winnsi.dll |
c:\windows\system32\nlaapi.dll |
c:\windows\system32\alttab.dll |
c:\windows\system32\wpdshserviceobj.dll |
c:\windows\system32\portabledevicetypes.dll |
c:\windows\system32\portabledeviceapi.dll |
c:\program files\filezilla ftp client\fzshellext.dll |
c:\windows\system32\wintrust.dll |
c:\windows\system32\taskschd.dll |
c:\windows\system32\pnidui.dll |
c:\windows\system32\qutil.dll |
c:\windows\system32\wevtapi.dll |
c:\windows\system32\dhcpcsvc6.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\dhcpcsvc.dll |
c:\windows\system32\mssprxy.dll |
c:\windows\system32\npmproxy.dll |
c:\windows\system32\wlanapi.dll |
c:\windows\system32\wlanutil.dll |
c:\windows\system32\wwanapi.dll |
c:\windows\system32\wwapi.dll |
c:\windows\system32\qagent.dll |
c:\windows\system32\srchadmin.dll |
c:\windows\system32\sxs.dll |
c:\windows\system32\bthprops.cpl |
c:\windows\system32\ieframe.dll |
c:\windows\system32\oleacc.dll |
c:\windows\system32\synccenter.dll |
c:\windows\system32\actioncenter.dll |
c:\windows\system32\imapi2.dll |
c:\windows\system32\hgcpl.dll |
c:\windows\system32\provsvc.dll |
c:\windows\system32\netprofm.dll |
c:\windows\system32\wkscli.dll |
c:\windows\system32\fxsst.dll |
c:\windows\system32\fxsapi.dll |
c:\windows\system32\fxsresm.dll |
c:\windows\system32\wscinterop.dll |
c:\windows\system32\wscapi.dll |
c:\windows\system32\wscui.cpl |
c:\windows\system32\werconcpl.dll |
c:\windows\system32\framedynos.dll |
c:\windows\system32\wercplsupport.dll |
c:\windows\system32\msxml6.dll |
c:\windows\system32\hcproviders.dll |
c:\program files\internet explorer\ieproxy.dll |
c:\windows\system32\mpr.dll |
c:\windows\system32\drprov.dll |
c:\windows\system32\ntlanman.dll |
c:\windows\system32\davclnt.dll |
c:\windows\system32\davhlpr.dll |
c:\windows\system32\searchfolder.dll |
c:\windows\system32\structuredquery.dll |
c:\windows\system32\naturallanguage6.dll |
c:\windows\system32\nlsdata0009.dll |
c:\windows\system32\nlslexicons0009.dll |
c:\windows\system32\thumbcache.dll |
c:\windows\system32\tquery.dll |
c:\program files\microsoft office\office14\onfilter.dll |
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll |
c:\windows\system32\sfc.dll |
c:\windows\system32\sfc_os.dll |
c:\windows\system32\devrtl.dll |
c:\windows\system32\winanr.dll |
c:\windows\system32\mswsock.dll |
c:\windows\system32\wshtcpip.dll |
c:\users\admin\appdata\local\temp\read.exe |
c:\windows\system32\winhttp.dll |
c:\windows\system32\webio.dll |
c:\windows\system32\credssp.dll |
c:\windows\system32\wship6.dll |
c:\windows\system32\dnsapi.dll |
c:\windows\system32\rasadhlp.dll |
c:\windows\system32\napinsp.dll |
c:\windows\system32\pnrpnsp.dll |
c:\windows\system32\winrnr.dll |
c:\windows\system32\fwpuclnt.dll |
c:\windows\system32\msoeacct.dll |
c:\windows\system32\msoert2.dll |
c:\windows\system32\inetcomm.dll |
c:\windows\system32\inetres.dll |
c:\windows\system32\acctres.dll |
c:\windows\system32\msxml3.dll |
c:\program files\common files\system\wab32.dll |
c:\windows\system32\cryptdlg.dll |
c:\windows\system32\imagehlp.dll |
c:\windows\system32\msimg32.dll |
Image |
---|
c:\users\admin\appdata\local\temp\read.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msimg32.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\msvcr100.dll |
Image |
---|
c:\windows\system32\cmd.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\winbrand.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\apphelp.dll |
c:\windows\system32\nslookup.exe |
Image |
---|
c:\windows\system32\nslookup.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\wsock32.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\mswsock.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\dnsapi.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\wshtcpip.dll |
c:\windows\system32\nlaapi.dll |
c:\windows\system32\napinsp.dll |
c:\windows\system32\pnrpnsp.dll |
c:\windows\system32\winrnr.dll |
c:\windows\system32\wship6.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\winnsi.dll |
c:\windows\system32\rasadhlp.dll |
c:\windows\system32\fwpuclnt.dll |
Image |
---|
c:\windows\system32\cmd.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\winbrand.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
252 | explorer.exe | GET | –– | 78.90.243.124:80 | http://adonis-medicine.at/images/5FMBCYNMV/5k_2FueXQtJzOZ3rQsZZ/4n5aqAIwKhXHZB5CwfD/JfMsx8OsYTmXAJdQzCxUEk/mNaZz_2BBy33i/NUCT37Kr/6SLu2VA_2BjLnAe95S8BoF_/2BDv_2Fg8h/PaDBlIGgf57kc3cGf/SWJpxBqnCunS/dzKey5U321t/P_2F82BPycSMZG/uR7zFbtrUudkMqys2e4OM/a8LXh.gif | BG |
––
|
––
|
malicious |
252 | explorer.exe | POST | –– | 78.90.243.124:80 | http://adonis-medicine.at/images/YSKHC_2F_2BXWMcT/p4zF1RUJHhgBDUN/7IHAc81KJkgrcBLDf9/lkPTDOenT/dQKvgnQ8qViUymN5bYQS/bhIHjy0o6NXzKudYwxp/_2Fp6lDiLHFXUXSDK_2BET/K8VQBl6TT6mrr/RJOo8LCr/SV3QhkiWZBzkdW_2F_2ByKs/bvQDCyIUEz/i_2FuycfdpCEntqdB/rQs7XhhQM_2F/pHq6Cq2QfNa/axOybq5y8H5z0Z/M9k.bmp | BG |
binary
––
|
––
|
malicious |
PID | Process | IP | ASN | CN | Reputation |
---|---|---|---|---|---|
2968 | nslookup.exe | 208.67.222.222:53 | OpenDNS, LLC | US | malicious |
252 | explorer.exe | 78.90.243.124:80 | Mobiltel Ead | BG | malicious |
Domain | IP | Reputation |
---|---|---|
11totalzaelooop11.club | No response | unknown |
resolver1.opendns.com | 208.67.222.222
|
shared |
222.222.67.208.in-addr.arpa | No response | unknown |
myip.opendns.com | 212.7.217.54
|
shared |
adonis-medicine.at | 78.90.243.124
84.54.187.24 194.204.25.137 79.100.148.150 31.5.167.149 86.61.75.99 212.98.131.181 151.251.23.210 188.254.179.205 188.143.24.123 |
malicious |
PID | Process | Class | Message |
---|---|---|---|
2968 | nslookup.exe | Potential Corporate Privacy Violation | ET POLICY External IP Lookup Domain (myip.opendns .com in DNS lookup) |
2968 | nslookup.exe | Potential Corporate Privacy Violation | ET POLICY External IP Lookup Domain (myip.opendns .com in DNS lookup) |
252 | explorer.exe | A Network Trojan was detected | ET TROJAN Ursnif Variant CnC Beacon |
252 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] W32.Dreambot HTTP GET Check-in |
252 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] W32.Dreambot HTTP |
252 | explorer.exe | A Network Trojan was detected | ET TROJAN Ursnif Variant CnC Data Exfil |
252 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] W32.Dreambot HTTP GET Check-in |
252 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] W32.Dreambot HTTP |
No debug info.