Post Valkyrie Links in Which You Believe That The Manual Analysis Is Wrong

I have accidentally deleted ( again during the execution of copy / paste operations and an unexpected imposed log off 88) ) my previous post ! :-\ If somebody had already checked it , please give me a short info . Thank you !!! >>> Advanced File Analysis System | Valkyrie VT : VirusTotal >>> My final Verdict is NOT Clean !!! But sometimes it´s just a question off definition … ! :wink:

Two new Files :

Human Expert Analysis = Clean >>> Advanced File Analysis System | Valkyrie
VT : VirusTotal

My Analysis Verdict = Not Clean - PUA.Variant.InstallCore

Some suspicious/malicious indicators : Matched Compiler/Packer signature ( Borland Delphi 4.0. ) , File has multiple PE Anomalies ( File contains more then 8 sections , PE file contains zero-size sections , PE Parsing in Sections “bss” , “tls”, “reloc” ) , File Code is packed and obfuscated , Reads the registry for installed applications , Scanning for window names , Scans for the windows taskbar , Contains ability to lookup the windows account name , Contains ability to reboot/shutdown the operating system , Opens the Kernel Security Device Driver , Found a known API Export symbol ( Found reference to API SHGetFolderPathA[at]SHFOLDER.DLL at PID 00002728 ) , Drops mutiple executable files , Drops executable files to the Windows system directory ( File type “VAX-order 68k Blit mpx/mux executable” was dropped at “%WINDIR%\Tasks\CouponViewer Toolbar.job” ) , Process drops a File with positive VT detection >>> “CVHP.exe” >>> VirusTotal , Creates named pipes for inter-process communication ( CreateNamedPipeA[at]KERNEL32.DLL at PID 00002728 & CreateNamedPipeA[at]KERNEL32.DLL at PID 00002800 ) , Installs hooks/patches the running process ( “regsvr32.exe” wrote bytes to address “0x76FE1000” ( part of NSI.DLL )

Dropped File :

Human Expert Analysis = Clean >>> Advanced File Analysis System | Valkyrie
VT : VirusTotal

My Analysis Verdict = Not Clean - PUA.Adware.Elex

Some suspicious/malicious indicators from the dropped File “CVHP.exe”: Found many suspicious Strings in file hex table , Matched Compiler/Packer signature ( VC8 → Microsoft Corporation ) , PE file contains unusual section name , Reads the active computer name , File Code is packed and obfuscated , Contains ability to lookup the windows account name , Tries to create guarded memory sections , Reads the registry for installed applications , Opens the Kernel Security Device Driver , Found API Hooks , Drops executable files ( CouponViewer Toolbar.job" has type "VAX-order 68k Blit mpx/mux executable ) , File querries the “Windows Internet library” and “Event Log” , File querries sensitive Browser settings (IE) ,

Not Clean !!!

PUA.Adware.InstallCore

Some suspicious/malicious Indicators : Matched Compiler/Packer signature > Compiler : Borland Delphi 6.0 - 7.0 , Packer : Inno Setup Installer , File has multiple PE Anomalies ( File ignores DEP , File ignores Code Integrity , Embeds another File ( type : Inno Setup , location : Resources ) CRC value set in PE header does not match actual value , PE file contains zero-size sections , The File has 3 shared sections , Contains unknown Resources , The file references 3 languages in the Resources ) , Contains ability to start/interact with device drivers , Contains ability to elevate privileges , Contains ability to create named pipes , Contains ability to lookup the windows account name , Found strings in conjunction with a procedure lookup that resolve to a known API export symbol , Tries to delay the analysis , Drops executable files , Creates guarded memory sections , Reads the active computer name , Scanning for window names , Reads the registry for installed applications , Scans for the windows taskbar , Queries process information , Looks up many procedures within the same disassembly stream ( Found 57 calls to GetProcAddress[at]KERNEL32.DLL ) , Wrotes bytes to itself , Duplicates the process handle of an other process to obtain access rights to that process , Accesses to the Windows default Safe DLL search path , Opens the Kernel Security Device Driver , Found network releated activity , File tries to receives Data from h**p://www.msftncsi.com (“ncsi.txt”)

Thx for the Reanalysis !!! So please create and add a signature for this File !!!

Thank you !!!

Not Clean !!!

Riskware/Adware.YoBrowser

Some suspicious/malicious Indicators : Matched Compiler/Packer signature > Compiler : Borland Delphi 6.0 - 7.0 , Packer : Inno Extractor , File has multiple PE Anomalies ( Timestamp in PE header is very old ( from Thu Jan 1 00:00:00 1970 ) , Embeds another File ( Type: Inno Setup , location: Overlay ) , File ignores Code Integrity , PE file contains zero-size sections , File has 3 shared sections , Contains unknown resources , resources contains 3 different languages ) , Contains ability to elevate privileges , Contains ability to enumerate processes/modules/threads , Contains ability to start/interact with device drivers , Contains ability to query CPU information , Contains ability to lookup the windows account name , Contains ability to create named pipes , Found Anti-VM Strings ( Found VM detection artifact “RDTSCP trick” (Offset: 220562) , Tries to delay the analysis ( “explorer.exe” tries to delay the analysis ) , Creates guarded memory sections , Reads the active computer name , Reads the registry for installed applications , Drops executable files ( dropped file “wharfholder.dll” was classified as “Application.Generic” with 19% detection rate on VT ) , Duplicates the process handle of an other process to obtain access rights to that process , Opens the Kernel Security Device Driver , Looks up many procedures within the same disassembly stream ( Found 57 calls to GetProcAddress@KERNEL32.DLL ) , Installs hooks/patches the running process ( File writes data to “SHFOLDER.DLL” , “MSIMG32.DLL” , “NSI.DLL” ) , Found Misc Activity ( Windows OS Submitting USB Metadata to Microsoft )

Not Clean !!!

PUA/Riskware.Downloader.Auslogics.BoostSpeed

Some suspicious/malicious Indicators : Matched Compiler/Packer/Crypter signature > Compiler : Borland Delphi 6.0 - 7.0 , Packer/Crypter : UPX 1.95 Beta - 3.x , File has mutiple PE Anomalies ( File ignores DEP , File ignores Code Integrity , Entrypoint is outside of first section , Checksum mismatches the PE header value , PE file contains zero-size sections , The file has 2 writable and executable sections , The file contains 7 unknown resources , The size “17048 bytes” of the certificate is suspicious , Imports sensitive Libaries > Net Win32 API DLL , Internet Extensions for Win32 ) , Contains ability to lookup the windows account name , Found Anti-VM Strings ( Querries the disk size , Checks network adapter addresses , Checks amount of memory in system ) , Checks for the presence of an Antivirus engine ( Malwarebytes ) , Tries to obtain the highest possible privilege level without UAC dialog , Creates guarded memory sections , Modifies file/console tracing settings , Reads the registry for installed applications , Reads the active computer name , Reads the cryptographic machine GUID , Accesses sensitive information from local browsers ( %APPDATA%\Microsoft\Windows\Cookies\index.dat & %LOCALAPPDATA%\Microsoft\Windows\History\History.IE5\index.dat ) , Modifies proxy settings , Creates windows services ( “CREATE”; Path: “HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS” ) , Opens the Kernel Security Device Driver , Found network releated activity ( collected information will be sent back to google >>> Host : “google-analytics.com/collect

Sorry Guys , but i`ve found another one !!!

PUA/Adware.Variant.InstallCore

Some suspicious/malicious Indicators : Matched Compiler/Packer/Crypter signature > Compiler : Borland Delphi 6.0 - 7.0 , Packer : Inno Setup 5.50 , File has mutiple PE Anomalies ( Compiler Timestamp is suspicious ( 06/20/1992 ) , File ignores DEP , File ignores Code Integrity , Checksum mismatches the PE header value , PE file contains zero-size sections , File has 3 shared sections , Contains unknown resources ) , Checks if a debugger is present , Contains ability to start/interact with device drivers , Tries to delay the analysis , Creates guarded memeory sections , Drops executable files , Reads the active computer name , Reads the registry for installed applications , Scanning for window names , Scans for the windows taskbar , Queries process information , Found strings in conjunction with a procedure lookup that resolve to a known API export symbol , Makes a code branch decision directly after an API that is environment aware , Duplicates the process handle of an other process to obtain access rights to that process , Creates a windows hook that monitors keyboard input , Opens the Kernel Security Device Driver , Looks up many procedures within the same disassembly stream ( Found 57 calls to GetProcAddress[at]KERNEL32.DLL ) , Found Misc activity ( PE EXE or DLL Windows file download over HTTP on Port 49163 (TCP) )

PUA/Rogueware.ReimageRepair

Some suspicious/malicious Indicators : Matched Compiler/Packer/Crypter signature > Compiler : MS Visual C++ 10.0 , Packer : Nullsoft SFX , Armadillo v1.xx - v2.xx , File has multiple binary anomalies ( CRC value set in PE header does not match actual value , PE file contains zero-size sections ) , Contains ability to open the clipboard , Contains ability to retrieve keyboard strokes , Expects Administrative permission , References Windows built-in privileges , Found potentially Anti-VM Strings ( Checks amount of system memory , Executes one or more WMI queries ) , Tries to delay the Analysis ( “tasklist.exe” tried to sleep “840” seconds ) , Reads the active computer name , Reads the cryptographic machine GUID , Reads configuration files , Reads the registry for installed applications , Reads terminal service related keys , Drops multiple executable files , Runs shell commands , Opens the MountPointManager , Opens the Kernel Security Device Driver , Queries kernel debugger information , Touches multiple files in the Windows directory , Found Windows Hook ( “cmd.exe” wrote bytes to “USER32.DLL”)

Thanks for reanalysis ! The Fiile has a correct Valkyrie Verdict and also a positive Human Expert Verdict as Malware (PUA)[ , but the signature is missing . Please take a Look at this . Thank you !!!

PUA/Adware.Variant.InstallCore

Some suspicious/malicious Indicators : Matched Compiler/Packer/Crypter signature > Compiler : Borland Delphi , Packer : Inno Setup Installer , Confuser : nSPack v.3.7 (NET) , File has multiple binary anomalies ( File ignores DEP , File ignores Code Integrity , PE file contains zero-size sections , The count of libraries is suspicious , The Compiler-stamp is suspicious ( from “Sat - Jun 20 - 00:22:17 - 1992” ) , Checks for known debuggers/analysis tools ( “sysinternals” ) , Checks for an ADS , Has the capability to lower Firefox security settings , Tries to delay the Analysis , Reads the system/video BIOS version , Reads the windows product ID , Reads the active computer name , Reads the cryptographic machine GUID , Reads terminal service related keys , Reads the registry for installed applications , Queries volume information of an entire harddrive , Spawns a lot of processes , Creates guarded memory sections , Modifies the access control lists of files , File Duplicates the process handle of an other process to obtain access rights to that process , Creates or modifies windows services , Creates a suspicious process ( C:\Windows\SysWOW64\ie4uinit.exe" -ShowQLIcon ) , Creates known “Dyreza Banking Trojan” files ( C:\Windows\System32\duser.dll ) , Accesses potentially sensitive information from local browsers , Queries sensitive IE security settings , Modifies proxy settings , Found possibly malicious network releated activity ( Detected increased number of ARP broadcast requests , Found instsant messenger related domains , HTTP request contains Base64 encoded artifacts ) , File POSTs data to >>> “54.72.212.121:80” ( “rp.ginihehen.com” ) >>> “107.21.227.8:80” ( “hokukoca.com” ) >>> “52.214.61.44:80” ( “lahuj.com” ) , Flie GETs data from >>> “185.59.222.146:80” ( “img.ginihehen.com” ) >>> “54.230.0.232:80” ( “d2d4tyqh0a47e0.cloudfront.net” ) >>> “104.20.174.30:80” ( “cheatengine.org” ) >>> “54.230.0.78:80” ( "ic-dc.cleanrepositorytowers.com ") >>> “212.124.115.196:80” ( “1-1ads.com” )

Thank you Pio. We will review the file and update the verdict if required.

Ceyhun
Product Manager - Valkyrie Product Suite

#malware #trojan #downloader #agent

[b]https://infosec.cert-pa.it/analyze/c6830efb14d4f80e1ba6a9e56d05bce6.html[/b]

File connects to the malicious domain “bigbatman.bid” >>> VirusTotal >>> VirusTotal

Downloads a malicous program >>> GET /updated/xmrig.exe , IP: “198.251.90.113” , HTTP/1.1 , Host: bigbatman.bid >>> VirusTotal

Thanks Pio, now it’s marked as malware by the human experts.

Hi Ceyhun.b ,

thanks for reviewing the file and also for notification !!! :-TU

Best Regards !
Pio

PUA/Adware.Variant.InstallCore

Some suspicious/malicious Indicators : Matched Compiler/Packer/Crypter signature > Compiler : Borland Delphi , Packer : Inno Setup Installer - Morphine v1.2 (DLL) , File has multiple binary anomalies ( File ignores DEP , File ignores Code Integrity , PE file contains zero-size sections , Contains unknown resources , The File has 3 shared sections ) , Embeds another file ( type: InnoSetup , location: overlay ) , References Windows built-in privileges , Reads the active computer name , Scanning for window names , Reads the registry for installed applications , Queries process information , Creates guarded memory sections , Duplicates the process handle of an other process to obtain access rights to that process , Writes data to itself , Creates named pipes , Makes a code branch decision directly after an API that is environment aware , Touches multiple files in the Windows directory , Opens the Kernel Security Device Driver , Looks up many procedures within the same disassembly stream ( Found 57 calls to GetProcAddress[at]KERNEL32.DLL )

PUA.SpeedUpMyPc

Some suspicious/malicious Indicators : Matched Compiler/Packer/Crypter signature > Compiler : Borland Delphi 4.0 , File has multiple binary anomalies ( File ignores DEP , File ignores Code Integrity , Embeds another file ( type: Executable, location: resources) , The entry-point is outside the first section , Contains zero-size sections , The count “12” of libraries is suspicious , The file has “2” executable sections , Imports sensitive Libaries ( “5” Imports to “Multiple Provider Router DLL” ) , Contains ability to reboot/shutdown the operating system , Contains ability to lookup the windows account name , Contains ability to start/interact with device drivers , Contains ability to retrieve keyboard strokes , References “1” Windows built-in privilege , Has no visible windows , Tries to sleep , Creates guarded memory sections , Makes a code branch decision directly after an API that is environment aware , Runs shell commands , Operates on files in the system directory , Opens the Kernel Security Device Driver

Thank you @pio,

be09bd449ca67fd5a64c1984c325fd87b8ceff46 has been reviewed and marked as PUA.

f23567de537621e21a99a24e2844c44594f8deb5 has been reviewed and our experts classified this file as “clean” again.

Hi Ceyhun.b ,

thanks for notification ! As far as the second file is concerned , that’s just a question of definition! So no one is right or wrong and I can live with that . :wink:

Trojan.Variant.SpyUrsnif

Some suspicious/malicious Indicators : Matched Compiler/Packer/Crypter signature > Compiler : Mircosoft Visual C++ 6.0 , Packer: aPLib Compression , File has multiple binary anomalies ( File ignores DEP , File ignores Code Integrity , Debug timestamp (05/15/2018 13:36:14) mismatches compiler timestamp (05/15/2009 13:36:15) , Checksum mismatches the PE header value , Contains unknown resources ) , Queries process information , Scanning for process managers ( “ProgMan” ) , Contains native function calls ( NtdllDefWindowProc_W[at]NTDLL.DLL ) , Contains ability to query CPU information , Has the capability to lower Firefox security settings , Tries to identify its external IP address , Checks if a debugger is present , Tries to delay the analysis , Reads the active computer name , Reads the registry for installed applications , Scanning for window names , Creates guarded memory sections , Disables SPDY-connections , Installs system wide “WH_KEYBOARD_LL” hook , Creates windows services ( “nslookup.exe”) > Access type: “CREATE”; Path: “HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS”) , Injects into explorer , Modifies the Memory of >>> “c:\windows\system32\control.exe” , “c:\windows\explorer.exe” , “c:\windows\system32\rundll32.exe” , “c:\windows\system32\runtimebroker.exe” , Modifies control flow of injected processes , Process launched with changed environment ( “explorer.exe” , rundll32.exe", “cmd.exe”, “nslookup.exe” ) , Queries sensitive IE security settings , Modifies proxy settings , Found possibly malicious network releated activity >>> Contacts a external IP address lookup service ( (Indicator: “myip.opendns.com”, "“resolver1.opendns.com” ; File: “nslookup.exe”) , Contacts Random Domain Names ( “x84v184asdwq.net” ) , File contacts Host ( “188.241.68.116” > VirusTotal )

Thank you pio,

883b9a573b62ff7a82b96ffd96e859f1a592dd09 has been reviewed and marked as Malware.