Managed XDR

autoupdate-hostfile_newup-autologin.rar — malware analysis report

File info

Filename
autoupdate-hostfile_newup-autologin.rar
File type
RAR archive data, v5
File size
2.3 MB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
00eb0a91f78c01e6f7c32287fb6feab2600ea91a
SHA256
622195761bbb2fb50e90ed7942cbfe2d87e1d03b724e78d2018b87ea2c243705
MD5
d91c4bcfd15a61edd21d814c05e7b0fb

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 antidbg_windows: Checks for open windows typical for debuggers and forensic tools
T1497 antidbg_setinformationthread: Attempts to evade debugger using NtSetInformationThread
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497 antidbg_query_system: Checks for kernel debugger (SystemKernelDebuggerInformation)
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 antidbg_windows: Checks for open windows typical for debuggers and forensic tools
T1497 antidbg_setinformationthread: Attempts to evade debugger using NtSetInformationThread
T1518.001 antidbg_devices: Checks for devices typical for debuggers and forensic tools
T1497 antidbg_query_system: Checks for kernel debugger (SystemKernelDebuggerInformation)
T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1071.001 wininet_openurl: Performs HTTP/HTTPS-requests using InternetOpenUrl

Other

unexpected_exception: Unexpected exception
static_pe_duplicate_sections: The PE file structure contains anomalies: duplicate section names
no_graphical_activity: No graphic activity
message_box: Displays a message
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
suricata_alert: Malicious traffic detected