Managed XDR

026.docx (Petya) — malware analysis report

File info

Filename
026.docx
File type
Zip archive data, at least v2.0 to extract
File size
421.9 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
f17c15580125b28dc7f31201c13df9631c64c711
SHA256
934e375ae7125c64fcc8c95a89e50e4c6e7ed1b01ced6d9ad8b682c18ef9307c
MD5
034f7064b68049f1bfad876ee49a8431

Malwares

  • Petya

Signatures

Execution

T1204.002 office_com_load: Microsoft Office loads COM DLL files (indicator of COM usage in macros)

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed

Defense Evasion

T1497.001 antivm_generic_disk: Checks information on disk, possibly for anti-virtualization or checking privileges
T1006 direct_disc_access: Direct disk access has been detected
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1497.002 antivm_usbstor: Reads information about usbdevices from regkey
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497.001 antivm_generic_disk: Checks information on disk, possibly for anti-virtualization or checking privileges
T1082 antivm_generic_disk: Checks information on disk, possibly for anti-virtualization or checking privileges
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1497.002 antivm_usbstor: Reads information about usbdevices from regkey

Impact

T1529 nt_raise_hard_error: Detected aggressive BSOD (typical for malware) using NtRaiseHardError

Other

ransomware_petya: Petya ransomware detected
office_embedded: Office document contains embedded executable file(s)
require_administrator: Requests administrator privileges
test_check_service: Starts services
office_links: Office file contains external links

Related reports