Managed XDR

home-petik-ptktriage-8...28683d2e315cd05fbc05b2 — malware analysis report

File info

Filename
home-petik-ptktriage-8b56d75369b933d12b1468863c0fd035a36e0781c928683d2e315cd05fbc05b2
File type
RAR archive data, v5
File size
1.6 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
81bb9cbf8d3bd5827868d4a85041ac74d11dc8af
SHA256
8b56d75369b933d12b1468863c0fd035a36e0781c928683d2e315cd05fbc05b2
MD5
18f5e8a2942ceb42136470a8b07e60d2

Signatures

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.001 antivm_network_adapters: Checks NIC addresses
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_network_adapters: Checks NIC addresses
T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1102.003 cloud_github: Connects to cloud services of Github (potentially for malicious payload delivery)

Other

yara_rules: Static rules
dotnet_suspicious_resources_names: Dotnet program has suspicious resources names
create_rpc_bindings: Creates RPC connection
dotnet_embeded_dependencies_by_costura: Dotnet program has embedded dependencies by Costura
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
dotnet_downloader_possible_network_problem: Dotnet program possibly has network problem
many_files_in_archive: The archive contains more than 5 files