Managed XDR

smnss.exe (Mydoom, DNS Sinkhole) — malware analysis report

File info

Filename
smnss.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
119.1 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d265732f591e8ef2d76896834a33f7457b3252ea
SHA256
313a6bfd2ce4e501c164d7bcb7f4d5d16cef7816140052a62ce4741b9708228d
MD5
dd57e2ea4b03d5052d138cddf1ce1015

Malwares

  • Mydoom
  • DNS Sinkhole

Signatures

Resource Development

T1585.001 social_facebook: Connects to Facebook domains (potentially for information gathering)
T1586.001 social_facebook: Connects to Facebook domains (potentially for information gathering)

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_generic_scsi: Attempts to detect virtualization by SCSI Disk Identifier
T1027.002 packer_polymorphic: Creates a modified copy of itself
T1564.001 stealth_file: Creates hidden or system files
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497.001 antivm_generic_scsi: Attempts to detect virtualization by SCSI Disk Identifier
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1518 locates_browser: Attempts to identify where browsers are installed

Command and Control

T1071.003 network_smtp: Sends emails, possibly SPAM
T1568.002 dga_domains: Connects to DGA domains
T1071.001 network_http: Performs HTTP requests

Other

yara_rules: Static rules
suricata_alert: Malicious traffic detected
executes_dropped_exe: Executes dropped exe files
creates_in_windows: Creates files in the Windows directory
copies_self: Creates a copy of itself
network_bind: Starts servers listening at 0.0.0.0:3159
creates_exe: Creates executable files in the file system
dns_without_resolve: DNS query without a response
network_ftp: Performs FTP requests
access_recyclebin: Manipulation with recyclebin detected
get_policy_info: Retrieves information about a Policy object
pe_overlay: PE file contains overlay

Related reports