Managed XDR

payload — malware analysis report

File info

Filename
payload
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
5.4 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
c5f7a22dce32095350c8cd182715b32a291b611a
SHA256
ba3b1dc89732232505fc21e8a6d994b3992964853aac5f1090672f05b9653316
MD5
965fb147d58512756ef2970696dcb575

Signatures

Execution

T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1480 system_default_lang_id_present: Checks the system language
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552 infostealer_browser: Retrieves personal information from local Internet browsers
T1503 infostealer_browser: Retrieves personal information from local Internet browsers
T1552 infostealer_im: Collects information about installed messengers
T1552 infostealer_ftp: Collects data from local FTP clients
T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1057 has_wmi: Executes one or several WMI requests
T1057 process_interest: Enumerates processes
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1082 reads_csrss: Attempts to read csrss.exe memory

Other

yara_rules: Static rules
dead_host: Connects to IP addresses that do not respond to requests
no_graphical_activity: No graphic activity
suspicious_network_port: Performs TCP or UDP request to non-standard port
open_winlogon_process: Trying to open winlogon process