Managed XDR

price-list-tour-list-hot-reviews.zip — malware analysis report

File info

Filename
price-list-tour-list-hot-reviews.zip
File type
Zip archive data, at least v1.0 to extract
File size
30.1 MB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
b968a7c07e97b91965cf588ed446393d56fac75e
SHA256
7ebc4e30d3f2a4120a131d1aefa74abfe61396dd0fcd11086e2a0759f2e91821
MD5
e7fec89bdcd676f44da235c26c9d8cdd

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 suspicious_batch: Suspicious batch
T1059.003 url_cmdline: Cmdline of process contains URL

Defense Evasion

T1218 suspicious_cmdline: Executes a suspicious command

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Command and Control

T1102.003 cloud_github: Connects to cloud services of Github (potentially for malicious payload delivery)

Other

static_pe_anomaly: The PE file structure contains anomalies
creates_exe: Creates executable files in the file system
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
pe_overlay: PE file contains overlay
suricata_alert: Malicious traffic detected
many_files_in_archive: The archive contains more than 5 files