Managed XDR

mata_upd.cab — malware analysis report

File info

Filename
mata_upd.cab
File type
Microsoft Cabinet archive data, 4168730 bytes, 381 files
File size
4 MB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
112fbe4b959770c19bb2104d9a684b60bdf49139
SHA256
fd9e2a586d210a2ba4260244af3fd544feed5301d81b07d09048c4100df74ca3
MD5
a5f16c9b66eed3d1fcd86a457f99b6a6

Signatures

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Defense Evasion

T1574.011 persistence_services: Modifies Services registry key
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1480 system_default_lang_id_present: Checks the system language
T1027.002 packer_vb: The executable file is packed using VB

Credential Access

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Discovery

T1057 process_interest: Enumerates processes
T1082 uses_windows_utilities: Uses Windows utilities for basic Windows functionality

Collection

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Impact

T1529 shutdown_system: Shuts the system down

Other

dead_host: Connects to IP addresses that do not respond to requests
unexpected_exception: Unexpected exception
dotnet_suspicious_resources_names: Dotnet program has suspicious resources names
require_administrator: Requests administrator privileges
has_pdb: This executable file has a PDB path
creates_suspended_process: Creates suspended process
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
origin_langid: Unconventional language of the executable file
dotnet_obfuscated: Dotnet program is potentially obfuscated
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay
dotnet_mixed_assembly: Dotnet program is mixed assembly
dotnet_unmanaged_entrypoint: Dotnet program has unmanaged entrypoint
yara_rules: Static rules
dotnet_downloader_possible_network_problem: Dotnet program possibly has network problem
many_files_in_archive: The archive contains more than 5 files