Managed XDR

skid.exe (Dharma) — malware analysis report

File info

Filename
skid.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
5.7 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
40809444e06c6e226ca22eddff26daf046b56100
SHA256
4981b9a7d6c5092844421671b53200b6e2e97ca342d56f1d14c0b3f69c2b8f3b
MD5
431e1d5bb24fff8e8a60af4a557ce857

Malwares

  • Dharma

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.003 suspicious_cmd_process: Cmd.exe without commandline launches a new process
T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1070.004 deletes_self: Moves to different location or removes the original executable file
T1564.001 stealth_file: Creates hidden or system files
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497.001 antivm_sandboxie: Attempts to detect Sandboxie
T1070 stealth_webhistory: Clears browsing history
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1497.001 antivm_network_adapters: Checks NIC addresses
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1497.001 antivm_queries_computername: Retrieves the computer name
T1070 stealth_window: A process created a hidden window

Credential Access

T1552 infostealer_mail: Collects personal data from local email clients
T1552 infostealer_browser: Retrieves personal information from local Internet browsers
T1552.001 infostealer_bitcoin: Attempts to obtain access to Bitcoin/ALTCoin wallets
T1503 infostealer_browser: Retrieves personal information from local Internet browsers
T1555.003 cookie_files: Accesses cookie files
T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager
T1552 cookie_files: Accesses cookie files

Discovery

T1497.001 antivm_sandboxie: Attempts to detect Sandboxie
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1057 process_interest: Enumerates processes
T1083 crawls_directories: Opens a huge number of directories all over disk C: (possibly, searches for sensitive data)
T1082 has_wmi: Executes one or several WMI requests
T1497.001 antivm_network_adapters: Checks NIC addresses
T1518 locates_browser: Attempts to identify where browsers are installed
T1497.001 antivm_queries_computername: Retrieves the computer name

Collection

T1114 infostealer_mail: Collects personal data from local email clients
T1074.001 access_recyclebin: Manipulation with recyclebin detected

Command and Control

T1071.001 network_cnc_http: Suspicious HTTP traffic
T1071.001 network_http: Performs HTTP requests

Exfiltration

T1022 encrypts_pc_info: Collects and encrypts information about the computer (possibly for exfiltration)

Impact

T1486 modifies_files: Cryptolocker indicators detected (renamed 500 or more files)
T1486 modifies_files2: Cryptolocker indicators detected (100 or more files are modified)
T1490 vssadmin_delete_shadows: Attempt to delete volume shadow copies
T1561 wiper_zeroed_bytes: Overwrites multiple files with zero bytes (hex 00)
T1486 ransomware_files_2: Ransomware(s) Roger indicators detected (creates keys and the instruction on how to unlock the files)
T1565.001 overwrites_firefox_settings: Modifies Mozilla Firefox settings
T1485 deletes_files: Removes 500 or more files from C: drive

Other

yara_rules: Static rules
ransomware_dharma: Detected Dharma ransomware
executes_dropped_exe: Executes dropped exe files
ransomware_shadowcopy: Removes volume shadow copies
creates_exe: Creates executable files in the file system
creates_in_windows: Creates files in the Windows directory
runs_utility_without_cmdline: Runs system utility without arguments (non-typical usage)
ip_domains: Identifies an IP address using external resources
create_process_failed: Could not start the process
process_crashed: One of the processes has failed
unexpected_exception: Unexpected exception
create_rpc_bindings: Creates RPC connection
require_administrator: Requests administrator privileges
creates_suspended_process: Creates suspended process
message_box: Displays a message
get_policy_info: Retrieves information about a Policy object
creates_in_programdata: Creates files in the ProgramData directory
test_check_service: Starts services
writes_data: Writes big amount of data to disk
suricata_alert: Malicious traffic detected

Related reports