Managed XDR

drive-download-20241009t170701z-001.zip — malware analysis report

File info

Filename
drive-download-20241009t170701z-001.zip
File type
Zip archive data, at least v2.0 to extract
File size
8 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
18424c170a6b89a1431e0caba4411f1eec7b801a
SHA256
1c498c733bf536da0333f346e02aea4a6186b8860fdc0dce998307e1a2e839bf
MD5
71fc2a393d56a15275bada5b8a40e816

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1047 has_wmi: Executes one or several WMI requests
T1059.001 suspicious_process: Spawns a suspicious process
T1106 susp_callbacks: Suspicious usage of some WinAPI with callbacks

Persistence

T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key

Privilege Escalation

T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1574.011 persistence_services: Modifies Services registry key
T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1562.004 firewall_add_rule: Modifies Firewall rules
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1480 system_default_lang_id_present: Checks the system language
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Discovery

T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1082 uses_windows_utilities: Uses Windows utilities for basic Windows functionality
T1518 locates_browser: Attempts to identify where browsers are installed
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1135 server_share_info: Retrieves information about each shared resource on a server

Command and Control

T1095 network_icmp: Creates ICMP traffic

Other

network_bind: Starts servers listening at 0.0.0.0:49157, 0.0.0.0:49153
codepage: Checks the system code page
unexpected_exception: Unexpected exception
create_rpc_bindings: Creates RPC connection
has_pdb: This executable file has a PDB path
break_limit_exceeded: Warning: function calls limit has been exceeded
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay
suricata_alert: Malicious traffic detected
many_files_in_archive: The archive contains more than 5 files