Managed XDR

cryptor.exe — malware analysis report

File info

Filename
cryptor.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
147.5 KB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
bbf868c00f89586ab58fc7545c9f02a553ed2aae
SHA256
a08b8b29517d85940d805bdb96d0e7c6ab4cb8547885f055db280447cf6b2efb
MD5
35dc9cd1b3229247e203982105f626d6

Signatures

Execution

T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1057 process_interest: Enumerates processes
T1016 get_hostname: Attempts to get hostname

Impact

T1490 vssadmin_delete_shadows: Attempt to delete volume shadow copies

Other

yara_rules: Static rules
ransomware_shadowcopy: Removes volume shadow copies
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
test_check_service: Starts services