Managed XDR

winprvse.exe — malware analysis report

File info

Filename
winprvse.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
28.3 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
60b1d3efb3d83a365516dad820c686d9124a80d7
SHA256
8bfb0584840c73e2ccf82cff097c4ea2bd52c90b7ab8c0faa8f945226af263a1
MD5
5fa393c376024c762015db3833473203

Signatures

Execution

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1053.005 creates_tasks: Creates a delayed task using Task Scheduler

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1562.001 disables_security: Disables Windows Security options
T1497.001 antivm_generic_bios: Checks the BIOS version, possibly for anti-virtualization
T1564.004 removes_zoneid_ads: Attempts to hide the indications that the file was downloaded from the Internet
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.001 antivm_network_adapters: Checks NIC addresses
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Discovery

T1497.001 antivm_generic_bios: Checks the BIOS version, possibly for anti-virtualization
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1497.001 antivm_network_adapters: Checks NIC addresses
T1497.001 antivm_queries_computername: Retrieves the computer name

Collection

T1115 checks_clipboard: Monitors clipboard data
T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Other

yara_rules: Static rules
networkdyndns_checkip: Connects to a Dynamic DNS domain
critical_process: Makes the process critical to the system (the system shuts down when it's terminated)
suricata_alert: Malicious traffic detected
dns_without_resolve: DNS query without a response
dead_host: Connects to IP addresses that do not respond to requests
no_graphical_activity: No graphic activity
creates_exe: Creates executable files in the file system
get_policy_info: Retrieves information about a Policy object
suspicious_network_port: Performs TCP or UDP request to non-standard port