Managed XDR

poc.rar (Meterpreter, Metasploit) — malware analysis report

File info

Filename
poc.rar
File type
Zip archive data, at least v2.0 to extract
File size
116.8 KB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
8353a3ebd8162f8ea1a9dbd6eb4e8d43d06a84a9
SHA256
56159fb89d458d71c635eb8f9346e06303cd149614743e49532a6cffaab726c5
MD5
820f1c728206080c65c3da62ee3190b7

Malwares

  • Meterpreter
  • Metasploit

Signatures

Execution

T1204.002 mimics_extension: Attempts to mimic the file extension

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1036 mimics_extension: Attempts to mimic the file extension
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
meterpreter: Memory region specific for Meterpreter config was found
ce_info: Meterpreter Configuration Data found
dead_host_suspicious: Connects to IP addresses with suspicious port that do not respond (possible Meterpreter)
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity

Related reports