Managed XDR

fmln_ransomware-main.zip — malware analysis report

File info

Filename
fmln_ransomware-main.zip
File type
Zip archive data, at least v1.0 to extract
File size
187.1 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
47ad5c71c759053efa1ba304543427f836c894da
SHA256
2e488d3612544dacd4c14725e1fd7dd7474c790020c8ce0ca4852943513d1853
MD5
8dbd16fe84c56aefa0dc7bfb73d75337

Signatures

Execution

T1059.003 suspicious_process: Spawns a suspicious process
T1059.003 executes_dropped_cmd: Executes dropped batch files
T1059.005 obfuscated_vbs: Detected obfuscated VBS
T1059 wscript_info_discovery: Collects info about system with Wscript.Shell

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1564.001 stealth_file: Creates hidden or system files
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1140 unpacking_utilities: Uses Windows utilities to unpack data
T1027 obfuscated_vbs: Detected obfuscated VBS
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1480 system_default_lang_id_present: Checks the system language

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1518 locates_browser: Attempts to identify where browsers are installed
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1033 wscript_info_discovery: Collects info about system with Wscript.Shell

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
creates_in_windows: Creates files in the Windows directory
cryptolocker_wallpaper: Ransomware indicators detected (changes the desktop wallpaper file)
http_file_not_found: Attempts to download EXE or DLL file but receives HTML with an error
require_administrator: Requests administrator privileges
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call