Managed XDR

a49cdd7c3e9a0582564915637e02696e.virus (Conti) — malware analysis report

File info

Filename
a49cdd7c3e9a0582564915637e02696e.virus
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
210.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
291f6815517cfd93488ba3d50f5d0791e6454920
SHA256
9e0eab0b9ce79adfa095505d2eaaff3fb6eec03e435a87f490b403b46caf0acb
MD5
a49cdd7c3e9a0582564915637e02696e

Malwares

  • Conti

Signatures

Execution

T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552 cookie_files: Accesses cookie files
T1555.003 cookie_files: Accesses cookie files

Discovery

T1057 process_interest: Enumerates processes
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Impact

T1490 vssadmin_delete_shadows: Attempt to delete volume shadow copies

Other

yara_rules: Static rules
ransomware_shadowcopy: Removes volume shadow copies
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
test_check_service: Starts services

Related reports