Managed XDR

ca966f7feeb280f8cca15b9c5f34218f.virus — malware analysis report

File info

Filename
ca966f7feeb280f8cca15b9c5f34218f.virus
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
717.7 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d048d138620e0502d94f9bf011b118abb5fa7e17
SHA256
220add4acbeaa882743e6e7c48edfe793f167b43f8a10d44223034c93ec62a65
MD5
ca966f7feeb280f8cca15b9c5f34218f

Signatures

Persistence

T1547 persistence_autorun: Makes itself run automatically on Windows startup
T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1543.003 creates_service: Creates a service, that will start automatically

Privilege Escalation

T1547 persistence_autorun: Makes itself run automatically on Windows startup
T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1543.003 creates_service: Creates a service, that will start automatically
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_polymorphic: Creates a modified copy of itself
T1497.002 antisandbox_foregroundwindows: Checks whether any human activity is being performed by constantly checking whether the foreground window has changed
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1036 system_filename: Created a file named as a common system file
T1036 system_procname: Created a process named as a common system process
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1027.002 packer_aspack: Executable file is packed with ASPack
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.002 antisandbox_foregroundwindows: Checks whether any human activity is being performed by constantly checking whether the foreground window has changed
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1010 checks_window_classname: Waits for a particular window to become active
T1057 process_interest: Enumerates processes
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
static_pe_anomaly: The PE file structure contains anomalies
creates_in_windows: Creates files in the Windows directory
suspicious_process: Spawns a suspicious process
executes_dropped_exe: Executes dropped exe files
static_pe_duplicate_sections: The PE file structure contains anomalies: duplicate section names
no_graphical_activity: No graphic activity
pe_overlay: PE file contains overlay