Managed XDR

readme.exe (Mydoom, DNS Sinkhole) — malware analysis report

File info

Filename
readme.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
2.3 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
6224f9353124bc9cbc8e3ff4856b15e4dfaa92db
SHA256
b8f8a823bd78c4565cfdd2744abd0eb0abe414acd36cb1e6d14f58e198269450
MD5
dcba6c81abdda99c6124914aa4a05844

Malwares

  • Mydoom
  • DNS Sinkhole

Signatures

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_generic_scsi: Attempts to detect virtualization by SCSI Disk Identifier
T1027.002 packer_polymorphic: Creates a modified copy of itself
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1564.001 stealth_file: Creates hidden or system files
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 packer_enigma: Enigma protector indicators detected
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497.001 antivm_generic_scsi: Attempts to detect virtualization by SCSI Disk Identifier
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1518 locates_browser: Attempts to identify where browsers are installed
T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1071.003 network_smtp: Sends emails, possibly SPAM
T1568.002 dga_domains: Connects to DGA domains
T1071.001 network_http: Performs HTTP requests

Other

yara_rules: Static rules
suricata_alert: Malicious traffic detected
executes_dropped_exe: Executes dropped exe files
creates_in_windows: Creates files in the Windows directory
copies_self: Creates a copy of itself
network_bind: Starts servers listening at 0.0.0.0:3159
creates_exe: Creates executable files in the file system
dns_without_resolve: DNS query without a response
network_ftp: Performs FTP requests
static_pe_duplicate_sections: The PE file structure contains anomalies: duplicate section names
no_graphical_activity: No graphic activity
access_recyclebin: Manipulation with recyclebin detected
get_policy_info: Retrieves information about a Policy object
pe_overlay: PE file contains overlay

Related reports