Managed XDR

kjh_x.exe — malware analysis report

File info

Filename
kjh_x.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
File size
42.9 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
91de3a254d37fab9f819069cac5dded5dadb2b66
SHA256
65ba32fd1ab16d8014de2e3e695c1c164b9f9781ba3f4939f429c8bc288bbf05
MD5
abb3454e3fb016c84ebc858f0f279bf0

Signatures

Execution

T1047 has_wmi: Executes one or several WMI requests

Persistence

T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1562.001 disables_security: Disables Windows Security options
T1562.001 stops_security_center: Stops Security Center
T1562.001 disables_windowsupdate: Disables Windows Auto Updates
T1574.011 persistence_services: Modifies Services registry key
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.002 nsis_archive: One of the packages is NSIS archive
T1070 stealth_window: A process created a hidden window

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1518 locates_browser: Attempts to identify where browsers are installed

Impact

T1490 vssadmin_delete_shadows: Attempt to delete volume shadow copies
T1489 stops_service: Stops Windows services
T1489 stops_security_center: Stops Security Center
T1490 wbadmin_delete_backup: Removes system backup copies using wbadmin utility
T1489 net_stop: Stops services through the use of net stop

Other

ransomware_shadowcopy: Removes volume shadow copies
ransomware_bcdedit: Runs bcdedit commands specific to ransomware
require_administrator: Requests administrator privileges
creates_exe: Creates executable files in the file system
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay
executes_dropped_exe: Executes dropped exe files
yara_rules: Static rules