Managed XDR

ea80a751f404a082a2f2b29913848f08.virus — malware analysis report

File info

Filename
ea80a751f404a082a2f2b29913848f08.virus
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed, PECompact2 compressed
File size
1.2 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
dd529e9e81d65bd3d8fe50d633792076216b36e5
SHA256
ccc751c625a5dcd090b96820dc85aab27944bf1cec158585adaac65f88bec791
MD5
ea80a751f404a082a2f2b29913848f08

Signatures

Execution

T1204.002 mimics_extension: Attempts to mimic the file extension

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_generic_services: Enumerates services, possibly for anti-virtualization
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 packer_upx: The executable file is compressed using UPX
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1036 mimics_extension: Attempts to mimic the file extension

Credential Access

T1552 infostealer_browser: Retrieves personal information from local Internet browsers
T1503 infostealer_browser: Retrieves personal information from local Internet browsers
T1552 infostealer_mail: Collects personal data from local email clients
T1552 cookie_files: Accesses cookie files
T1555.003 cookie_files: Accesses cookie files
T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497.001 antivm_generic_services: Enumerates services, possibly for anti-virtualization
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1083 crawls_directories: Opens a huge number of directories all over disk C: (possibly, searches for sensitive data)
T1057 process_interest: Enumerates processes
T1518 locates_browser: Attempts to identify where browsers are installed
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.001 antivm_queries_computername: Retrieves the computer name

Collection

T1114 infostealer_mail: Collects personal data from local email clients

Command and Control

T1095 network_icmp: Creates ICMP traffic

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
winsxsbot: WinSxsBot/Sfone Worm indicators detected
creates_in_windows: Creates files in the Windows directory
dns_without_resolve: DNS query without a response
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
break_limit_exceeded: Warning: function calls limit has been exceeded
access_recyclebin: Manipulation with recyclebin detected
get_policy_info: Retrieves information about a Policy object
creates_in_programdata: Creates files in the ProgramData directory
writes_data: Writes big amount of data to disk
pe_overlay: PE file contains overlay