Managed XDR

arszvpk3ptivquvqhwx.exe (TrickBot) — malware analysis report

File info

Filename
arszvpk3ptivquvqhwx.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
335.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
b4e6598ab7f749c80750e4a007d5df709642b197
SHA256
db6ae0497c5ead86169508f5540545d4b048ab4a8d477a84205a14567182e92e
MD5
dba88eedcae2f45701aa13312af189ed

Malwares

  • TrickBot

Signatures

Execution

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process

Persistence

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key

Privilege Escalation

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1562.001 disables_security: Disables Windows Security options
T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1574.011 persistence_services: Modifies Services registry key
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1497 antidbg_strings: Checks for malware analysis tools (specific strings found)
T1497.001 antivm_queries_computername: Retrieves the computer name

Discovery

T1518.001 antiav_detectservice: Attempts to detect installed antiviruses by a certain service
T1057 process_interest: Enumerates processes
T1518 locates_browser: Attempts to identify where browsers are installed
T1497 antidbg_strings: Checks for malware analysis tools (specific strings found)
T1497.001 antivm_queries_computername: Retrieves the computer name
T1049 list_ts_rdp_sessions: Lists ts/rdp sessions

Impact

T1489 stops_service: Stops Windows services
T1489 net_stop: Stops services through the use of net stop

Other

yara_rules: Static rules
ce_info: Trickbot Configuration Data found
trickbot: TrickBot banking Trojan indicators detected
copies_self: Creates a copy of itself
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
unnamed_region_exception_handler: Creates an exception handler in an unnamed region
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
creates_in_programdata: Creates files in the ProgramData directory
test_check_service: Starts services

Related reports