Managed XDR

kmsmatrix.7.0.rar — malware analysis report

File info

Filename
kmsmatrix.7.0.rar
File type
RAR archive data, v5
File size
10.8 MB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
05105d0e825a6554dfb3aa6b4470dc155295ff72
SHA256
5feaf6fb2c5af380f39a6addfdcb6021b7c8ceae8fa0215b47275a9fd837bc63
MD5
1128048b2358fe5f39cfbbec95e68c56

Signatures

Execution

T1059.003 suspicious_batch: Suspicious batch
T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1070 stealth_window: A process created a hidden window
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1082 uses_windows_utilities: Uses Windows utilities for basic Windows functionality
T1082 reads_csrss: Attempts to read csrss.exe memory

Other

static_pe_anomaly: The PE file structure contains anomalies
creates_exe: Creates executable files in the file system
creates_doc: Creates (office) documents in the file system
only_exec_in_archive: The archive contains only an executable file
no_graphical_activity: No graphic activity
require_administrator: Requests administrator privileges
message_box: Displays a message
get_policy_info: Retrieves information about a Policy object
yara_rules: Static rules