Managed XDR

win1.exe (BlackCat) — malware analysis report

File info

Filename
win1.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
1.1 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
665687a8f410eb25f3cefa3b6533317415c5a8a3
SHA256
113787db8ad6024f3f986eb95f70d6e3634c152be006bd805fed00d0cca45ec6
MD5
6e4ed24b25751cb9812e8133ff39f16f

Malwares

  • BlackCat

Signatures

Execution

T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552.001 infostealer_bitcoin: Attempts to obtain access to Bitcoin/ALTCoin wallets
T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1083 crawls_directories: Opens a huge number of directories all over disk C: (possibly, searches for sensitive data)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1057 process_interest: Enumerates processes
T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1071.001 wininet_openurl: Performs HTTP/HTTPS-requests using InternetOpenUrl

Impact

T1486 modifies_files2: Cryptolocker indicators detected (500 or more files are modified)
T1486 modifies_files: Cryptolocker indicators detected (renamed 500 or more files)
T1490 vssadmin_delete_shadows: Attempt to delete volume shadow copies
T1486 ransomware_message: Ransomware indicators detected (possible ransom message creation)
T1489 service_control_stop: Stops services via ControlService

Other

yara_rules: Static rules
ransomware_blackcat: Detected BlackCat ransomware
modifies_certs: Attempts to generate or modify system certificates
create_rpc_bindings: Creates RPC connection
access_recyclebin: Manipulation with recyclebin detected
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
writes_data: Writes big amount of data to disk
suricata_alert: Malicious traffic detected

Related reports