Managed XDR

downloads-sqli-dumper-9.6.rar — malware analysis report

File info

Filename
downloads-sqli-dumper-9.6.rar
File type
RAR archive data, v5
File size
2.1 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
7b031d160f40de32c46688b1ff209e145c56ed76
SHA256
5812aad17725f872538180bc82166a8734a8138322ff68a26b8b858c08b865f1
MD5
e5f33dff3f741478bae28eb1db4c833b

Signatures

Initial Access

T1192 html_urls: HTML-document downloads a file

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1564.001 stealth_file: Creates hidden or system files
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1497.001 antivm_network_adapters: Checks NIC addresses
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.002 packer_entropy: Probably contains compressed or encrypted data

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1497.001 antivm_network_adapters: Checks NIC addresses

Command and Control

T1071.001 network_cnc_http: Suspicious HTTP traffic
T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

yara_rules: Static rules
code_share_services: Connects to text storage services (potentially for malicious payload delivery)
copies_self: Creates a copy of itself
suricata_alert: Malicious traffic detected
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
dotnet_suspicious_resources_names: Dotnet program has suspicious resources names
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
error_drawtext: An error occured while executing the file
origin_langid: Unconventional language of the executable file
dotnet_obfuscated: Dotnet program is potentially obfuscated
get_policy_info: Retrieves information about a Policy object
creates_in_programdata: Creates files in the ProgramData directory
checktokenmembership: Checks user token with CheckTokenMembership call
many_files_in_archive: The archive contains more than 5 files