Managed XDR

1c.predpriiatie-platez...-579823592352-2024.scr — malware analysis report

File info

Filename
1c.predpriiatie-platezhnaia-nakladnaia-no.-579823592352-2024.scr
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
1.1 MB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
fe14ad041a9f35c3e3ef45627d0087f9d0dd4a3c
SHA256
d20db240d5c3fef6779643c52ec8e1cf35026bee6dc196032810788c4ee53b50
MD5
8356933246962e0278b0cb3768172c42

Signatures

Execution

T1059 autoit: AutoIt script execution detected
T1059.003 executes_dropped_cmd: Executes dropped batch files

Persistence

T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key

Privilege Escalation

T1068 integrity_level: Process privileges have been escalated
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1562.001 disables_security: Disables Windows Security options
T1564.001 stealth_file: Creates hidden or system files
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1574.011 persistence_services: Modifies Services registry key
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1070 stealth_window: A process created a hidden window

Credential Access

T1503 infostealer_browser: Retrieves personal information from local Internet browsers
T1552 infostealer_browser: Retrieves personal information from local Internet browsers
T1552 infostealer_im: Collects information about installed messengers
T1552 infostealer_mail: Collects personal data from local email clients
T1552 cookie_files: Accesses cookie files
T1555.003 cookie_files: Accesses cookie files
T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1033 recon_beacon: The process has sent information about the computer over the network
T1518.001 antiav_detectservice: Attempts to detect installed antiviruses by a certain service
T1083 crawls_directories: Opens a huge number of directories all over disk C: (possibly, searches for sensitive data)
T1518 locates_browser: Attempts to identify where browsers are installed
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1082 fingerprint_to_file: Collects data about system and user and writes it to a text file

Collection

T1114 infostealer_mail: Collects personal data from local email clients
T1560.001 archive_via_utility: Detected archiving data via utility

Command and Control

T1071.001 recon_beacon: The process has sent information about the computer over the network
T1071.003 network_smtp: Sends emails, possibly SPAM

Impact

T1489 change_service_config: Stops services via ChangeServiceConfig

Other

creates_in_windows: Creates files in the Windows directory
opens_document: Opens office documents
creates_exe: Creates executable files in the file system
creates_doc: Creates (office) documents in the file system
executes_dropped_exe: Executes dropped exe files
network_ftp: Performs FTP requests
create_rpc_bindings: Creates RPC connection
require_administrator: Requests administrator privileges
creates_suspended_process: Creates suspended process
access_recyclebin: Manipulation with recyclebin detected
get_policy_info: Retrieves information about a Policy object
creates_in_programdata: Creates files in the ProgramData directory
test_check_service: Starts services
pe_overlay: PE file contains overlay
yara_rules: Static rules