Managed XDR

readme.exe (Mydoom, DNS Sinkhole) — malware analysis report

File info

Filename
readme.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
2.3 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
b91ffd7beeff33c45feaee484188f27210c7e442
SHA256
208637add87e59556a376e2b0424f5a89cc3d7da85d3ef3543ebfd0d3fed5ecf
MD5
4d20c606064a23fcba2e959816659b55

Malwares

  • Mydoom
  • DNS Sinkhole

Signatures

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1564.001 stealth_file: Creates hidden or system files
T1027.002 packer_polymorphic: Creates a modified copy of itself
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497.001 antivm_generic_scsi: Attempts to detect virtualization by SCSI Disk Identifier
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1027.002 packer_enigma: Enigma protector indicators detected
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1497.001 antivm_queries_computername: Retrieves the computer name

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497.001 antivm_generic_scsi: Attempts to detect virtualization by SCSI Disk Identifier
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1518 locates_browser: Attempts to identify where browsers are installed
T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1568.002 dga_domains: Connects to DGA domains
T1071.003 network_smtp: Sends emails, possibly SPAM
T1071.001 network_http: Performs HTTP requests

Other

yara_rules: Static rules
suricata_alert: Malicious traffic detected
executes_dropped_exe: Executes dropped exe files
creates_in_windows: Creates files in the Windows directory
copies_self: Creates a copy of itself
network_bind: Starts servers listening at 0.0.0.0:3159
creates_exe: Creates executable files in the file system
dns_without_resolve: DNS query without a response
dead_host: Connects to IP addresses that do not respond to requests
network_ftp: Performs FTP requests
static_pe_duplicate_sections: The PE file structure contains anomalies: duplicate section names
no_graphical_activity: No graphic activity
access_recyclebin: Manipulation with recyclebin detected
get_policy_info: Retrieves information about a Policy object
pe_overlay: PE file contains overlay

Related reports