Managed XDR

optimization-v2-20240925t222924z-001.zip — malware analysis report

File info

Filename
optimization-v2-20240925t222924z-001.zip
File type
Zip archive data, at least v2.0 to extract
File size
8 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
1be7dcc8b21ac0b77d046f52e5870ad60fd5a8a0
SHA256
cfbeb1325230a2026188120262b64fce1daf017be7c58803dc02c2af825cabf3
MD5
d6145ba3be15da2279c92790e9c454a6

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1047 has_wmi: Executes one or several WMI requests
T1059.001 suspicious_process: Spawns a suspicious process
T1106 susp_callbacks: Suspicious usage of some WinAPI with callbacks

Persistence

T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key

Privilege Escalation

T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1574.011 persistence_services: Modifies Services registry key
T1562.004 firewall_add_rule: Modifies Firewall rules
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1480 system_default_lang_id_present: Checks the system language

Discovery

T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1082 uses_windows_utilities: Uses Windows utilities for basic Windows functionality
T1518 locates_browser: Attempts to identify where browsers are installed
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1135 server_share_info: Retrieves information about each shared resource on a server

Command and Control

T1095 network_icmp: Creates ICMP traffic

Other

network_bind: Starts servers listening at 0.0.0.0:49157, 0.0.0.0:49153
codepage: Checks the system code page
unexpected_exception: Unexpected exception
create_rpc_bindings: Creates RPC connection
has_pdb: This executable file has a PDB path
break_limit_exceeded: Warning: function calls limit has been exceeded
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay
suricata_alert: Malicious traffic detected
many_files_in_archive: The archive contains more than 5 files