Managed XDR

c-windows-installer-53e8b6.msi — malware analysis report

File info

Filename
c-windows-installer-53e8b6.msi
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Number of Characters: 0, Create Time/Date: Sun May 19 22:37:32 2024, Last Printed: Sun May 19 22:37:32 2024, Code page: 0, Title: Lockbit Test, Author: LB, Subject: LockBit, Comments: This installer database contains the logic and data required to install <product name>., Keywords: Installer, MSI, Database, Template: x64;1033, Revision Number: {7B0DEE36-6D30-4D27-9714-83E100ED1259}, Number of Pages: 500, Security: 0, Number of Words: 10, Last Saved Time/Date: Sun May 19 23:01:17 2024, Last Saved By: 123, Name of Creating Application: MSI Editor
File size
1.2 MB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
a2d1ab81fe4b168e5827fcbc45be11acfe352bf5
SHA256
d1fcb888365175ef63d2799b5d4f214f0bc516f8367f26547642a3e11f8bbc93
MD5
a3751e53be0ac536bc0e2712b547938d

Signatures

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions

Other

yara_rules: Static rules
create_rpc_bindings: Creates RPC connection
test_check_service: Starts services