Managed XDR

uc-export-download-con...6waydqojgyasglzs5t.url — malware analysis report

File info

Filename
uc-export-download-confirm-no_antivirus-id-1woppudrwndnekm6waydqojgyasglzs5t.url
File type
MS Windows 95 Internet shortcut text (URL=<https://drive.google.com/uc?export=download&confirm=no_antivirus&id=1woPPuDRwNDneKM6wAYDQOJgYas>), ASCII text
File size
124 Bytes
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
d277df321268bd7fee03b60bee45b60f418229fa
SHA256
b5e14206b287e8c3b6b01f0dbdc349d1729a29200df0e65441f4137a75aa01d4
MD5
321956fad0e55f946b8448e7d1c164b9

Signatures

Resource Development

T1585.001 social_telegram: Connects to Telegram (potentially for information gathering)
T1586.001 social_telegram: Connects to Telegram (potentially for information gathering)

Execution

T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1070.004 deletes_self: Moves to different location or removes the original executable file
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497.001 antivm_generic_cpu: Checks the CPU name, possibly for anti-virtualization
T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1070 stealth_window: A process created a hidden window
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.001 antivm_queries_computername: Retrieves the computer name
T1070.004 self_removal_command: Executes command to delete itself
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552 infostealer_ftp: Collects data from local FTP clients
T1552.001 infostealer_winscp: Collects information from configuration file of WinSCP

Discovery

T1497.001 antivm_generic_cpu: Checks the CPU name, possibly for anti-virtualization
T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1082 has_wmi: Executes one or several WMI requests
T1057 process_interest: Enumerates processes
T1518 recon_programs: Collects information about installed programs
T1518 locates_browser: Attempts to identify where browsers are installed
T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1071 internet_security_options: Sets Internet connections options that are not secure
T1032 internet_security_options: Sets Internet connections options that are not secure
T1102.003 references_google: Contains links to cloud services of Google (potentially for malicious payload delivery)
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

static_pe_anomaly: The PE file structure contains anomalies
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
static_compression_ratio: Very high compression ratio of a file
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay
susp_callbacks: Suspicious usage of some WinAPI with callbacks
suricata_alert: Malicious traffic detected
valid_authenticode: The digital signature has been verified