Managed XDR

exemplar (Ramnit) — malware analysis report

File info

Filename
exemplar
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
188 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
187bce876f1d2d2af94c5479490cf467a64081f3
SHA256
7aed7934423548dbc5fff5e5ffa9b6b8b020e44dbbd8bac8db6f1709399a4b77
MD5
05679259402f6f347a4960fc62a6f1f0

Malwares

  • Ramnit

Signatures

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1547.004 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1547.004 persistence_autorun: Makes itself run automatically on Windows startup
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1562.004 bypass_firewall: Changes local firewall configuration and policies
T1562.001 disables_security: Disables Windows Security options
T1564.001 stealth_file: Creates hidden or system files
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1562 modify_security_center_warnings: Attempts to modify or disable Security Center notifications
T1562 disables_uac: Disable UAC
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Discovery

T1518.001 antiav_detectservice: Attempts to detect installed antiviruses by a certain service
T1057 process_interest: Enumerates processes
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Impact

T1489 stops_service: Stops Windows services
T1489 change_service_config: Stops services via ChangeServiceConfig
T1489 service_control_stop: Stops services via ControlService

Other

yara_rules: Static rules
ramnit_alt: Ramnit banking trojan indicators detected
copies_self: Creates a copy of itself
creates_exe: Creates executable files in the file system
static_pe_duplicate_sections: The PE file structure contains anomalies: duplicate section names
no_graphical_activity: No graphic activity
get_policy_info: Retrieves information about a Policy object

Related reports

Managed XDR