Managed XDR

vpncheck-pro.exe (Orcus RAT) — malware analysis report

File info

Filename
vpncheck-pro.exe
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size
958.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
58757e953c3e3c022317ad07cd6928e7592d7ae8
SHA256
58afd2b6eb6eb7fa2e11d7c782c1663ae965d8b66eb043639d6d45f5105c574d
MD5
38880f7cf62dc447e52b0ea684931ec1

Malwares

  • Orcus RAT

Signatures

Execution

T1569.002 persistence_service: Starts newly created service

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1543.003 creates_service: Creates a service, that will start automatically

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1543.003 creates_service: Creates a service, that will start automatically
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1070.004 deletes_self: Moves to different location or removes the original executable file
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1564.001 stealth_file: Creates hidden or system files
T1564.004 removes_zoneid_ads: Attempts to hide the indications that the file was downloaded from the Internet
T1497.001 antivm_generic_services: Enumerates services, possibly for anti-virtualization
T1096 persistence_ads: Creates Alternate Data Stream (ADS)
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.004 compiles_code: Compiles C# code
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Credential Access

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Discovery

T1497.001 antivm_generic_services: Enumerates services, possibly for anti-virtualization
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Collection

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Other

yara_rules: Static rules
orcus_rat_behavior: Exhibits behavior characteristics of Orcus RAT
executes_dropped_exe: Executes dropped exe files
creates_exe: Creates executable files in the file system
caon_rat_behavior: Exhibits behavior characteristics of BoxCaon RAT
critical_process: Makes the process critical to the system (the system shuts down when it's terminated)
creates_in_windows: Creates files in the Windows directory
event_hook: Hooks Windows events associated with UI
dead_host: Connects to IP addresses that do not respond to requests
no_graphical_activity: No graphic activity
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
message_box: Displays a message
get_policy_info: Retrieves information about a Policy object
changes_ext_type: File extension changed from executable to non-executable or vice versa
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
dotnet_suspicious_module_name: Dotnet program has suspicious module name

Related reports