Managed XDR

iris.exe — malware analysis report

File info

Filename
iris.exe
File type
PE32+ executable (GUI) x86-64, for MS Windows
File size
288 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
05c21f5181769a08d0ecfcccf7c8ab6a41f659c9
SHA256
a1eec4dd34764f48a7272b6cdc8403a0d23549c3fb66f6c4a7379ca8432ed032
MD5
e1abe0b17c581eb72dc534d5c9582123

Signatures

Execution

T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1047 has_wmi: Executes one or several WMI requests
T1059.001 powershell_through_runspace: Executes PowerShell script without spawning powershell.exe process
T1047 antivm_wmi: Uses WMI to detect virtual environment

Persistence

T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1547.004 persistence_autorun: Makes itself run automatically on Windows startup
T1547 persistence_bootexecute: Installs a native application to be launched at Windows startup

Privilege Escalation

T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1547.004 persistence_autorun: Makes itself run automatically on Windows startup
T1547 persistence_bootexecute: Installs a native application to be launched at Windows startup
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1562 firewall_disable: Disables Firewall
T1497 evasion_winlogon: Attempts to detect Sandbox by winlogon sessions
T1497 evasion_sru: Attempts to detect Sandbox by process activity difference
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1070 stealth_window: A process created a hidden window
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552.002 opens_registry_hive_file: Attempts to open Windows registry hive file
T1003.002 opens_registry_hive_file: Attempts to open Windows registry hive file

Discovery

T1082 has_wmi: Executes one or several WMI requests
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1057 process_interest: Enumerates processes
T1082 uses_windows_utilities: Uses Windows utilities for basic Windows functionality
T1518 locates_browser: Attempts to identify where browsers are installed
T1497 evasion_winlogon: Attempts to detect Sandbox by winlogon sessions
T1497 evasion_sru: Attempts to detect Sandbox by process activity difference
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization

Impact

T1565 modifies_hostfile: Writes data to system hosts file
T1486 modifies_files2: Cryptolocker indicators detected (500 or more files are modified)
T1490 vssadmin_delete_shadows: Attempt to delete volume shadow copies
T1485 deletes_files: Removes 500 or more files from C: drive
T1490 wbadmin_delete_backup: Removes system backup copies using wbadmin utility

Other

ransomware_shadowcopy: Removes volume shadow copies
ransomware_bcdedit: Runs bcdedit commands specific to ransomware
creates_in_windows: Creates files in the Windows directory
copies_self: Creates a copy of itself
bitcoin_opencl: Installs the OpenCL library, possibly to mine bitcoins
creates_exe: Creates executable files in the file system
create_process_failed: Could not start the process
has_pdb: This executable file has a PDB path
creates_suspended_process: Creates suspended process
test_check_service: Starts services
writes_data: Writes big amount of data to disk
yara_rules: Static rules