Managed XDR

da8f0416ae373e9267a45827307dbfab.virus (Conti) — malware analysis report

File info

Filename
da8f0416ae373e9267a45827307dbfab.virus
File type
PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed
File size
734 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
5c49d3e4f86393cb9a5a3af3c84593eb0865402c
SHA256
da3e397c34105d561b22e83fe2b90e443737f1c7a39fa63aa39e72220342ab32
MD5
da8f0416ae373e9267a45827307dbfab

Malwares

  • Conti

Signatures

Execution

T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1070 yara_rules: Static rules
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1027.002 packer_upx: The executable file is compressed using UPX
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1057 has_wmi: Executes one or several WMI requests
T1082 has_wmi: Executes one or several WMI requests
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

network_bind: Starts servers listening at None
creates_suspended_process: Creates suspended process
creates_in_programdata: Creates files in the ProgramData directory
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services

Related reports