Managed XDR

stub.exe — malware analysis report

File info

Filename
stub.exe
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size
644.5 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
6b2fc5940e56961d80d69dd4759f05d50d055925
SHA256
83e3af6015b8e42a5076a588cda732db422571dd67d47f2a50724b21a613ea41
MD5
18e05cd57814b57defa4a727281da430

Signatures

Execution

T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1547.004 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1547.004 persistence_autorun: Makes itself run automatically on Windows startup
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_generic_bios: Checks the BIOS version, possibly for anti-virtualization
T1497.001 antivm_vmware_files: Detects VMware through the presence of specific files
T1497.001 antivm_vbox_keys: Detects VirtualBox through the presence of a registry key
T1497.001 antivm_vbox_files: Detects VirtualBox through the presence of a file
T1497.001 antivm_vmware_keys: Detects VMware through the presence of a registry key
T1497.001 antivm_generic_scsi: Attempts to detect virtualization by SCSI Disk Identifier
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497 antidbg_query_process: Checks if the process is being debugged (ProcessDebugPort)
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497 evasion_runmru: Attempts to detect Sandbox by Run MRU
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.001 antivm_generic_video: Checks information about video adapters in registry, possibly for anti-virtualization
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497.001 antivm_generic_bios: Checks the BIOS version, possibly for anti-virtualization
T1497.001 antivm_vmware_files: Detects VMware through the presence of specific files
T1497.001 antivm_vbox_keys: Detects VirtualBox through the presence of a registry key
T1497.001 antivm_vbox_files: Detects VirtualBox through the presence of a file
T1497.001 antivm_vmware_keys: Detects VMware through the presence of a registry key
T1497.001 antivm_generic_scsi: Attempts to detect virtualization by SCSI Disk Identifier
T1497 antidbg_query_process: Checks if the process is being debugged (ProcessDebugPort)
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1082 has_wmi: Executes one or several WMI requests
T1082 uses_windows_utilities: Uses Windows utilities for basic Windows functionality
T1057 has_wmi: Executes one or several WMI requests
T1497 evasion_runmru: Attempts to detect Sandbox by Run MRU
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.001 antivm_generic_video: Checks information about video adapters in registry, possibly for anti-virtualization
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1497.001 antivm_queries_computername: Retrieves the computer name
T1016 get_hostname: Attempts to get hostname

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

kills_explorer: Terminates explorer.exe process
network_bind: Starts servers listening at 127.0.0.1:0, None
dotnet_suspicious_resources_names: Dotnet program has suspicious resources names
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
error_drawtext: An error occurred while executing the file
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
pe_overlay: PE file contains overlay