Managed XDR

g-extract-2018-samples...6184a816e38df5b950.vir — malware analysis report

File info

Filename
g-extract-2018-samples-dll32-virussign.com_165cc9989dd3216184a816e38df5b950.vir
File type
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
File size
1.3 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
b1f2207f215250b881a2a811c980f82a1c852b9d
SHA256
3d173ba6e8331a54839809a19d978a1d4ca65323479ef44d829b0eaf8583f61e
MD5
165cc9989dd3216184a816e38df5b950

Signatures

Execution

T1047 has_wmi: Executes one or several WMI requests

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_vbox_devices: Detects VirtualBox through the presence of a device
T1497.001 antivm_vbox_files: Detects VirtualBox through the presence of a file
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Discovery

T1497.001 antivm_vbox_devices: Detects VirtualBox through the presence of a device
T1497.001 antivm_vbox_files: Detects VirtualBox through the presence of a file
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
dead_host: Connects to IP addresses that do not respond to requests
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
valid_authenticode: The digital signature has been verified
message_box: Displays a message
error_drawtext: An error occured while executing the file
pe_overlay: PE file contains overlay
Managed XDR