Managed XDR

zmove — malware analysis report

File info

Filename
zmove
File type
PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
52.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
9b5e7efe9938cd1487e98ea12f5043d5b25a8c4d
SHA256
ee1b7c9411cb2e622b0d05a27c1d848be5caf0ca666cfd7a180f54a521bc2b56
MD5
6dfb5da6f50e94b10b693ae0f85c62f6

Signatures

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1055 injection_thread: Code injection to a remote process using CreateRemoteThread or NtQueueApcThread
T1055.012 injection_runpe: Injects code into another process
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1055 injection_thread: Code injection to a remote process using CreateRemoteThread or NtQueueApcThread
T1055.012 injection_runpe: Injects code into another process
T1070 stealth_webhistory: Clears browsing history
T1497 antidbg_query_process: Checks if the process is being debugged (ProcessDebugPort)
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497 antidbg_query_process: Checks if the process is being debugged (ProcessDebugPort)
T1057 process_interest: Enumerates processes
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
has_pdb: This executable file has a PDB path
message_box: Displays a message
error_drawtext: An error occured while executing the file
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services