Managed XDR

cmd.exe (Expiro) — malware analysis report

File info

Filename
cmd.exe
File type
PE32 executable (console) Intel 80386, for MS Windows
File size
692.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
1c6662dd27577b32ffa2473526528382c65119e2
SHA256
0855ba74fb1d16c6e012641794063edeae745f5bb4d4ebe5fefba2276a898c84
MD5
151955ff170213e05e2f1d7a5e695fdc

Malwares

  • Expiro

Signatures

Execution

T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1562.001 disables_security: Disables Windows Security options
T1497.001 antivm_generic_services: Enumerates services, possibly for anti-virtualization
T1112 stealth_hide_notifications: Attempts to change notification settings
T1027.002 packer_polymorphic: Creates a modified copy of itself
T1562 modify_security_center_warnings: Attempts to modify or disable Security Center notifications
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1036 system_filename: Created a file named as a common system file
T1574.011 persistence_services: Modifies Services registry key
T1089 disables_smartscreen: Modifies or disables Windows SmartScreen
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1480 system_default_lang_id_present: Checks the system language

Discovery

T1497.001 antivm_generic_services: Enumerates services, possibly for anti-virtualization
T1518.001 antiav_detectservice: Attempts to detect installed antiviruses by a certain service
T1518.001 antiav_detectreg: Attempts to detect installed antiviruses by a certain registry key
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1518 recon_programs: Collects information about installed programs
T1057 has_wmi: Executes one or several WMI requests
T1057 process_interest: Enumerates processes
T1082 has_wmi: Executes one or several WMI requests
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.001 antivm_queries_computername: Retrieves the computer name

Impact

T1489 stops_service: Stops Windows services
T1489 change_service_config: Stops services via ChangeServiceConfig
T1489 service_control_stop: Stops services via ControlService

Other

yara_rules: Static rules
executes_dropped_exe: Executes dropped exe files
creates_in_windows: Creates files in the Windows directory
expiro_mutexes: Expiro is detected: mutex
network_bind: Starts servers listening at 127.0.0.1:42424
creates_exe: Creates executable files in the file system
has_pdb: This executable file has a PDB path
access_recyclebin: Manipulation with recyclebin detected
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
writes_data: Writes big amount of data to disk

Related reports