Managed XDR

c-users-user-downloads...-9021-1556cb46bcf0.tmp — malware analysis report

File info

Filename
c-users-user-downloads-26efafe4-ab94-4345-9021-1556cb46bcf0.tmp
File type
Zip archive data, at least v2.0 to extract
File size
17.4 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
72c2a65fbc0d7cb2d86bf8cf0d5e043292fdd298
SHA256
8a7140df7cb463ed0010603c24fc44f8718e0f5ab59e0fd8f3405c670f81ddae
MD5
7c46f17ebac226a67c832c6191e09243

Signatures

Execution

T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests
T1059 wscript_info_discovery: Collects info about system with Wscript.Shell

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552 infostealer_browser: Retrieves personal information from local Internet browsers
T1503 infostealer_browser: Retrieves personal information from local Internet browsers
T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1082 has_wmi: Executes one or several WMI requests
T1082 uses_windows_utilities: Uses Windows utilities for basic Windows functionality
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1082 reads_csrss: Attempts to read csrss.exe memory
T1082 wscript_info_discovery: Collects info about system with Wscript.Shell
T1087.002 domain_account_discovery: Collects information about accounts and groups in domain
T1033 wscript_info_discovery: Collects info about system with Wscript.Shell

Command and Control

T1102.003 cloud_amazonaws: Connects to cloud services of Amazon AWS (potentially for malicious payload delivery)

Other

opens_document: Opens office documents
creates_exe: Creates executable files in the file system
creates_doc: Creates (office) documents in the file system
creates_in_programdata: Creates files in the ProgramData directory
test_check_service: Starts services