Managed XDR

expressed.exe (Dharma) — malware analysis report

File info

Filename
expressed.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed
File size
645 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
709f0ae6468155a547c309b6b17ce326fbe455d2
SHA256
2be419fd9277a0c240c03258ea8d4d6e39e3cb29fc3448b158f6c210d45d3ca4
MD5
6c74508ff7625ace8090eb29754d58a2

Malwares

  • Dharma

Signatures

Execution

T1059.003 suspicious_cmd_process: Cmd.exe without commandline launches a new process

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1070 stealth_webhistory: Clears browsing history
T1564.001 stealth_file: Creates hidden or system files
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 packer_upx: The executable file is compressed using UPX
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1480 system_default_lang_id_present: Checks the system language

Credential Access

T1552 infostealer_mail: Collects personal data from local email clients
T1552 infostealer_browser: Retrieves personal information from local Internet browsers
T1552.001 infostealer_bitcoin: Attempts to obtain access to Bitcoin/ALTCoin wallets
T1503 infostealer_browser: Retrieves personal information from local Internet browsers
T1555.003 cookie_files: Accesses cookie files
T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager
T1552 cookie_files: Accesses cookie files

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1083 crawls_directories: Opens a huge number of directories all over disk C: (possibly, searches for sensitive data)
T1057 process_interest: Enumerates processes
T1518 locates_browser: Attempts to identify where browsers are installed
T1497.001 antivm_queries_computername: Retrieves the computer name
T1082 wts_enumproc: Attempts to enumerate processes using WTS

Collection

T1114 infostealer_mail: Collects personal data from local email clients
T1074.001 access_recyclebin: Manipulation with recyclebin detected

Impact

T1486 modifies_files: Cryptolocker indicators detected (renamed 500 or more files)
T1486 modifies_files2: Cryptolocker indicators detected (100 or more files are modified)
T1486 ransomware_extensions: Ransomware(s) Roger indicators detected (specific extension is added to files)
T1490 vssadmin_delete_shadows: Attempt to delete volume shadow copies
T1561 wiper_zeroed_bytes: Overwrites multiple files with zero bytes (hex 00)
T1486 ransomware_files_2: Ransomware(s) Roger indicators detected (creates keys and the instruction on how to unlock the files)
T1565.001 overwrites_firefox_settings: Modifies Mozilla Firefox settings
T1485 deletes_files: Removes 500 or more files from C: drive

Other

yara_rules: Static rules
ransomware_dharma: Detected Dharma ransomware
ransomware_shadowcopy: Removes volume shadow copies
creates_in_windows: Creates files in the Windows directory
runs_utility_without_cmdline: Runs system utility without arguments (non-typical usage)
copies_self: Creates a copy of itself
creates_exe: Creates executable files in the file system
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
creates_in_programdata: Creates files in the ProgramData directory
test_check_service: Starts services
writes_data: Writes big amount of data to disk
open_winlogon_process: Trying to open winlogon process

Related reports