Managed XDR

c-users-user-appdata-l...rms-of-partnership.lnk (Brute Ratel) — malware analysis report

File info

Filename
c-users-user-appdata-local-temp-ppzpuf0a.1ak-documents-terms-of-partnership.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon, Archive, ctime=Thu Jan 30 15:35:21 2025, mtime=Fri Sep 25 21:44:38 2026, atime=Thu Jan 30 15:35:21 2025, length=455680, window=hide
File size
2.5 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
2e4195743463e5f9fbdb3269e350b9f714f7f855
SHA256
523d6d2479a05d5a3c854fe6a76af1156afc05c9a46e1e8f74bea5c8b8d87aa0
MD5
8cf57f185a27f84a284c7850493748de

Malwares

  • Brute Ratel

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious PowerShell process
T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests
T1059.001 suspicious_process: Spawns a suspicious process
T1059.003 executes_dropped_cmd: Executes dropped batch files

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1027.002 decompress_pefile: Unpacks a PE file into memory
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497 antidbg_setinformationthread: Attempts to evade debugger using NtSetInformationThread
T1497.001 antivm_generic_cpu: Checks the CPU name, possibly for anti-virtualization
T1140 decompress_pefile: Unpacks a PE file into memory
T1027.004 compiles_code: Compiles C# code
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1497 evasion_runmru: Attempts to detect Sandbox by Run MRU
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552 infostealer_mail: Collects personal data from local email clients
T1552 infostealer_browser: Retrieves personal information from local Internet browsers
T1503 infostealer_browser: Retrieves personal information from local Internet browsers
T1552.001 infostealer_bitcoin: Attempts to obtain access to Bitcoin/ALTCoin wallets
T1552.001 infostealer_vpn: Collects information about installed VPN software
T1555.003 cookie_files: Accesses cookie files
T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager
T1552 cookie_files: Accesses cookie files
T1003.001 dumps_lsass: Dumps lsass.exe process (probably, to extract credentials)

Discovery

T1033 recon_beacon: The process has sent information about the computer over the network
T1497 antidbg_setinformationthread: Attempts to evade debugger using NtSetInformationThread
T1497.001 antivm_generic_cpu: Checks the CPU name, possibly for anti-virtualization
T1518.001 antiav_detectreg: Attempts to detect installed antiviruses by a certain registry key
T1057 has_wmi: Executes one or several WMI requests
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1518 recon_programs: Collects information about installed programs
T1082 has_wmi: Executes one or several WMI requests
T1082 uses_windows_utilities: Uses Windows utilities for basic Windows functionality
T1518 locates_browser: Attempts to identify where browsers are installed
T1497 evasion_runmru: Attempts to detect Sandbox by Run MRU
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization

Collection

T1114 infostealer_mail: Collects personal data from local email clients

Command and Control

T1071.001 recon_beacon: The process has sent information about the computer over the network
T1071.001 network_cnc_http: Suspicious HTTP traffic
T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

suricata_alert: Malicious traffic detected
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
network_bind: Starts servers listening at None
codepage: Checks the system code page
network_powershell: PowerShell process network connection detected
create_rpc_bindings: Creates RPC connection
dll_mapping_exception: Failed mapping of DLL with exception
creates_suspended_process: Creates suspended process
creates_in_programdata: Creates files in the ProgramData directory
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
open_winlogon_process: Trying to open winlogon process
yara_rules: Static rules

Related reports