Managed XDR

onafriq-app-new-platform.eml — malware analysis report

File info

Filename
onafriq-app-new-platform.eml
File type
RFC 822 mail, ASCII text, with very long lines, with CRLF line terminators
File size
2.3 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
0b4264c28ea4bbd0f823cbdcd9f71110e138c5fe
SHA256
affa0a55fab234b1ea9ab18ed28fb944302db6926bf1c0eab3cf4dda1b69b6eb
MD5
533dfb9038fd3ed1d6fd045c1f6405c7

Signatures

Initial Access

T1192 html_urls: HTML-document downloads a file

Execution

T1569.002 persistence_service: Starts newly created service
T1047 has_wmi: Executes one or several WMI requests

Persistence

T1543.003 creates_service: Creates a service, that will start automatically
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key

Privilege Escalation

T1543.003 creates_service: Creates a service, that will start automatically
T1055 injection_thread: Code injection to a remote process using CreateRemoteThread or NtQueueApcThread
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1055 injection_thread: Code injection to a remote process using CreateRemoteThread or NtQueueApcThread
T1497.001 antivm_generic_services: Enumerates services, possibly for anti-virtualization
T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1497 antidbg_query_process: Checks if the process is being debugged (ProcessDebugPort)
T1036 system_filename: Created a file named as a common system file
T1036 system_procname: Created a process named as a common system process
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1574.011 persistence_services: Modifies Services registry key
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1003.001 dumps_lsass: Dumps lsass.exe process (probably, to extract credentials)
T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Discovery

T1497.001 antivm_generic_services: Enumerates services, possibly for anti-virtualization
T1497 antidbg_query_process: Checks if the process is being debugged (ProcessDebugPort)
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.001 antivm_queries_computername: Retrieves the computer name
T1082 has_wmi: Executes one or several WMI requests
T1049 list_ts_rdp_sessions: Lists ts/rdp sessions

Collection

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Impact

T1565 modifies_hostfile: Writes data to system hosts file
T1529 shutdown_system: Shuts the system down

Other

creates_in_windows: Creates files in the Windows directory
creates_exe: Creates executable files in the file system
suspicious_process_network: Unusual process network activity detected
dead_host: Connects to IP addresses that do not respond to requests
suspicious_process: Spawns a suspicious process
process_crashed: One of the processes has failed
unsigned_driver_drop: Sample is not signed and drops a device driver
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
msi_has_custom_action: MSI file contains custom action
creates_in_programdata: Creates files in the ProgramData directory
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
driver_load: Loads a driver
checktokenmembership: Checks user token with CheckTokenMembership call
open_winlogon_process: Trying to open winlogon process
suricata_alert: Malicious traffic detected
yara_rules: Static rules