Managed XDR
Group-IB MDP Report
File info
Filename: remote-access-windows64-offline.exe_ico
File Type: PE32+ executable (GUI) x86-64, for MS Windows
File Size: 33.7 MB
Env info
win7/x64 en
Hashes
SHA1: 1c1c1d2c1e15370b00d3795b51674ba5f71cbde1
SHA256: e4043bfe2c1bc3ea771b468d8418a6e48877c88c8e38b18edb0b1d64b8635b00
MD5: 4c7083fc402b80774a3eda237b8ace66
Signatures
Privilege Escalation
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Defense Evasion
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1222 icacls: May obtain or change Discretionary access control lists (DACLs)
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1480 system_default_lang_id_present: Checks the system language
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1497.001 antivm_queries_computername: Retrieves the computer name
Credential Access
T1552 cookie_files: Accesses cookie files
T1555.003 cookie_files: Accesses cookie files
Discovery
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1135 server_share_info: Retrieves information about each shared resource on a server
T1497.001 antivm_queries_computername: Retrieves the computer name
Command and Control
T1032 internet_security_options: Sets Internet connections options that are not secure
T1071 internet_security_options: Sets Internet connections options that are not secure
T1071.001 network_http: Performs HTTP requests
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet
Other
suricata_alert: Malicious traffic detected
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
create_rpc_bindings: Creates RPC connection
require_administrator: Requests administrator privileges
get_policy_info: Retrieves information about a Policy object
creates_in_programdata: Creates files in the ProgramData directory
test_check_service: Starts services
pe_overlay: PE file contains overlay
static_big_overlay: Executable file contains an enormously big overlay
valid_authenticode: The digital signature has been verified
Managed XDR