Managed XDR

c-documents-and-settin...7g6unzjkvv2vd.exe-copy (DCRat) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-documents-and-settings-default-downloads-papnbqlu7g6unzjkvv2vd.exe-copy
Тип файла
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Размер файла
784 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x86 en

Хеши

SHA1
887131e93c024b787ae73d0690bc8d1ed082d079
SHA256
3f4f5e4245c29186b1c4d490f81f3cb9bf833d6126c6c207c9eb50139d92e829
MD5
46f294327e2748676f7e5a1a38ef8f7b

Вредоносное ПО

  • DCRat

Сигнатуры

Execution

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup

Persistence

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Defense Evasion

T1564.001 hides_original_file: Makes original executable file hidden
T1564.001 stealth_file: Creates hidden or system files
T1027.002 packer_polymorphic: Creates a modified copy of itself
T1562 modify_uac_prompt: Attempts to modify UAC pop-up window behavior
T1562 disables_uac: Disable UAC
T1036 system_filename: Created a file named as a common system file
T1497 debugs_self: Creates a process and debugs it

Discovery

T1497 debugs_self: Creates a process and debugs it

Other

yara_rules: Static rules
suspicious_process: Spawns a suspicious process
creates_in_windows: Creates files in the Windows directory
creates_exe: Creates executable files in the file system
no_graphical_activity: No graphic activity
dotnet_suspicious_resources_names: Dotnet program has suspicious resources names
creates_suspended_process: Creates suspended process
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
message_box: Displays a message
add_base64_to_registry: Writes Base64 encoded data to registry
test_check_service: Starts services
dotnet_downloader_possible_network_problem: Dotnet program possibly has network problem
dotnet_suspicious_module_name: Dotnet program has suspicious module name

Похожие отчёты