Managed XDR

servicess.exe — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
servicess.exe
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
216.2 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
2344bba2392cae414a76397ea0d8cfd543003c9d
SHA256
2bea957118b8a852c85ff125a3a8bc2dad0a72b907f6fe8e136c5bdf2747af5f
MD5
5e745e38053fab1c037ad2241f5d5823

Сигнатуры

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1183 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1183 persistence_autorun: Makes itself run automatically on Windows startup
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1183 persistence_autorun: Makes itself run automatically on Windows startup
T1497.001 antisandbox_productid: Obtains Windows ProductID, probably to fingerprint a sandbox
T1027.002 packer_polymorphic: Creates a modified copy of itself
T1564.001 stealth_file: Creates hidden or system files
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antisandbox_productid: Obtains Windows ProductID, probably to fingerprint a sandbox
T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
static_pe_anomaly: The PE file structure contains anomalies
creates_in_windows: Creates files in the Windows directory
copies_self: Creates a copy of itself
creates_exe: Creates executable files in the file system
no_graphical_activity: No graphic activity
pe_overlay: PE file contains overlay