Managed XDR

dm-spammer_original.exe — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
dm-spammer_original.exe
Тип файла
PE32+ executable (console) x86-64, for MS Windows
Размер файла
9.3 MB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
25aaa28323b00f72eec147cc44dc5aaae8f99dc3
SHA256
9428a8d5955b305b52b403dccf721daa65d01a4d367f7d028fb2e52b64854abc
MD5
d450b72a5d0be74aee2f1a3f3d7ec0ab

Сигнатуры

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests
T1059.001 suspicious_process: Spawns a suspicious process
T1059.006 drops_python_dll: Drops python dll

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1562 windefender_rollback: Rolls back signature definitions in Windows Defender
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1562.001 windows_defender_add_exclusion: Adds a path to Microsoft Defender exclusion list

Discovery

T1082 has_wmi: Executes one or several WMI requests
T1082 uses_windows_utilities: Uses Windows utilities for basic Windows functionality
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1518 locates_browser: Attempts to identify where browsers are installed

Command and Control

T1071.001 network_http: Performs HTTP requests

Other

ip_domains: Identifies an IP address using external resources
dns_without_resolve: DNS query without a response
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
creates_exe: Creates executable files in the file system
pe_overlay: PE file contains overlay
suricata_alert: Malicious traffic detected
yara_rules: Static rules