Managed XDR

199006f7d4dbc6ccdecbe9...ebd3de095a3a63_new.exe (Hive) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
199006f7d4dbc6ccdecbe99b18e8582ba42e6f66f6e3de865eebd3de095a3a63_new.exe
Тип файла
PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
Размер файла
3.5 MB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
849a430a4b9bf830ff55bd12d62f9e5994a4f231
SHA256
e58dca27e182aab06f4d0ea1f4a2f8cfe327af9c9a7a8725fe6b59a0920b0374
MD5
61b72270ba74ec5d415a35b742f92de2

Вредоносное ПО

  • Hive

Сигнатуры

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1047 has_wmi: Executes one or several WMI requests
T1059.001 suspicious_process: Spawns a suspicious process

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1562.001 disables_security: Disables Windows Security options
T1070.001 wevtutil_clear_log: Clears event log using wevtutil
T1562 windefender_rollback: Rolls back signature definitions in Windows Defender
T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1562 disables_etw: Attempt to disable security Windows Event Logging

Discovery

T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1518 locates_browser: Attempts to identify where browsers are installed

Impact

T1489 stops_service: Stops Windows services
T1489 net_stop: Stops services through the use of net stop

Other

yara_rules: Static rules
hive: Detected Hive ransomware
hides_autorun_taskmanager: Hides application autorun record from Task Manager
ransomware_shadowcopy: Removes volume shadow copies
creates_many_processes: Spawns a lot of processes (over 70)
ransomware_bcdedit: Runs bcdedit commands specific to ransomware
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
test_check_service: Starts services
writes_data: Writes big amount of data to disk

Похожие отчёты

Managed XDR