Managed XDR

optimization-v2-20240914t063413z-001.zip — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
optimization-v2-20240914t063413z-001.zip
Тип файла
Zip archive data, at least v2.0 to extract
Размер файла
8 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
e73b1582fdc8033ae13300146ee0c06d3e8b1138
SHA256
30771b575fc44a83b499f0e23f9f91a5086c3980706e3f915bf9730370aa0c54
MD5
0b1d970111833c27f52079c9727a98ab

Сигнатуры

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1047 has_wmi: Executes one or several WMI requests
T1059.001 suspicious_process: Spawns a suspicious process
T1106 susp_callbacks: Suspicious usage of some WinAPI with callbacks

Persistence

T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key

Privilege Escalation

T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1574.011 persistence_services: Modifies Services registry key
T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1562.004 firewall_add_rule: Modifies Firewall rules
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1480 system_default_lang_id_present: Checks the system language
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Discovery

T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1082 uses_windows_utilities: Uses Windows utilities for basic Windows functionality
T1518 locates_browser: Attempts to identify where browsers are installed
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1135 server_share_info: Retrieves information about each shared resource on a server

Command and Control

T1095 network_icmp: Creates ICMP traffic

Other

network_bind: Starts servers listening at 0.0.0.0:49157, 0.0.0.0:49153
codepage: Checks the system code page
unexpected_exception: Unexpected exception
create_rpc_bindings: Creates RPC connection
has_pdb: This executable file has a PDB path
break_limit_exceeded: Warning: function calls limit has been exceeded
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay
suricata_alert: Malicious traffic detected
many_files_in_archive: The archive contains more than 5 files