Managed XDR

d8fb0d64ea8b4a32d6c586...7e4cf090a67d22d8f78b62 (njRAT, K.G.B RAT) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
d8fb0d64ea8b4a32d6c5869212a62a3c9c6357e4fd7e4cf090a67d22d8f78b62
Тип файла
Zip archive data, at least v2.0 to extract
Размер файла
95.2 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
172367b18ae7240c649fb514725ee80d9a86915c
SHA256
d8fb0d64ea8b4a32d6c5869212a62a3c9c6357e4fd7e4cf090a67d22d8f78b62
MD5
08af4ffbaff1d8a4a3de99e17ec2ad2c

Вредоносное ПО

  • njRAT
  • K.G.B RAT

Сигнатуры

Execution

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1059.001 suspicious_powershell: Creates suspicious PowerShell process
T1059.001 suspicious_process: Spawns a suspicious process
T1047 has_wmi: Executes one or several WMI requests

Persistence

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1564.001 hides_original_file: Makes original executable file hidden
T1112 stealth_hiddenreg: Attempts to change Explorer settings so that hidden files won't be displayed
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1564.001 stealth_file: Creates hidden or system files
T1562 modify_uac_prompt: Attempts to modify UAC pop-up window behavior
T1562 modify_security_warnings: Attempts to modify or disable security notifications
T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1036 system_filename: Created a file named as a common system file
T1036 system_procname: Created a process named as a common system process
T1497.001 antivm_network_adapters: Checks NIC addresses
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1497.002 antivm_usbstor: Reads information about usbdevices from regkey
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1070 stealth_window: A process created a hidden window

Credential Access

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)
T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1082 recon_systeminfo: Collects system information (ipconfig, netstat, systeminfo, net)
T1033 recon_beacon: The process has sent information about the computer over the network
T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1082 has_wmi: Executes one or several WMI requests
T1518.001 wmi_check_av: Uses WMI to check for installed antivirus software
T1057 has_wmi: Executes one or several WMI requests
T1497.001 antivm_network_adapters: Checks NIC addresses
T1518 locates_browser: Attempts to identify where browsers are installed
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1497.002 antivm_usbstor: Reads information about usbdevices from regkey
T1016 system_network_configuration_discovery: System network configuration discovery detected

Collection

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Command and Control

T1071.001 recon_beacon: The process has sent information about the computer over the network
T1071.001 network_cnc_http: Suspicious HTTP traffic
T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Impact

T1565 modifies_hostfile: Writes data to system hosts file

Other

yara_rules: Static rules
keylogger_sendsdata_telegram: Keylogger logs keystrokes and sends intercepted data via Telegram
ce_info: K.G.B RAT Configuration Data found
static_pe_anomaly: The PE file structure contains anomalies
suricata_alert: Malicious traffic detected
ip_domains: Identifies an IP address using external resources
network_bind: Starts servers listening at None
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
only_exec_in_archive: The archive contains only an executable file
telegram_api: Telegram Messenger API is used
create_rpc_bindings: Creates RPC connection
require_administrator: Requests administrator privileges
creates_suspended_process: Creates suspended process
break_limit_exceeded: Warning: function calls limit has been exceeded
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services

Похожие отчёты