Managed XDR

wifi-242ko-.msg — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
wifi-242ko-.msg
Тип файла
Composite Document File V2 Document, No summary info
Размер файла
259 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
ffb42ab5c233a3ce0cb0f68002c6db85142edb02
SHA256
98481b23344706975d3361503eb4436d1a2b0a2380d1a37fb82a029512ec9469
MD5
af697f56b330d63beb4478f1ff83798b

Сигнатуры

Execution

T1059.003 executes_dropped_cmd: Executes dropped batch files
T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests
T1059.003 suspicious_batch: Suspicious batch

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1112 creates_largekey: Saves very large data in the registry, can be used to save the configuration or body of the malware
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1082 has_wmi: Executes one or several WMI requests
T1082 uses_windows_utilities: Uses Windows utilities for basic Windows functionality
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1057 has_wmi: Executes one or several WMI requests
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1016.001 system_network_configuration_discovery: System network configuration discovery detected

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

creates_exe: Creates executable files in the file system
network_anomaly: Network anomalies occurred during the analysis
creates_suspended_process: Creates suspended process
break_limit_exceeded: Warning: function calls limit has been exceeded
test_check_service: Starts services
Managed XDR