Managed XDR

home-petik-ss-malware-...thys_smoke-loader_stop (DarkComet, ISR Stealer, Hupigon) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
home-petik-ss-malware-2025-05-28_cfbb0f921fa5cef043d838f5eda07476_amadey_elex_gcleaner_rhadamanthys_smoke-loader_stop
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
1.1 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
42ec13e82bdc50f58fc5b60dee70d1bf8dba5772
SHA256
1437d64005768e8d58dded4bfffeef23105f3b4488fcde4bfec0a4e65bdc7b05
MD5
cfbb0f921fa5cef043d838f5eda07476

Вредоносное ПО

  • DarkComet
  • ISR Stealer
  • Hupigon

Сигнатуры

Privilege Escalation

T1055.002 inject_write_pe: Writes PE file to another process's memory
T1055.012 injection_runpe: Injects code into another process
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1055.002 inject_write_pe: Writes PE file to another process's memory
T1055.012 injection_runpe: Injects code into another process
T1140 decompress_pefile: Unpacks a PE file into memory
T1027.002 decompress_pefile: Unpacks a PE file into memory
T1497.001 antivm_generic_cpu: Checks the CPU name, possibly for anti-virtualization
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1218 suspicious_cmdline_keywords: Cmdline with suspicious keywords
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1497.001 antivm_queries_computername: Retrieves the computer name

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager
T1552 cookie_files: Accesses cookie files

Discovery

T1497.001 antivm_generic_cpu: Checks the CPU name, possibly for anti-virtualization
T1033 recon_beacon: The process has sent information about the computer over the network
T1012 infostealer_dm: Retrieves sensitive data from download managers
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1518 locates_browser: Attempts to identify where browsers are installed
T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1071.001 recon_beacon: The process has sent information about the computer over the network
T1071.001 network_http: Performs HTTP requests
T1071.001 wininet_openurl: Performs HTTP/HTTPS-requests using InternetOpenUrl

Other

yara_rules: Static rules
suricata_alert: Malicious traffic detected
networkdyndns_checkip: Connects to a Dynamic DNS domain
executes_dropped_exe: Executes dropped exe files
creates_exe: Creates executable files in the file system
rat_fynloski: Fynloski/DarkComet indicators detected
dns_without_resolve: DNS query without a response
dns_tld_cc: Connects to TLD .CC, possibly malware
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
origin_langid: Unconventional language of the executable file
get_policy_info: Retrieves information about a Policy object

Похожие отчёты