Managed XDR

media-cape-malware-nic...b069b8db93fdde1764.exe (babuk, Cobalt Strike, Babuk, Lockbit) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
media-cape-malware-nico-dataset_resized_malicious_binaries-babuk-7cdc8057b3fe13b069b8db93fdde1764.exe
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
92.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
8ddd3c69fe3935e4903a2b397bc6f0de772a1bcb
SHA256
393a7a313548a4edc025fb47c6c8e614ecc2b41db880ecb59f20cf238e9a864c
MD5
7cdc8057b3fe13b069b8db93fdde1764

Вредоносное ПО

  • babuk
  • Cobalt Strike
  • Babuk
  • Lockbit

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1562 registry_hide_tracing: Modifies File/Console tracing settings (often used to hide iocs from the system)
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1070 stealth_window: A process created a hidden window

Credential Access

T1552 cookie_files: Accesses cookie files
T1555.003 cookie_files: Accesses cookie files

Discovery

T1057 process_interest: Enumerates processes
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Command and Control

T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Impact

T1490 vssadmin_delete_shadows: Attempt to delete volume shadow copies
T1486 ransomware_files: Ransomware indicators detected Lockbit (creates keys and the instruction on how to unlock the files)
T1486 ransomware_message: Ransomware indicators detected (possible ransom message creation)

Other

yara_rules: Static rules
ransomware_shadowcopy: Removes volume shadow copies
dead_host: Connects to IP addresses that do not respond to requests
create_rpc_bindings: Creates RPC connection
access_recyclebin: Manipulation with recyclebin detected
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call

Похожие отчёты