Managed XDR

malicious-364.rar (Cobalt Strike) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
malicious-364.rar
Тип файла
RAR archive data, v5
Размер файла
2.1 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
38170f7b577abc0533e6f1a883061920b57bd3a7
SHA256
f64934b4257cf26cd760a7726a0a4b0498d46eae3ac38e42f9e207bb2f32cdfc
MD5
d47608b01e9cb9181c69ad65e56e6121

Вредоносное ПО

  • Cobalt Strike

Сигнатуры

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059 powershell_cmd_longcommandline: Suspiciously long commandline

Privilege Escalation

T1055 possible_injection_to_itself: Possible code injection to itself
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1055 possible_injection_to_itself: Possible code injection to itself
T1497 antidbg_query_process: Checks if the process is being debugged (ProcessDebugPort)
T1027.004 compiles_code: Compiles C# code
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 antidbg_query_process: Checks if the process is being debugged (ProcessDebugPort)
T1497.001 antivm_queries_computername: Retrieves the computer name
T1135 server_share_info: Retrieves information about each shared resource on a server

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
dead_host: Connects to IP addresses that do not respond to requests
process_crashed: One of the processes has failed
unexpected_exception: Unexpected exception
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call
many_files_in_archive: The archive contains more than 5 files

Похожие отчёты