Managed XDR

download.exe — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
download.exe
Тип файла
PE32+ executable (console) x86-64, for MS Windows
Размер файла
6.9 MB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
522d1dc4b6ce2a42584fa87c601f9362279505cf
SHA256
4bc0d5eeedb2916251fe62683813e865a79ab5c9625b941c66246f0187b0d270
MD5
3c3910133cdacccf8ff725f0a76819c8

Сигнатуры

Execution

T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL
T1059.006 drops_python_dll: Drops python dll

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1218 suspicious_cmdline: Executes a suspicious command
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1071.001 wininet_openurl: Performs HTTP/HTTPS-requests using InternetOpenUrl

Other

certutil_download: Download file using certutil
creates_in_windows: Creates files in the Windows directory
dead_host: Connects to IP addresses that do not respond to requests
creates_suspended_process: Creates suspended process
creates_exe: Creates executable files in the file system
test_check_service: Starts services
pe_overlay: PE file contains overlay